Web App Automation with GCP

AboutApril 2026

15· DevOpsMaintained·Academic project

A containerized Node.js app deployed to Google Cloud Run through a GitHub Actions pipeline, with images pushed to Artifact Registry and CI authenticating as a service account scoped to exactly three roles.

webacademic projectserverless

Source ↗

Service account credentialStep 1
Generating a scoped service account's JSON key for GitHub Actions to authenticate with.
GitHub Secrets setupStep 2
Wiring the service account key and project config into the repository's secrets.
CI/CD runStep 3
The workflow building the image, pushing it to Artifact Registry, and deploying to Cloud Run.
Live verificationStep 4
The deployed Cloud Run service and a record confirmed through the app.
Write-up

A deliberately scoped exercise in doing by hand what a platform usually does for you. A containerized Node.js app is deployed to Google Cloud Run through a GitHub Actions pipeline: billing and the Cloud Run, Artifact Registry and IAM APIs enabled on a new GCP project, then a dedicated service account created and its JSON key generated for CI/CD authentication.

The part worth keeping is the access model. That service account is scoped to exactly three roles, Cloud Run Admin, Artifact Registry Writer and Service Account User, rather than borrowing broad project access, which is the difference between a leaked CI credential being an incident and being a catastrophe.

The Docker image is built, pushed to a new Artifact Registry repository, and deployed to Cloud Run on every push, with the service account key and project config held in GitHub Secrets and the Actions run log watched until the live app answered on its Cloud Run URL. Build an image, push it to a registry, deploy it on merge is the default shape of most production deployment today, and doing it once by hand is how the managed abstractions stop being magic.

Things to underline
  • Containerized a Node.js app with Docker and deployed it to Google Cloud Run
  • Automated image build, push, and deploy through a GitHub Actions CI/CD pipeline
  • Scoped a dedicated service account to exactly three IAM roles (Cloud Run Admin, Artifact Registry Writer, Service Account User) instead of broad project access
  • Authenticated GitHub Actions using a service account JSON key stored as a repository secret
Built with
JavaScriptDockerGithub ActionsGoogle Cloud Platform Cloud Run