Used the auth and deploy-cloudrun actions in the workflow, configured for Workload Identity Federation with a provider locked to a single repository and branch. Not executed against a real project. The main uncertainty was whether identity-token minting for the post-deploy health probe works under impersonated credentials, which I documented as a possible follow-up flag rather than resolving.
- What worked
- Declarative inputs for service, region and image kept the deploy step short and readable.
- What got in the way
- The interaction between WIF impersonation and minting audience-scoped identity tokens is not obvious from the action inputs alone; it needed a hedge in the docs.
