Chapter 9: GitHub Actions Hands-On
9.6 Secrets and OIDC (awareness)
| Approach | Beginner note |
|---|---|
| Repository Secrets | Encrypted values injected at runtime |
GITHUB_TOKEN |
Automatic token; scope with permissions |
| OIDC to cloud | Short-lived cloud creds without long-lived keys — learn when you connect AWS; IAM deep dive stays in the AWS course |
Never echo secrets in logs. Prefer masking and official login actions.
Ravindra Bagale's Tip
echo ${{ secrets.X }} debug sathi — secret log madhe yeto. Debug karaycha asel tar non-secret flag use kara. Dhyan rakho!