{"id":78742,"date":"2026-09-26T04:25:36","date_gmt":"2026-09-26T04:25:36","guid":{"rendered":"https:\/\/www.devopsschool.com\/blog\/?p=78742"},"modified":"2026-09-26T04:25:39","modified_gmt":"2026-09-26T04:25:39","slug":"github-actions-ci-cd-automation-devops-engineering","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/blog\/github-actions-ci-cd-automation-devops-engineering\/","title":{"rendered":"GitHub Actions \u2014 CI\/CD Automation &amp; DevOps Engineering"},"content":{"rendered":"\n<h3 class=\"wp-block-heading\">Course Duration<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2 Days | 16 Hours<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Format:<\/strong> Instructor-Led Training + Hands-on Labs + Real-World CI\/CD Project<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Offered By<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DevOpsSchool<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Website:<\/strong> <a href=\"https:\/\/www.devopsschool.com\/?utm_source=chatgpt.com\">DevOpsSchool<\/a><\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h3 class=\"wp-block-heading\">GitHub Actions \u2014 CI\/CD Automation &amp; DevOps Engineering<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Duration:<\/strong> 2 Days<br><strong>Level:<\/strong> Beginner to Advanced<br><strong>Format:<\/strong> Instructor-Led + Hands-on<br><strong>Mode:<\/strong> Online \/ Classroom<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Learn how to design, implement, secure and troubleshoot CI\/CD pipelines using <a href=\"https:\/\/www.devopsschool.com\/courses\/github\/\" data-type=\"link\" data-id=\"https:\/\/www.devopsschool.com\/courses\/github\/\">GitHub Actions<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">You Will Learn<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Actions fundamentals<\/li>\n\n\n\n<li>Workflow YAML<\/li>\n\n\n\n<li>Events &amp; triggers<\/li>\n\n\n\n<li>Jobs &amp; dependencies<\/li>\n\n\n\n<li>Runners<\/li>\n\n\n\n<li>Variables &amp; contexts<\/li>\n\n\n\n<li>Expressions<\/li>\n\n\n\n<li>Secrets &amp; GITHUB_TOKEN<\/li>\n\n\n\n<li>Matrix builds<\/li>\n\n\n\n<li>Caching &amp; artifacts<\/li>\n\n\n\n<li>Reusable workflows<\/li>\n\n\n\n<li>Environments &amp; approvals<\/li>\n\n\n\n<li>Docker CI\/CD<\/li>\n\n\n\n<li>GitHub Actions security<\/li>\n\n\n\n<li>AWS OIDC<\/li>\n\n\n\n<li>Kubernetes deployments<\/li>\n\n\n\n<li>Terraform automation<\/li>\n\n\n\n<li>CI\/CD troubleshooting<\/li>\n\n\n\n<li>Performance &amp; cost optimization<\/li>\n\n\n\n<li>Production CI\/CD best practices<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Project<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build a production-style:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>GitHub \u2192 Actions \u2192 Test \u2192 Security \u2192 Docker \u2192 Registry \u2192 Staging \u2192 Approval \u2192 Production \u2192 Verification<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">pipeline.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Ideal for:<\/strong> DevOps Engineers, SREs, Cloud Engineers, Platform Engineers, Developers, Automation Engineers and CI\/CD professionals.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This structure gives DevOpsSchool a <strong>credible 2-day commercial course offering<\/strong> while preserving the breadth of your original GitHub Actions curriculum and concentrating the actual classroom time on skills participants can implement immedia<\/p>\n\n\n\n<h1 class=\"wp-block-heading\">1. Course Overview<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">GitHub Actions is a GitHub-native automation and CI\/CD platform that enables development and DevOps teams to automate software build, test, security, packaging and deployment workflows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This 2-day practical course is designed to take participants from <strong>GitHub Actions fundamentals to production-grade CI\/CD