Skip to main content

GitHub Actions: Build CI/CD Pipelines from Zero

Learn GitHub Actions from zero: workflows, triggers, expressions, matrix builds, secrets, Docker images, OIDC deploys and secure pipelines, with a lab.

~3 hours
13 Topics
Hands-on Scenarios

What You'll Learn

Understanding CI/CD and Why GitHub Actions Matters

Thursday, 4:50 PM, release day at a Bengaluru fintech.

Understanding Workflows, Jobs and Runners

How do the building blocks fit together? Everything in GitHub Actions combines six ideas. An event triggers a workflow. A workflow contains jobs.

Writing Workflows and Choosing Triggers

How do you write and run your first workflow? Create the folder, add a YAML file, and push.

Using Expressions, Contexts and Outputs

What are expressions and contexts? An expression is anything inside ${{ }}. GitHub evaluates it before the step runs and substitutes the result.

Orchestrating Jobs with needs, Matrix and Services

How do you run jobs in parallel and in order? Jobs in a workflow start at the same time unless one declares needs.

Managing Variables, Secrets, Permissions and Environments

When do you use variables versus secrets?

Skills You'll Master

GITHUB-ACTIONSCI-CDWORKFLOWSAUTOMATIONDEVSECOPSOIDC

Curriculum Index13 topics

1

Understanding CI/CD and Why GitHub Actions Matters

Thursday, 4:50 PM, release day at a Bengaluru fintech.

2

Understanding Workflows, Jobs and Runners

How do the building blocks fit together? Everything in GitHub Actions combines six ideas. An event triggers a workflow.

3

Writing Workflows and Choosing Triggers

How do you write and run your first workflow? Create the folder, add a YAML file, and push.

4

Using Expressions, Contexts and Outputs

What are expressions and contexts? An expression is anything inside ${{ }}.

5

Orchestrating Jobs with needs, Matrix and Services

How do you run jobs in parallel and in order? Jobs in a workflow start at the same time unless one declares needs.

6

Managing Variables, Secrets, Permissions and Environments

When do you use variables versus secrets?

7

Speeding Up Pipelines with Caching and Artifacts

What is the difference between a cache and an artifact?

8

Building and Publishing Docker Images

How do you build an image and push it to GitHub Container Registry?

9

Deploying to the Cloud Securely with OIDC

Why is OIDC better than stored cloud keys?

10

Reusing Pipelines with Reusable Workflows and Composite Actions

What is a reusable workflow? A reusable workflow is a complete workflow that other workflows call like a function...

11

Securing Workflows Against Supply-Chain Attacks

Why are pipelines an attack target? Your pipeline holds the keys to everything: cloud credentials, registry tokens...

12

Building a Complete Pipeline Hands-On

What will you build in this lab? You will build a small Node.js cart service and a production-style pipeline around it.

13

Troubleshooting Workflows with a Quick Reference

How do you fix the most common GitHub Actions problems?

Career Impact

Roles that use the skills in this module.

  • DevSecOps Engineer

  • Platform Engineer

  • Cloud Engineer

  • DevOps Engineer

See how this is asked in interviews

Practice on the Coding Sheet

Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.

Open the Coding Sheet

Frequently Asked Questions

Standard GitHub-hosted runners are free for public repositories. Private repositories get a monthly allowance of free minutes that depends on your plan, and Linux minutes cost the least while macOS minutes cost the most. Check GitHub's billing documentation for current numbers, because they change.

GitHub Actions is built into GitHub, runs on machines GitHub manages, and is configured with YAML files in your repository. Jenkins is a separate server you install, maintain and secure yourself, configured with Jenkinsfiles and plugins. Actions is faster to start; Jenkins gives more control at the cost of upkeep.

Avoid it when you can. Use OIDC instead: the workflow requests a short-lived token at run time and AWS exchanges it for temporary credentials, so there are no long-lived keys to leak or rotate. Store keys as secrets only for systems that do not support OIDC.

A red check alone does not block anything. Add a branch ruleset or branch protection rule on main that requires your CI jobs as status checks. GitHub then disables the merge button until those checks pass.