3. Deployment automation flow
This documentation outlines the Terraform flow for managing deployments in our service architecture on Google Cloud Platform (GCP). The setup includes various app repositories for different services, a central deployment repository managing Terraform configurations and workflows, and a series of automated processes triggered by pushing docker image to artifact registry of connect-adatpers-prod.
Key elements
- **Build project: **connect-adapters-prod
- **Acceptance project: **connect-core-accept-355509
- **Production project: **connect-core-prod
- **Artifact registry repo: **services
- Cloud function: connect-adapters-prod → gcr-webhook-publisher
- Pub/Sub Topic and subscription:
- Topic: gcr (Click to know more)
- Subscription: eventarc-europe-west4-gcr-webhook-publisher-947541-sub-935
Components
- App Repositories
- Purpose: Each repository represents a distinct service with its source code and which generates docker image which will be used for deployment.
- Image Push: Docker images are pushed to a specific Artifact Registry
serviceswithin theconnect-adapters-prodproject.
- Deployment Repository
- Purpose: Contains all Terraform configurations and GitHub Actions workflows for deployment management.
- Terraform Configuration: Monitors changes in services defined in
tfvars.jsonfor push of docker images in artifact registry, plans and changes in infrastructure of GCP accordingly. - GitHub Actions: Executes deployment workflows triggered by image push in artifact registry.
- Artifact Registry
- Location: Project
connect-adapters-prod. - Function: Stores Docker images for the various services.
- Location: Project
- Pub/Sub Topic
- Purpose: Receives events when Docker images are pushed to the Artifact Registry.
- Subscription: Publishes messages to notify cloud function
gcr-webhook-publisher.
- Cloud Run Function
- Purpose: Handles the pub/sub event message with payload containing image data of pushed image.
- Action: Calls the deployment repository on GitHub to trigger a deployment action with the updated image details.
- Functionality: Uses GitHub App credentials (
app_id,installation_id, etc.) to generate an access token.
Acceptance Workflow
- Image Update
- Action: A Docker image is pushed to the Artifact Registry in the
connect-adapters-prodproject. - Trigger: Terraform listens for changes defined in
tfvars.jsonrelated to Docker image updates.
- Action: A Docker image is pushed to the Artifact Registry in the
- Event Publishing
- Action: Terraform publishes an event to the Pub/Sub topic indicating an image update.
- Pub/Sub to Cloud Run Service
- Action: The Pub/Sub topic delivers the event message to the Cloud Run service.
- Functionality: The Cloud Run service processes the message, generates an access token using GitHub App credentials, and triggers a Cloud Run function.
- Cloud Run Function Execution
- Action: The Cloud Run function uses the generated access token to authenticate and interact with the deployment repository.
- Deployment: The function dispatches a GitHub Actions workflow in the deployment repository, providing updated image details for the deployment process.
- Deployment Repository Action
- Action: GitHub Actions workflow in the deployment repository executes the deployment process using the updated image details provided by the Cloud Run function.
Production Workflow
- **Approval **
- Action: Production update job needs to be approved by marketplace admins
- Cloud Run Function Execution
- Action: On approval, job invokes function in GCP with image name and commit id details
- Deployment: The function dispatches a GitHub Actions workflow in the deployment repository, providing updated image details for the deployment process.
- Deployment Repository Action
- Action: GitHub Actions workflow in the deployment repository executes the deployment process using the updated image details provided by the Cloud Run function.
Conclusion
This flow ensures automated and secure deployment of services based on Docker image updates, leveraging Terraform, Pub/Sub, Cloud Run, and GitHub Actions for seamless integration and continuous deployment in GCP.