Observed Signal · May 13, 2026 · Technical Guide · Source: DEV Community · Impact: 1/5 · Sentiment: Neutral

Terraform CI/CD on GCP: Plan on PR, Manual Apply

Executive Signal Summary

A tutorial showing how to move Terraform execution from a local machine into GitHub Actions for GCP. The author builds two workflows: a plan workflow triggered on pull requests (runs terraform fmt, validate, plan) and a manually triggered apply workflow (requires environment approval). Authentication uses Google Workload Identity Federation (GitHub Actions OIDC -> Google provider -> service account impersonation) to avoid downloading service account JSON keys. Terraform remote state is stored in a Google Cloud Storage backend. The author documents an error caused by an empty GitHub repository variable for GCP_PROJECT_ID, how to debug it safely, and confirms a successful end-to-end run that created a VPC and subnet.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Practical how-to for cloud CI/CD and identity best practices; useful to engineers but not industry-shifting for AdTech/MarTech.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Author implemented Terraform CI/CD using GitHub Actions with separate 'plan' (on pull_request) and 'apply' (workflow_dispatch with manual approval) workflows.
  • Authentication uses Google Workload Identity Federation (GitHub Actions OIDC token) to impersonate a Google Cloud service account—no static JSON key is downloaded.
  • Terraform remote state is stored in Google Cloud Storage bucket 'terraform-gcp-learning-lab-terraform-state' with a specific prefix for the lab.
  • Plan workflow requires GitHub permission 'id-token: write' so Actions can request an OIDC token; apply workflow uses a GitHub environment configured with required approvals.
  • The author encountered and fixed an error caused by an empty GitHub repository variable (GCP_PROJECT_ID) which prevented terraform plan from receiving the project variable.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: May 13, 2026
Original Coverage Title: “CI/CD for Terraform on GCP: Plan on Pull Request, Apply with Approval, No Static Keys”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Infrastructure as CodeMay 26, 2026

Terraform Drift Detection and Recovery on Google Cloud

A developer-published lab and GitHub repository demonstrating Terraform drift detection, importing existing Google Cloud resources, and state recovery. The project uses a small baseline (VPC, subnet, firewall rule, service account) to simulate manual drift, demonstrates detection with terraform plan (including -detailed-exitcode and -refresh-only), shows terraform state inspection and terraform import for recovery, and automates scheduled drift checks via GitHub Actions. The workflow writes a GCS backend dynamically from repository variables, authenticates with Google Cloud using Workload Identity Federation (OIDC) to keep the pipeline keyless, and creates GitHub issues when drift is detected rather than auto-applying fixes. The artifact is published with documentation, scripts, example imports and CI workflows in a public GitHub repo.

Read assessment
Infrastructure as CodeMay 3, 2026

Provision a GCP VPC with Terraform

A developer tutorial that demonstrates provisioning, inspecting, and destroying a Google Cloud VPC using Terraform. The guide walks through prerequisites (macOS, VS Code, Terraform CLI v1.15.1, Google Cloud CLI, a GCP project with billing and Compute Engine API enabled), shows a sample main.tf using the HashiCorp Google provider (version 6.8.0) to create a google_compute_network named "terraform-network", and covers the full Terraform workflow: init, fmt, validate, plan, apply, inspect state (terraform.tfstate), and destroy. Authentication uses gcloud auth application-default login. The article is a step-by-step hands-on lab aimed at beginners learning Infrastructure as Code on GCP.

Read assessment
InfrastructureMay 14, 2026

Hands-On Terraform: Build AWS Infrastructure with CLI

A technical tutorial demonstrating how to use Terraform (HashiCorp) on Ubuntu to initialize and manage AWS infrastructure via the CLI. The article covers the core Terraform workflow (terraform init, plan, apply, destroy), HCL file structure, a sample .tf that creates two S3 buckets in ap-southeast-1 (using aws provider ~> 6.0), inspecting and understanding terraform.tfstate (the state file), making in-place changes via plan/apply, and cleaning up resources with terraform destroy. It emphasizes best practices such as unique global S3 bucket names and never committing or manually editing state files.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.