Skip to content

Commit 4652db3

Browse files
fix(deploy): do not allow public access to prod
1 parent 1e27601 commit 4652db3

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

.github/workflows/sub-cloudrun-deploy.yml

+3-2
Original file line numberDiff line numberDiff line change
@@ -118,10 +118,11 @@ jobs:
118118
--set-cloudsql-instances=${{ vars.CLOUDSQL_INSTANCE }}
119119
--add-volume=name=files,type=in-memory
120120
--add-volume-mount=volume=files,mount-path=/app/data
121-
--network=projects/zfnd-dev-net-spoke-0/global/networks/dev-spoke-0
122-
--subnet=projects/zfnd-dev-net-spoke-0/regions/us-east1/subnetworks/dev-default-ue1
121+
--network=${{ vars.GCP_NETWORK }}
122+
--subnet=${{ vars.GCP_SUBNETWORK }}
123123
124124
- name: Allow unauthenticated calls to the service
125+
if: ${{ inputs.environment != 'prod' }}
125126
run: |
126127
gcloud run services add-iam-policy-binding ${{ inputs.app_name }}-${{ needs.versioning.outputs.version || env.GITHUB_HEAD_REF_SLUG || inputs.environment }} \
127128
--region=${{ inputs.region }} --member=allUsers --role=roles/run.invoker --quiet

0 commit comments

Comments
 (0)