GCP
Stategraph Orchestration gets credentials for your Google Cloud project from a service account key or from OIDC. Plans and applies run on your GitHub Actions or GitLab CI runners, so the credentials stay there. The server never holds your cloud credentials.
Setup options
- Static credentials: a service account key, stored as a GitHub secret or GitLab CI/CD variable. It gets a first plan running quickly.
- OIDC: the GitHub Actions job impersonates a service account through Workload Identity Federation. There is no key file to store or rotate. It is the recommended method for production.
To change to OIDC later, add an oidc hook to .stategraph/config.yml and delete the key.
Next Steps
- Comment
stategraph planon a pull request to preview the changes, andstategraph applyto apply them. - Workflows: give each environment its own service account
- Cloud credentials: OIDC, static credentials, and custom credential scripts across providers
- GitHub Environments: let Google verify which GitHub Actions environment a run came from
- Configuration: the
.stategraph/config.ymlfile