<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GitHubActions on LIFELOG</title>
    <link>/tags/githubactions/</link>
    <description>Recent content in GitHubActions on LIFELOG</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>ja</language>
    <copyright>© 2026 0222-nnn</copyright>
    <lastBuildDate>Tue, 11 Aug 2026 00:00:00 +0900</lastBuildDate><atom:link href="/tags/githubactions/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
      <title>TerraformでGitHub Actions用Workload Identity Federationを構築してみた</title>
      <link>/blog/20260811_terraform_gcp_advanced_wif_github_actions/</link>
      <pubDate>Tue, 11 Aug 2026 00:00:00 +0900</pubDate>
      
      <guid>/blog/20260811_terraform_gcp_advanced_wif_github_actions/</guid>
      <description>&lt;h2 class=&#34;relative group&#34;&gt;概要 
    &lt;div id=&#34;概要&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;
    
    &lt;span
        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100&#34;&gt;
        &lt;a class=&#34;group-hover:text-primary-300 dark:group-hover:text-neutral-700&#34;
            style=&#34;text-decoration-line: none !important;&#34; href=&#34;#%e6%a6%82%e8%a6%81&#34; aria-label=&#34;アンカー&#34;&gt;#&lt;/a&gt;
    &lt;/span&gt;        
    
&lt;/h2&gt;
&lt;p&gt;GitHub ActionsからGoogle Cloudへ認証する際、Service Account KeyをGitHub Secretsへ置く方法は漏洩の経路になります。長期間有効なJSON Keyは外部システムへ置きたくありません。&lt;/p&gt;
&lt;p&gt;そこでWorkload Identity Federation（WIF）を使います。GitHub ActionsのOIDC TokenをGoogle Cloudが直接受け入れる仕組みです。Service AccountをImpersonateでき、鍵ファイル自体を作りません。&lt;/p&gt;
&lt;p&gt;Terraformの基本操作とGitHub Actionsのworkflow構文は前提としています。&lt;/p&gt;
&lt;p&gt;Service Account Keyの発行は扱いません。Branch/Environment単位の細かいCondition設計や、Private Repositoryでの追加設定も対象外です。&lt;/p&gt;

&lt;h2 class=&#34;relative group&#34;&gt;検証すること 
    &lt;div id=&#34;検証すること&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;
    
    &lt;span
        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100&#34;&gt;
        &lt;a class=&#34;group-hover:text-primary-300 dark:group-hover:text-neutral-700&#34;
            style=&#34;text-decoration-line: none !important;&#34; href=&#34;#%e6%a4%9c%e8%a8%bc%e3%81%99%e3%82%8b%e3%81%93%e3%81%a8&#34; aria-label=&#34;アンカー&#34;&gt;#&lt;/a&gt;
    &lt;/span&gt;        
    
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Actions向けWorkload Identity PoolとProviderを作成できること&lt;/li&gt;
&lt;li&gt;OIDC ClaimとIAMの両方でRepositoryを限定できること&lt;/li&gt;
&lt;li&gt;Service Account KeyなしでWorkflowからGoogle Cloudへ認証できること&lt;/li&gt;
&lt;li&gt;Demo Bucketの読取で権限を確認できること&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class=&#34;relative group&#34;&gt;前提環境 
    &lt;div id=&#34;前提環境&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;
    
    &lt;span
        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100&#34;&gt;
        &lt;a class=&#34;group-hover:text-primary-300 dark:group-hover:text-neutral-700&#34;
            style=&#34;text-decoration-line: none !important;&#34; href=&#34;#%e5%89%8d%e6%8f%90%e7%92%b0%e5%a2%83&#34; aria-label=&#34;アンカー&#34;&gt;#&lt;/a&gt;
    &lt;/span&gt;        
    
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Google Cloud CLIとApplication Default Credentials（ADC）、Terraform&lt;/li&gt;
&lt;li&gt;GitHub Actionsを実行できるGitHub Repository&lt;/li&gt;
&lt;li&gt;IAM、Service Account、Cloud Storageを操作できるGoogle Cloud Project&lt;/li&gt;
&lt;li&gt;検証時のバージョン：Terraform 1.14.3、google 7.43.0&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 class=&#34;relative group&#34;&gt;今回の構成 
    &lt;div id=&#34;今回の構成&#34; class=&#34;anchor&#34;&gt;&lt;/div&gt;
    
    &lt;span
        class=&#34;absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100&#34;&gt;
        &lt;a class=&#34;group-hover:text-primary-300 dark:group-hover:text-neutral-700&#34;
            style=&#34;text-decoration-line: none !important;&#34; href=&#34;#%e4%bb%8a%e5%9b%9e%e3%81%ae%e6%a7%8b%e6%88%90&#34; aria-label=&#34;アンカー&#34;&gt;#&lt;/a&gt;
    &lt;/span&gt;        
    
&lt;/h2&gt;
&lt;p&gt;Workload Identity Poolは、外部のIDをGoogle Cloudへ受け入れる入口です。Projectの直下に置かれ、Regionには属しません。&lt;/p&gt;</description>
      
    </item>
    
  </channel>
</rss>
