Skip to main content

GitHub Secrets and Variables

Configure these values in GitHub under Settings > Secrets and variables > Actions.

warning

Never commit secret values, service account keys, OAuth credentials, or runtime env files to either repository.

Create the Google service accounts and JSON keys before adding these secrets. See Create Google service-account keys for the storage runtime, Document AI runtime, and deployment account definitions. Terraform CI accounts use WIF and need no JSON key secrets.

Backend repository​

Repository: CATALOG-Historic-Records/orphaned-wells-ui-server

NameRequired forNotes
PROJECT_IDGKE deploymentGoogle Cloud project ID for GKE authentication. Terraform uses its tracked configuration; bootstrap takes a shell environment variable.
DOCKERHUB_USERNAMEGKE deploymentDocker Hub account used to push and pull backend images.
DOCKERHUB_ACCESS_TOKENGKE deploymentDocker Hub token used by CI and Kubernetes image pull secret creation.
DEPLOYMENT_SERVICE_KEY_JSONGKE deploymentGoogle Cloud service account key JSON used by GitHub Actions for deployment only. Use the same deployment service account as the frontend repo if it has both GKE and App Engine deploy roles.
STORAGE_SERVICE_KEY_JSONBackend runtime filesGoogle Cloud service account key JSON used by the backend for Cloud Storage only.
DOCUMENT_AI_SERVICE_KEY_JSONBackend runtime filesGoogle Cloud service account key JSON used by the backend for Document AI processing and processor administration.
K8S_DEPLOY_TARGETSDisabled Terraform CI rollout fallbackTarget JSON used only while ENABLE_TERRAFORM_CI is not true. Enabled deployments read live Terraform outputs.
<COLLABORATOR>_ENVGKE deploymentRuntime .env content for each dispatch-supported backend collaborator. The current dispatch workflow reads STAGING_ENV, CA_ENV, ISGS_ENV, NEWTS_ENV, OSAGE_ENV, and RRC_ENV.

The runtime env secrets should contain backend runtime values such as database settings, storage settings, OAuth settings, and collaborator configuration. The GKE workflow overrides:

  • ENVIRONMENT
  • BACKEND_URL
  • LOG_DIR
  • LOCAL_STORAGE_ROOT
  • LOCAL_STORAGE_URL_BASE
  • STORAGE_BUCKET_NAME
  • STORAGE_SERVICE_KEY
  • DOCUMENT_AI_SERVICE_KEY
  • GOOGLE_APPLICATION_CREDENTIALS

Keep COLLABORATOR in the runtime secret if the backend uses collaborator-specific processors or configuration.

Backend repository variables​

Use repository variables to control automatic GKE deploys:

NamePurpose
ENABLE_GKE_DEPLOYMENTSEnables automatic GKE deploys for all collaborator workflows that check this variable.
ENABLE_GKE_STAGING_DEPLOYEnables automatic staging GKE deploys.
ENABLE_GKE_CA_DEPLOYEnables automatic CA GKE deploys.
ENABLE_GKE_ISGS_DEPLOYEnables automatic ISGS GKE deploys.
ENABLE_GKE_NEWTS_DEPLOYEnables automatic NEWTS GKE deploys.
ENABLE_GKE_OSAGE_DEPLOYEnables automatic OSAGE GKE deploys.
ENABLE_TERRAFORM_CIEnables upstream WIF planning, automatic no-change completion, approval-gated changes, and live deploy targets. Leave disabled until bootstrap and apply protection are configured.
TF_WIF_PROVIDERFull WIF provider resource name from bootstrap.
TF_PLAN_SERVICE_ACCOUNTPlan/no-change account email, with infrastructure reads and narrowly scoped state-lock and readiness-record writes.
TF_APPLY_SERVICE_ACCOUNTEnvironment-gated infrastructure apply account email.
TF_WORKSPACEExisting remote Terraform workspace, currently documented as ogrre.
TF_CI_BUCKETDedicated private plan/readiness bucket name, without gs://.

