Skip to content

How to deploy to a Quake AI Kubernetes cluster from CI

How-to · Updated Sep 2026

How to deploy to a Quake AI Kubernetes cluster from CI

Apply manifests or Helm releases from GitHub Actions or GitLab CI to a Magnum cluster. Fetch a fresh kubeconfig at job start with application credentials. Do not commit kubeconfig files to the repository.

Prerequisites
  • A Magnum cluster in CREATE_COMPLETE state
  • python-openstackclient and python-magnumclient in the CI job. python-magnumclient registers the openstack coe plugin.
  • Application credentials with access to the cluster's project
  • kubectl in the job (and Helm, if you run the Helm workflow). GitHub-hosted ubuntu-latest runners include both. The GitLab tab installs them on python:3.12-slim.

CI secrets for OpenStack auth#

SecretMaps to
OS_AUTH_URLKeystone endpoint
OS_AUTH_TYPEv3applicationcredential
OS_APPLICATION_CREDENTIAL_IDApplication credential ID
OS_APPLICATION_CREDENTIAL_SECRETApplication credential secret
OS_REGION_NAMEQuake AI region
OS_PROJECT_IDProject UUID
CLUSTER_NAMEMagnum cluster name

See OpenTofu CI/CD secrets for the full variable set.

Workflow: kubectl apply#

YAML
name: Deploy to Kubernetes
on:
  push:
    branches: [main]

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - name: Install OpenStack CLI
        run: pip install python-openstackclient python-magnumclient
      - name: Fetch kubeconfig
        env:
          OS_AUTH_URL: ${{ secrets.OS_AUTH_URL }}
          OS_AUTH_TYPE: v3applicationcredential
          OS_APPLICATION_CREDENTIAL_ID: ${{ secrets.OS_APPLICATION_CREDENTIAL_ID }}
          OS_APPLICATION_CREDENTIAL_SECRET: ${{ secrets.OS_APPLICATION_CREDENTIAL_SECRET }}
          OS_REGION_NAME: ${{ secrets.OS_REGION_NAME }}
          OS_PROJECT_ID: ${{ secrets.OS_PROJECT_ID }}
        run: |
          openstack coe cluster config "${{ secrets.CLUSTER_NAME }}" --dir "$RUNNER_TEMP/kube"
          echo "KUBECONFIG=$RUNNER_TEMP/kube/config" >> "$GITHUB_ENV"
      - name: Apply manifests
        run: kubectl apply -f k8s/

Workflow: Helm upgrade#

After the kubeconfig step, run:

bash
helm upgrade --install myapp ./chart \
  --namespace my-namespace --create-namespace \
  --set image.repository=ghcr.io/USERNAME/myapp \
  --set image.tag="${CI_COMMIT_SHA}"

Configure image pull secrets when the chart pulls from a private registry.

See also#

Usage Guidelines

The sample code, software libraries, command line tools, proofs of concept, templates, and other related technology on this page (including any of the foregoing that is provided by Quake AI personnel) is provided to you as Quake AI Content under the Quake AI Customer Agreement, or the relevant written agreement between you and Quake AI (whichever applies). Do not use this Quake AI Content in your production accounts, or on production or other critical data. You are responsible for testing, securing, and optimizing the Quake AI Content (such as sample code) as appropriate for production grade use based on your specific quality control practices and standards. Deploying Quake AI Content may incur Quake AI charges for creating or using Quake AI chargeable resources, such as running Compute instances or storing data in Object Storage. Your use is also subject to the Acceptable Use Policy.

For the full policy, see Usage Guidelines.

Last validated: 01.09.2026

Quick answers

Was this page helpful?