Chapter 9: GitHub Actions Hands-On
9.11 Lab — PR tests and main image push
Lab
Automate badge API checks with GitHub Actions.
- Ensure the repo has a working local test command (
pytestornpm test). - Add
.github/workflows/ci.ymlthat runs tests onpull_requesttomain. - Open a PR; capture a screenshot or note of the green check (no PDF upload needed for the site — keep in your own notes).
- Extend the workflow (or add a second job) so that on push to
mainyoudocker buildand push an image tagged with${{ github.sha }}to GHCR or Docker Hub using secrets /GITHUB_TOKEN. - Confirm the registry shows the SHA tag.
- Optional: manually pull that tag on a lab VM and curl health (SSH automation optional).
- Verify
.envand cloud keys are not in the repo.
Practice task
Map your Chapter 8 paper pipeline to Actions: which YAML job covers lint/test, which covers build/push, and where a human approval would sit later.
Thodkyaat sangaycha tar
- Workflows live in
.github/workflows/; events start jobs on runners. - Steps use
uses:(actions) orrun:(shell); sequence jobs withneeds:. - Cache speeds deps; artifacts store reports; registries store runnable images.
- Push images with secrets /
GITHUB_TOKEN— never plain passwords in YAML. - Tag with git SHA; deploy the same tag; SSH deploy stays a thin sketch — AWS course owns VPC/EC2 depth.
- Required checks on
mainenforce quality gates.
Samajla ka? Nasel tar lab (9.11) PR green + SHA tag push paryant neuya – secrets YAML baher. Aata pudhe jaauya Jenkins intro kade.