Skip to main content

GitHub Repository Secrets & Variables Configuration

This document lists all required secrets and variables needed for CI/CD workflows.

Overview

The MCP Server LangGraph project uses GitHub Actions for CI/CD automation. To enable full functionality, you need to configure repository secrets (sensitive data) and variables (non-sensitive configuration). Configuration Location: SettingsSecrets and variablesActions

Required Repository Variables

Configure these under SettingsSecrets and variablesActionsVariables tab.

GCP Project Configuration

GKE Cluster Configuration

Namespace Configuration


Required Repository Secrets

Configure these under SettingsSecrets and variablesActionsSecrets tab.

GCP Authentication (Workload Identity Federation)

Example Values:

Publishing & Distribution

Notifications

Auto-Provided Secrets

These secrets are automatically provided by GitHub Actions (no configuration needed):

Setup Instructions

1. Configure GCP Workload Identity Federation

Before setting secrets, set up Workload Identity Federation in your GCP project:

2. Configure GitHub Secrets

Navigate to your repository: SettingsSecrets and variablesActions

Add Variables:

  1. Click Variables tab
  2. Click New repository variable
  3. Add each variable from the tables above
  4. Click Add variable

Add Secrets:

  1. Click Secrets tab
  2. Click New repository secret
  3. Add each secret from the tables above
  4. Click Add secret

3. Verify Configuration

Run this workflow manually to test authentication:
Or use the GitHub CLI:

Workflow-Specific Requirements

Deployment Workflows

Required for:
  • deploy-preview-gke.yaml
  • deploy-production-gke.yaml
Secrets/Variables:
  • GCP_PROJECT_ID (variable)
  • GCP_REGION (variable)
  • GCP_WIF_PROVIDER (secret)
  • GCP_STAGING_SA_EMAIL or GCP_PRODUCTION_SA_EMAIL (secret)

Compliance & Security Scanning

Required for:
  • gcp-compliance-scan.yaml
  • security-scan.yaml
Secrets/Variables:
  • GCP_PROJECT_ID (variable)
  • PROJECT_NUMBER (variable)
  • GCP_WIF_PROVIDER (secret)
  • SLACK_SECURITY_WEBHOOK (secret, optional for notifications)

Drift Detection

Required for:
  • gcp-drift-detection.yaml
Secrets/Variables:
  • GCP_PROJECT_ID (variable)
  • GCP_WIF_PROVIDER (secret)

Release & Publishing

Required for:
  • release.yaml
Secrets:
  • PYPI_TOKEN (required for PyPI publishing)
  • SLACK_WEBHOOK (optional for notifications)
  • MCP_REGISTRY_TOKEN (optional for MCP registry)

Security Best Practices

✅ DO:

  • Rotate secrets regularly (recommended: every 90 days)
  • Use least-privilege IAM roles for service accounts
  • Enable audit logging for service account usage
  • Review secret access periodically
  • Use environment-specific service accounts (separate staging/production)

❌ DON’T:

  • Never commit secrets to git (use .gitignore)
  • Never share secrets in plain text (Slack, email, etc.)
  • Never use production credentials in non-production workflows
  • Never grant overly broad permissions to service accounts

Troubleshooting

Authentication Failures

Error: Failed to authenticate to Google Cloud Solution:
  1. Verify GCP_WIF_PROVIDER secret is correctly set
  2. Verify service account email is correctly set
  3. Check workload identity binding:
  4. Verify repository attribute in workload identity condition matches your repo

Missing Secrets/Variables

Error: The secret 'GCP_WIF_PROVIDER' was not found Solution:
  1. Go to SettingsSecrets and variablesActions
  2. Verify secret exists in Secrets tab
  3. Check spelling matches exactly (case-sensitive)
  4. Re-create secret if needed

Permission Denied Errors

Error: Permission denied when accessing GCP resources Solution:
  1. Verify service account has required IAM roles:
  2. Grant necessary roles:

Migration Guide

Migrating from Hardcoded Values

If you’re migrating from workflows with hardcoded project IDs:
  1. Extract current values from workflows:
  2. Create variables with those values as defaults (already done in updated workflows)
  3. Add secrets for sensitive data (WIF provider, service account emails)
  4. Test workflows in a non-production environment first
  5. Update production after successful testing

Fallback Behavior

All updated workflows include fallback defaults:
  • If variables/secrets are not set, workflows use the default hardcoded values
  • This ensures backward compatibility during migration
  • Remove fallbacks after confirming configuration works
Example:

Support

For issues or questions:
Last Updated: 2025-11-03 Version: 1.0 Maintained By: DevOps Team