Set these variables in the upstream backend repository. RRC automatic deployment uses the global ENABLE_GKE_DEPLOYMENTS flag; it has no separate RRC enablement variable. Fork pushes skip staging jobs even if flags are enabled.

Follow the backend Terraform CI setup guide to create WIF and configure terraform-apply with required reviewers, a main-only branch restriction, and administrator bypass disabled. PRs only run credential-free checks; the terraform-plan Environment is retired. Normal PR merge approvals and the apply Environment's self-review policy are independent. Referencing an Environment in YAML does not configure its protection rules.

Rerun the updated bootstrap before enabling automatic no-change completion on an existing installation. Reuse the existing variable values; the added grant allows only this workspace's readiness record to be replaced. For first rollout, update active collaborator workflows to read live targets before enabling CI. Phase one retains DEPLOYMENT_SERVICE_KEY_JSON; Terraform CI needs no new JSON key.

When adding a new collaborator, add the matching secret and variable only after the workflow is configured to read it. The reusable GKE dispatch workflow must include the collaborator in its DEPLOY_ENV options, accepted secrets, and runtime-env case mapping.

Legacy backend VM secrets​

These are only needed for the legacy VM deployment path:

NamePurpose
DEPLOY_TARGETSJSON map of VM names and zones consumed by older VM deployment workflows.
SSH_USERNAMESSH user for deployment commands against Compute Engine VMs.

Frontend repository​

Repository: CATALOG-Historic-Records/orphaned-wells-ui

NameRequired forNotes
DEPLOYMENT_SERVICE_KEY_JSONApp Engine deploymentGoogle Cloud service account key JSON used by frontend deployment workflows. Use the same deployment service account as the backend repo if it has both App Engine and GKE deploy roles.
GOOGLE_CLIENTIDFrontend buildGoogle OAuth client ID written to REACT_APP_GOOGLE_CLIENTID.
DEV_BACKEND_URLDefault/staging frontend deploymentBackend URL used by the main frontend deploy workflow.
<COLLABORATOR>_BACKEND_URLCollaborator frontend deploymentsBackend URL for a collaborator frontend, such as CA_BACKEND_URL, ISGS_BACKEND_URL, NEWTS_BACKEND_URL, or OSAGE_BACKEND_URL.

Backend URL values must not include a trailing slash.

Updating secrets​

For command-line secret updates, first authenticate the GitHub CLI with an account that can edit repository Actions secrets:

gh auth login
gh auth status --hostname github.com

Set or update the three service-account key secrets:

gh secret set DEPLOYMENT_SERVICE_KEY_JSON \
--repo CATALOG-Historic-Records/orphaned-wells-ui-server \
< /secure/path/ogrre-deployment-ci-service-key.json

gh secret set STORAGE_SERVICE_KEY_JSON \
--repo CATALOG-Historic-Records/orphaned-wells-ui-server \
< /secure/path/ogrre-storage-runtime-service-key.json

gh secret set DOCUMENT_AI_SERVICE_KEY_JSON \
--repo CATALOG-Historic-Records/orphaned-wells-ui-server \
< /secure/path/ogrre-document-ai-service-key.json

gh secret set DEPLOYMENT_SERVICE_KEY_JSON \
--repo CATALOG-Historic-Records/orphaned-wells-ui \
< /secure/path/ogrre-deployment-ci-service-key.json

Only for the disabled Terraform CI rollout fallback, refresh the target secret after target changes from orphaned-wells-ui-server/deployment/terraform:

env -u TF_WORKSPACE terraform workspace select ogrre
gh secret set K8S_DEPLOY_TARGETS \
--repo CATALOG-Historic-Records/orphaned-wells-ui-server \
--body "$(terraform output -json kubernetes_deploy_targets | jq -c .)"

For manual updates in GitHub:

  1. Open the target repository on GitHub.
  2. Go to Settings > Secrets and variables > Actions.
  3. Select the secret or variable to create or update.
  4. Save the new value.
  5. Re-run the affected deployment workflow.