Chapter 9: GitHub Actions Hands-On
9.7 Deploy sketch — SSH to one lab VM
Keep this thin. You already launch and secure VMs in the AWS course — we do not rebuild VPC, DNS or EC2 launch here.
Idea only:
- Store
SSH_HOST,SSH_USER, and a private key as secrets (lab keys only; rotate). - After image push, a job SSHs to the VM and runs
docker pull … && docker compose up -d(or restart a single container with the new tag). - Curl a health URL on the VM's published shop counter.
- On failure, redeploy the previous tag.
Official community SSH actions exist; read their docs and pin versions. For early labs, many students stop at push image and pull manually once — that is still honest CI.
Security. Do not leave a world-open SSH with password auth. Use keys, tight Security Groups (AWS course), and lab-only hosts you can wipe.
Practice task
Write five shell lines you would run on a lab VM to pull badge-api:<sha> and restart the API container — no need to automate SSH yet.