This GitHub repository is managed by Cloud Ops Works LLC and contains a comprehensive collection of GitHub Actions and workflows. The primary goal of this repository is to streamline and automate the deployment of infrastructure and applications. Whether you're deploying cloud resources or applications, these blueprints can help you achieve a higher level of automation and efficiency in your CI/CD pipelines.
This project is part of our comprehensive approach towards DevOps Acceleration.
It's 100% Open Source and licensed under the APACHE2.
The Cloud Ops Works Blueprints works along with GitHub Secrets and Variables, they should be declared preferably at organization level, and then used in the workflows. This way, the secrets and variables are not exposed in the workflows and can be managed centrally.
<style> table th { background: grey; text-align: center; color: ghostwhite; } </style>Required GitHub Secrets and Variables, in the below table:
| Name | Type | Description | Required |
|---|---|---|---|
| Dependency track | |||
| DEPENDENCYTRACK_TOKEN | Secret | Dependency track token | Yes |
| DEPENDENCYTRACK_URL | Variable | Dependency track URL | Yes |
| SonarQube | |||
| SONARQUBE_TOKEN | Secret | SonarQube token | Yes |
| SONARQUBE_URL | Variable | SonarQube URL | Yes |
| Semgrep | |||
| SEMGREP_TOKEN | Secret | Semgrep token | Yes |
| Snyk | |||
| SNYK_TOKEN | Secret | Snyk token | Yes |
| GitHub | |||
| BOT_TOKEN | Secret | GitHub token | Yes |
| BOT_USER | Variable | GitHub user for commits | Yes |
| BOT_EMAIL | Variable | GitHub email for commits | Yes |
| BOT_TOKEN_SCOPED | Secret | GitHub token with repo scope, this Token is a Fine-Grained Token | Yes |
| AWS | - AWS Based Resources | ||
| BUILD_AWS_ACCESS_KEY_ID | Secret | AWS Access Key ID, used for builds (ECR deploy, Repositories) | Yes |
| BUILD_AWS_SECRET_ACCESS_KEY | Secret | AWS Secret Access Key | Yes |
| BUILD_AWS_REGION | Variable | AWS Region | Yes |
| BUILD_AWS_STS_ROLE_ARN | Variable | AWS STS Role ARN, Only needded if all actions are performed throug STS Assume Role | No |
| DEPLOYMENT_STATE_CONF | Variable | Deployment State Configuration, This is a YAML representation of Terraform Remote state configuration | No |
| DEPLOYMENT_AWS_REGION | Variable | Default AWS Region used for deployments | Yes |
| DEPLOYMENT_AWS_STS_ROLE_ARN | Variable | Default AWS STS Role ARN, Only needded if all actions are performed throug STS Assume Role | No |
| DEPLOYMENT_AWS_ACCESS_KEY_ID | Secret | AWS Access Key ID used for deployments | Yes |
| DEPLOYMENT_AWS_SECRET_ACCESS_KEY | Secret | AWS Secret Access Key used for deployments | Yes |
| PREVIEW_AWS_REGION | Variable | AWS Region used for preview deployments, defaults to us-east-1 |
Yes |
| PREVIEW_AWS_STS_ROLE_ARN | Variable | AWS STS Role ARN, Only needded if all actions are performed throug STS Assume Role | No |
| PREVIEW_AWS_ACCESS_KEY_ID | Secret | AWS Access Key ID used for preview deployments | Yes |
| PREVIEW_AWS_SECRET_ACCESS_KEY | Secret | AWS Secret Access Key used for preview deployments | Yes |
| Azure | - Azure Based Resources | ||
| BUILD_AZURE_SERVICE_ID | Secret | Azure Client ID used for Build | Yes |
| BUILD_AZURE_SERVICE_SECRET | Secret | Azure Client Secret used for Builds | Yes |
| BUILD_AZURE_RESOURCE_GROUP | Variable | Default Azure Resource Group used for Builds | Yes |
| DEPLOYMENT_AZURE_SERVICE_ID | Secret | Azure Client ID used for deployments | Yes |
| DEPLOYMENT_AZURE_SERVICE_SECRET | Secret | Azure Client Secret used for deployments | Yes |
| DEPLOYMENT_AZURE_RESOURCE_GROUP | Variable | Default Azure Resource Group used for deployments | Yes |
| PREVIEW_AZURE_SERVICE_ID | Secret | Azure Client ID used for preview deployments | Yes |
| PREVIEW_AZURE_SERVICE_SECRET | Secret | Azure Client Secret used for preview deployments | Yes |
| PREVIEW_AZURE_RESOURCE_GROUP | Variable | Default Azure Resource Group used for preview deployments | Yes |
