infra/.
- Provision a GCP project, billing, Terraform state bucket, and GitHub Actions Workload Identity Federation.
- Configure Terraform inputs and store each runtime secret value in its own Secret Manager secret.
- Apply the environment with Terraform, or deploy through protected GitHub
devandprodenvironments. - Point your domain at the provisioned load balancer and register the app URL with GitHub OAuth.
gke_workers to true in the deployment inputs to use the primary worker architecture; the Cloud Run worker pool is the fallback. For a local stack, see the Development section of the README.