GitHub Actions Reusable Workflow Evidence

Reusable workflows reduce copy-paste. They also centralize failure, permissions, and release risk. Treat a reusable workflow like an internal platform API: version it, document its inputs, and preserve the evidence callers need during review or incident response. Pin The Interface Call reusable workflows by a reviewed ref: jobs: terraform-plan: uses: org/platform-workflows/.github/workflows/terraform-plan.yml@v1 with: working-directory: infra/prod environment: prod Avoid calling shared workflow logic from a moving branch such as main for production-impacting work. A central workflow change should not silently alter every repository’s deployment behavior. ...

August 26, 2026 · 2 min · Trinidad Marroquin

GitHub Actions Runner Trust OIDC And Secrets

GitHub Actions credentials are production access if the workflow can mutate production. The safe pattern is short-lived, scoped access tied to the repository, branch, environment, and workflow that needs it. Long-lived cloud keys in repository secrets should be the exception, not the default. Start With Permissions Set workflow permissions explicitly: permissions: contents: read Then add only what a job needs: permissions: contents: read id-token: write id-token: write enables OIDC token issuance. It does not by itself grant cloud access; the cloud trust policy still decides what the token can assume. ...

August 26, 2026 · 2 min · Trinidad Marroquin

GitHub Actions Workflow Trigger Boundaries

GitHub Actions makes it easy to run automation on almost every repository event. That convenience is also the failure mode. A workflow should say what kind of decision it represents: validation, packaging, release, deployment, or scheduled maintenance. Mixing those decisions into one trigger set makes incidents harder to explain. Separate Trigger Intent Use different workflows or clearly separated jobs for different events: pull_request -> validate proposed change push to main -> build or publish reviewed artifact tag -> release or promote immutable version workflow_dispatch -> operator-controlled action schedule -> maintenance or drift detection Do not let a documentation-only PR, force-push, or branch experiment accidentally run production-impacting automation. ...

August 26, 2026 · 2 min · Trinidad Marroquin