| Google Cloud | - Google Cloud Based Resources | ||
| BUILD_GCP_CREDENTIALS | Secret | Google Cloud Platform Credentials JSON for builds (JSON with newlines stripped) | Yes |
| DEPLOY_GCP_CREDENTIALS | Secret | Google Cloud Platform Credentials JSON for deployments (JSON with newlines stripped) | Yes |
| PREVIEW_GCP_CREDENTIALS | Secret | Google Cloud Platform Credentials JSON for previews (JSON with newlines stripped) | Yes |
| Independent of Provider | |||
| PREVIEW_DOCKER_REGISTRY_ADDRESS | Variable | Docker Registry Address for preview deployments | Yes |
| DOCKER_REGISTRY_ADDRESS | Variable | Default Docker Registry Address for deployments | Yes |
| DEPLOYMENT_RUNNER_SET | Variable | Default Runner set for deployment, used to identify the runner set for deployment, can be overriden at pipeline, defaults to ubuntu-latest |
No |
| PREVIEW_RUNNER_SET | Variable | Default Runner set for preview deployments, used to identify the runner set for preview deployments, defaults to ubuntu-latest |
No |
| AI Patching Management | - Supported by Patchwork | ||
| PATCHWORK_ENABLED | Variable | Enable / Disable Patchwork AI Patching features, defaults to false |
No |
| OPENAI_API_KEY | Secret | OpenAI API KEY or Hosted LLM API Key for the provided URL. | No |
| LIBRARIES_IO_API_KEY | Secret | libraries.io API KEY, if set the DependencyUpgrade process will set analyze_impact=true | No |
| PATCHED_CODES_TOKEN | Secret | Patched Codes Token, if set the AutoFix and DependencyUpgrade processes will use the SAAS service at https://www.patched.codes/ | No |
| HOSTED_LLM_BASE_URL | Variable | Hosted LLMs Local or remote different from OpenAI's provided, if this is set, HOSTED_LLM_MODEL must be set. | No |
| HOSTED_LLM_MODEL | Variable | Hosted LLM Local or Remote Model, can be used also to change default OpenAI's Model used in actions. | No |
| JIRA Integration | |||
| JIRA_INTEGRATION_ENABLED | Variable | Enable / Disable JIRA Integration for Release Management | No |
| JIRA_INTEGRATION_API_USER | Variable | JIRA API User for JIRA Integration | No |
| JIRA_INTEGRATION_API_TOKEN | Secret | JIRA API Token for Integration | No |
| JIRA_INTEGRATION_CLOUD_DOMAIN | Variable | Atlassian Custom Cloud Domain for the project | No |
| JIRA_INTEGRATION_DEFAULT_PROJECT_ID | Variable | JIRA Project ID (numbers) to set as default Project ID | No |
| JIRA_INTEGRATION_DEFAULT_PROJECT_KEY | Variable | JIRA Project Key (string) to set as default Project Key on commit filtering | No |
| HOOP Integration | |||
| HOOP_INTEGRATION_API_KEY | Secret | HOOP.dev API Key for integration of HOOP enabled workflows | |
| HOOP_INTEGRATION_API_URL | Variable | HOOP.dev API URL for integration of HOOP enabled workflows, defaults to https://api.hoop.dev | |
| Apple / macOS Code Signing | - Required for Go release actions targeting macOS with code signing and notarization | ||
| XCODE_BUILD_CERTIFICATE_BASE64 | Secret | Apple Developer certificate (P12) encoded in base64, used for macOS binary signing | No |
| XCODE_BUILD_CERTIFICATE_PASS | Secret | Passphrase for the Apple Developer certificate | No |
| APPLE_STORE_CONNECT_KEY_BASE64 | Secret | Apple Store Connect API key encoded in base64, used for notarization | No |
| APPLE_STORE_CONNECT_KEY_ID | Secret | Apple Store Connect API key ID | No |
| APPLE_STORE_CONNECT_ISSUER_ID | Secret | Apple Store Connect issuer ID | No |
Got a question? We got answers.
File a GitHub issue, send us an email or join our Slack Community.
Our Products CI/CD Blueprint Open Source
Please use the issue tracker to report any bugs or file feature requests.
Copyright © 2024-2026 Cloud Ops Works LLC
See LICENSE for full details.
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
https://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
All other trademarks referenced herein are the property of their respective owners.
This project is maintained by Cloud Ops Works LLC.
![]() Cristian Beraha |
|---|



