GitHub Environments
Stategraph Orchestration can run a workflow in a GitHub Environment. The environment's secrets and variables are then available to that workflow and to no other, and the environment's protection rules apply to the run.
A GitHub Environment is a GitHub Actions feature: a named deployment target in a repository, such as production, staging, or qa. Each environment has its own secrets, variables, and protection rules, such as required reviewers or a branch restriction.
Configure an environment
Set the environment key on a workflow in .stategraph/config.yml:
workflows:
- tag_query: production
environment: production
This workflow runs in the production GitHub Environment, with the secrets and variables of that environment.
To bind several workflows to several environments:
workflows:
- tag_query: staging
environment: staging
- tag_query: qa
environment: qa
Each workflow runs in the environment that its environment key names. See the workflows reference.
Best practices
- Name environments after their purpose:
production,staging,qa. - Store API keys, passwords, and certificates as secrets in their environment, not as repository secrets.
- Add protection rules, such as required reviewers or required status checks, to critical environments.
- Pair environments with access control, so that only the right people can start runs in them. See Security best practices.
Next steps
- Cloud credentials: OIDC role ARNs and other secrets referenced from the environment.
- Hardening AWS OIDC: restrict which runs can assume a role.