Discover Packages
github.com/chainguard-dev/terraform-infra-common
modules
github-bots
directory
Version:
v1.57.0
Opens a new window with list of versions in this module.
Published: Oct 7, 2026
License: Apache-2.0
Opens a new window with license information.
README
README
¶
github-bots
This Terraform module deploys a regional GitHub bot service and subscribes it to a GitHub event type through a CloudEvents broker. It creates a service account unless you provide service_account_email, and it adds a Cloud Monitoring dashboard.
Supply the project, region network settings, broker topics, container source, GitHub event type, and notification channels. See the module inputs for the current contract and the module implementation for the resources it creates. The SDK under sdk/ contains helpers for bot handlers.
Requirements
No requirements.
Providers
Modules
Resources
Name
Description
Type
Default
Required
broker
A map from each of the input region names to the name of the Broker topic in that region.
map(string)
n/a
yes
containers
The containers to run in the service. Each container will be run in each region.
map(object({ source = object({ base_image = optional(string, "cgr.dev/chainguard/static:latest-glibc@sha256:bf639cba19ba56329e6907ac26a7afcdde57a80b6aa66d5100da6883196e6b82") working_dir = string importpath = string }) args = optional(list(string), []) ports = optional(list(object({ name = optional(string, "http1") container_port = optional(number, 8080) })), []) resources = optional( object( { limits = optional(object( { cpu = string memory = string } ), null) cpu_idle = optional(bool, true) startup_cpu_boost = optional(bool, true) } ), { cpu_idle = true } ) env = optional(list(object({ name = string value = optional(string) value_source = optional(object({ secret_key_ref = object({ secret = string version = string }) }), null) })), []) regional-env = optional(list(object({ name = string value = map(string) })), []) volume_mounts = optional(list(object({ name = string mount_path = string })), []) }))
n/a
yes
deletion_protection
Whether to enable delete protection for the service.
bool
true
no
enable_observability_iam
Whether this module grants the service account the observability roles (monitoring.metricWriter, cloudtrace.agent, cloudprofiler.agent) on the project. Set false when the caller manages these grants itself, e.g. a service account shared across multiple services, where per-service grants would create overlapping non-authoritative IAM members that revoke each other on destroy.
bool
true
no
enable_profiler
Enable cloud profiler.
bool
false
no
extra_filter
Optional additional filters to include.
map(string)
{}
no
extra_filter_has_attributes
Optional additional attributes to check for presence.
list(string)
[]
no
extra_filter_not_has_attributes
Optional additional prefixes to check for presence.
list(string)
[]
no
extra_filter_prefix
Optional additional prefixes for filtering events.
map(string)
{}
no
github-event
The GitHub event type to subscribe to.
string
n/a
yes
labels
Labels to apply to the service.
map(string)
{}
no
launch_stage
The launch stage of the Cloud Run service (e.g. BETA to leverage features like disk volumes).
string
"GA"
no
name
The name of the bot.
string
n/a
yes
notification_channels
List of notification channels to alert.
list(string)
n/a
yes
observability_role
Fully-qualified id of a single role (e.g. from the observability-role module) to grant the service account in place of the three built-in observability roles (monitoring.metricWriter, cloudtrace.agent, cloudprofiler.agent). Collapsing to one role keeps large projects under the 1,500-member IAM policy limit.
string
null
no
product
Product label to apply to the service.
string
"unknown"
no
project_id
Project ID to create resources in.
string
n/a
yes
raw_filter
Raw PubSub filter to apply, ignores other variables. https://cloud.google.com/pubsub/docs/subscription-message-filter#filtering_syntax
string
""
no
regions
A map from region names to a network and subnetwork.
map(object({ network = string subnet = string }))
n/a
yes
resource_manager_tags
Resource Manager tags forwarded to this module's taggable resources, as tagKeys/ => tagValues/.
map(string)
{}
no
service_account_email
The email of the service account being authorized to invoke the private Cloud Run service. If empty, a service account will be created and used.
string
""
no
team
Team label to apply to resources (replaces deprecated 'squad').
string
n/a
yes
Outputs
Expand ▾
Collapse ▴
Directories
¶
Package sdk provides a framework for building GitHub bots that receive and handle GitHub webhook events delivered as CloudEvents.
Package sdk provides a framework for building GitHub bots that receive and handle GitHub webhook events delivered as CloudEvents.
check
Package check provides utilities for creating and updating GitHub Check Runs.
Package check provides utilities for creating and updating GitHub Check Runs.
octosts
Package octosts provides utilities for working with OctoSTS bot users.
Package octosts provides utilities for working with OctoSTS bot users.
Click to show internal directories.
Click to hide internal directories.