GitHub Actions: Build CI/CD Pipelines from Zero
Learn GitHub Actions from zero: workflows, triggers, expressions, matrix builds, secrets, Docker images, OIDC deploys and secure pipelines, with a lab.
What You'll Learn
Understanding CI/CD and Why GitHub Actions Matters
Thursday, 4:50 PM, release day at a Bengaluru fintech.
Understanding Workflows, Jobs and Runners
How do the building blocks fit together? Everything in GitHub Actions combines six ideas. An event triggers a workflow. A workflow contains jobs.
Writing Workflows and Choosing Triggers
How do you write and run your first workflow? Create the folder, add a YAML file, and push.
Using Expressions, Contexts and Outputs
What are expressions and contexts? An expression is anything inside ${{ }}. GitHub evaluates it before the step runs and substitutes the result.
Orchestrating Jobs with needs, Matrix and Services
How do you run jobs in parallel and in order? Jobs in a workflow start at the same time unless one declares needs.
Managing Variables, Secrets, Permissions and Environments
When do you use variables versus secrets?
Skills You'll Master
Curriculum Index13 topics
Understanding CI/CD and Why GitHub Actions Matters
Thursday, 4:50 PM, release day at a Bengaluru fintech.
Understanding Workflows, Jobs and Runners
How do the building blocks fit together? Everything in GitHub Actions combines six ideas. An event triggers a workflow.
Writing Workflows and Choosing Triggers
How do you write and run your first workflow? Create the folder, add a YAML file, and push.
Using Expressions, Contexts and Outputs
What are expressions and contexts? An expression is anything inside ${{ }}.
Orchestrating Jobs with needs, Matrix and Services
How do you run jobs in parallel and in order? Jobs in a workflow start at the same time unless one declares needs.
Managing Variables, Secrets, Permissions and Environments
When do you use variables versus secrets?
Speeding Up Pipelines with Caching and Artifacts
What is the difference between a cache and an artifact?
Building and Publishing Docker Images
How do you build an image and push it to GitHub Container Registry?
Deploying to the Cloud Securely with OIDC
Why is OIDC better than stored cloud keys?
Reusing Pipelines with Reusable Workflows and Composite Actions
What is a reusable workflow? A reusable workflow is a complete workflow that other workflows call like a function...
Securing Workflows Against Supply-Chain Attacks
Why are pipelines an attack target? Your pipeline holds the keys to everything: cloud credentials, registry tokens...
Building a Complete Pipeline Hands-On
What will you build in this lab? You will build a small Node.js cart service and a production-style pipeline around it.
Troubleshooting Workflows with a Quick Reference
How do you fix the most common GitHub Actions problems?
Career Impact
Roles that use the skills in this module.
DevSecOps Engineer
Platform Engineer
Cloud Engineer
DevOps Engineer
Next Modules
Related Guides
Practice on the Coding Sheet
Not a software engineer sheet. Every problem comes from real DevOps, SRE, Platform and Cloud interviews, from your first script to a system you build yourself.
Open the Coding SheetFrequently Asked Questions
Standard GitHub-hosted runners are free for public repositories. Private repositories get a monthly allowance of free minutes that depends on your plan, and Linux minutes cost the least while macOS minutes cost the most. Check GitHub's billing documentation for current numbers, because they change.
GitHub Actions is built into GitHub, runs on machines GitHub manages, and is configured with YAML files in your repository. Jenkins is a separate server you install, maintain and secure yourself, configured with Jenkinsfiles and plugins. Actions is faster to start; Jenkins gives more control at the cost of upkeep.
Avoid it when you can. Use OIDC instead: the workflow requests a short-lived token at run time and AWS exchanges it for temporary credentials, so there are no long-lived keys to leak or rotate. Store keys as secrets only for systems that do not support OIDC.
A red check alone does not block anything. Add a branch ruleset or branch protection rule on main that requires your CI jobs as status checks. GitHub then disables the merge button until those checks pass.