ci: add config-as-code apply pipeline - #24
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
Adds a production CD pipeline that applies the declarative kuma-config/ configuration to the Uptime Kuma instance at status.zfnd.org when changes are merged to main (or manually via workflow_dispatch), using keyless Google Cloud Workload Identity Federation and runtime Secret Manager access.
Changes:
- Document the new “config-as-code apply” pipeline in
kuma-config/README.md. - Add a GitHub Actions workflow that authenticates via WIF, fetches required secrets from Secret Manager, and runs
npm ci && node apply.jsinkuma-config/.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 5 comments.
| File | Description |
|---|---|
kuma-config/README.md |
Documents the prod apply pipeline and how secrets/vars are sourced. |
.github/workflows/cd-apply-kuma-config.yml |
New workflow to reconcile kuma-config/ onto prod Kuma using WIF + Secret Manager at runtime. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Mask the fetched secrets with ::add-mask:: before use, add a job timeout-minutes, pass project_id to the auth step, and clarify the KUMA_PUBLIC_URL->KUMA_URL mapping in the README.
Skip the job unless running on main (a workflow_dispatch from a feature branch must not apply unmerged config to prod), and add set -euo pipefail so a failed secret fetch aborts instead of running apply.js with empty vars.
gustavovalverde
approved these changes
Jul 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reconciles
kuma-config/onto the prod Kuma (status.zfnd.org) on merge tomain, or viaworkflow_dispatch.apply.jsis declarative and non-destructive.Auth is keyless Workload Identity Federation as a least-privilege SA that reads the admin/webhook secrets from Secret Manager at run time — no secrets stored in GitHub.