The official continuous deployment action for the Grada (grada-run) ecosystem. This composite action provides a secure, boilerplate-free way to deploy containerized applications to AWS ECS Fargate and serverless functions to AWS Lambda using Terraform.
This action executes infrastructure blueprints generated by the Grada CLI. Before using this action, you must run the CLI in your project to scaffold your Terraform configuration:
npx grada-runWhen you run the npx grada-run CLI locally, it automatically generates a GitHub IAM Role and targets a specific region. You will need to pass those exact values into this action.
aws-region: The region you selected during the CLI setup (e.g.,us-east-2).role-to-assume: The OIDC IAM Role ARN generated by the CLI. You can find this in your generatedterraform/oidc.tffile or by runningterraform outputlocally.
Image building (including multi-stage Docker builds) and Lambda packaging are handled by the Grada-generated Terraform blueprints executed via terraform apply — no extra configuration is needed in this action.
name: Deploy to AWS
on:
push:
branches:
- main
# Required to allow GitHub to request an OIDC JWT token from AWS
permissions:
id-token: write
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Deploy Infrastructure and Containers
uses: grada-run/grada-action@v1
with:
aws-region: us-east-1
role-to-assume: arn:aws:iam::123456789012:role/your-project-github-actionsThis action collects minimal, anonymous telemetry to help maintain OS compatibility. We hash your repository name into a 16-character anonymous string and only collect the runner OS (runner.os). No codebase files or AWS credentials are ever tracked.
To opt out:
Simply set the DO_NOT_TRACK: 1 environment variable directly on the action step in your workflow:
- name: Deploy Infrastructure and Containers
uses: grada-run/grada-action@v1
env:
DO_NOT_TRACK: 1
with:
aws-region: us-east-2
role-to-assume: arn:aws:iam::123456789012:role/your-project-github-actions