How to deploy to a Quake AI Kubernetes cluster from CI
How to deploy to a Quake AI Kubernetes cluster from CI
Apply manifests or Helm releases from GitHub Actions or GitLab CI to a Magnum cluster. Fetch a fresh kubeconfig at job start with application credentials. Do not commit kubeconfig files to the repository.
Prerequisites
- A Magnum cluster in
CREATE_COMPLETEstate python-openstackclientandpython-magnumclientin the CI job.python-magnumclientregisters theopenstack coeplugin.- Application credentials with access to the cluster's project
kubectlin the job (and Helm, if you run the Helm workflow). GitHub-hostedubuntu-latestrunners include both. The GitLab tab installs them onpython:3.12-slim.
CI secrets for OpenStack auth#
| Secret | Maps to |
|---|---|
OS_AUTH_URL | Keystone endpoint |
OS_AUTH_TYPE | v3applicationcredential |
OS_APPLICATION_CREDENTIAL_ID | Application credential ID |
OS_APPLICATION_CREDENTIAL_SECRET | Application credential secret |
OS_REGION_NAME | Quake AI region |
OS_PROJECT_ID | Project UUID |
CLUSTER_NAME | Magnum cluster name |
See OpenTofu CI/CD secrets for the full variable set.
Workflow: kubectl apply#
name: Deploy to Kubernetes
on:
push:
branches: [main]
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Install OpenStack CLI
run: pip install python-openstackclient python-magnumclient
- name: Fetch kubeconfig
env:
OS_AUTH_URL: ${{ secrets.OS_AUTH_URL }}
OS_AUTH_TYPE: v3applicationcredential
OS_APPLICATION_CREDENTIAL_ID: ${{ secrets.OS_APPLICATION_CREDENTIAL_ID }}
OS_APPLICATION_CREDENTIAL_SECRET: ${{ secrets.OS_APPLICATION_CREDENTIAL_SECRET }}
OS_REGION_NAME: ${{ secrets.OS_REGION_NAME }}
OS_PROJECT_ID: ${{ secrets.OS_PROJECT_ID }}
run: |
openstack coe cluster config "${{ secrets.CLUSTER_NAME }}" --dir "$RUNNER_TEMP/kube"
echo "KUBECONFIG=$RUNNER_TEMP/kube/config" >> "$GITHUB_ENV"
- name: Apply manifests
run: kubectl apply -f k8s/Workflow: Helm upgrade#
After the kubeconfig step, run:
helm upgrade --install myapp ./chart \
--namespace my-namespace --create-namespace \
--set image.repository=ghcr.io/USERNAME/myapp \
--set image.tag="${CI_COMMIT_SHA}"Configure image pull secrets when the chart pulls from a private registry.
See also#
Usage Guidelines
The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.
For the full policy, see Usage Guidelines.
Last validated: 01.09.2026
Quick answers
- Why does `openstack coe cluster create` fail with a Keystone trust or unauthorized error when I use an application credential?CLIAPITerraform
- Why does a Kubernetes LoadBalancer service stay `<pending>` for several minutes?CLI
- Why does my GitHub Actions or GitLab CI job fail to run `openstack coe` or `kubectl` on a Magnum cluster?CLI
- Why does my Magnum cluster create fail with "Only volume-backed servers" or "Quota exceeded for compute_units"?CLIAPI