implementation<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The course focuses on:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflow creation<\/li>\n\n\n\n<li>YAML configuration<\/li>\n\n\n\n<li>Events and triggers<\/li>\n\n\n\n<li>Jobs and steps<\/li>\n\n\n\n<li>GitHub-hosted runners<\/li>\n\n\n\n<li>Environment variables and secrets<\/li>\n\n\n\n<li>Expressions and contexts<\/li>\n\n\n\n<li>Matrix builds<\/li>\n\n\n\n<li>Caching<\/li>\n\n\n\n<li>Artifacts<\/li>\n\n\n\n<li>Reusable workflows<\/li>\n\n\n\n<li>CI\/CD pipeline design<\/li>\n\n\n\n<li>Docker-based CI\/CD<\/li>\n\n\n\n<li>Security hardening<\/li>\n\n\n\n<li>GitHub environments<\/li>\n\n\n\n<li>AWS OIDC authentication<\/li>\n\n\n\n<li>Kubernetes deployment concepts<\/li>\n\n\n\n<li>Terraform automation<\/li>\n\n\n\n<li>Troubleshooting<\/li>\n\n\n\n<li>Production CI\/CD best practices<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The underlying topic structure is derived from the supplied GitHub Actions reference curriculum, which covers workflow syntax, triggers, jobs, steps, runners, variables, contexts, expressions, secrets, tokens, matrices, caching, artifacts and concurrency.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">2. Who Should Attend<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This course is suitable for:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DevOps Engineers<\/li>\n\n\n\n<li>SRE Engineers<\/li>\n\n\n\n<li>Cloud Engineers<\/li>\n\n\n\n<li>Platform Engineers<\/li>\n\n\n\n<li>Software Developers<\/li>\n\n\n\n<li>Software Engineers<\/li>\n\n\n\n<li>Build &amp; Release Engineers<\/li>\n\n\n\n<li>CI\/CD Engineers<\/li>\n\n\n\n<li>Automation Engineers<\/li>\n\n\n\n<li>System Administrators<\/li>\n\n\n\n<li>Kubernetes Engineers<\/li>\n\n\n\n<li>Cloud Architects<\/li>\n\n\n\n<li>Technical Leads<\/li>\n\n\n\n<li>Engineering Managers<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">3. Prerequisites<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Participants should have basic knowledge of:<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Required<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Git fundamentals<\/li>\n\n\n\n<li>GitHub repositories<\/li>\n\n\n\n<li>Basic Linux commands<\/li>\n\n\n\n<li>Basic YAML<\/li>\n\n\n\n<li>Basic scripting<\/li>\n\n\n\n<li>Basic software development lifecycle<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Knowledge of:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Docker<\/li>\n\n\n\n<li>Kubernetes<\/li>\n\n\n\n<li>AWS\/Azure\/GCP<\/li>\n\n\n\n<li>Terraform<\/li>\n\n\n\n<li>CI\/CD concepts<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Participants do <strong>not<\/strong> need prior GitHub Actions experience.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">4. Learning Objectives<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">By the end of the course, participants will be able to:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Understand GitHub Actions architecture and execution model.<\/li>\n\n\n\n<li>Create GitHub Actions workflows from scratch.<\/li>\n\n\n\n<li>Configure workflow triggers and filters.<\/li>\n\n\n\n<li>Design multi-job CI\/CD pipelines.<\/li>\n\n\n\n<li>Use variables, secrets, contexts and expressions.<\/li>\n\n\n\n<li>Implement conditional workflow execution.<\/li>\n\n\n\n<li>Build matrix-based pipelines.<\/li>\n\n\n\n<li>Implement dependency caching.<\/li>\n\n\n\n<li>Publish and consume workflow artifacts.<\/li>\n\n\n\n<li>Configure GitHub environments.<\/li>\n\n\n\n<li>Implement deployment approval controls.<\/li>\n\n\n\n<li>Create reusable workflows.<\/li>\n\n\n\n<li>Work with GitHub-hosted and self-hosted runners.<\/li>\n\n\n\n<li>Build Docker images using GitHub Actions.<\/li>\n\n\n\n<li>Publish container images to a registry.<\/li>\n\n\n\n<li>Implement secure <code>GITHUB_TOKEN<\/code> permissions.<\/li>\n\n\n\n<li>Understand GitHub Actions security risks.<\/li>\n\n\n\n<li>Implement OIDC-based cloud authentication.<\/li>\n\n\n\n<li>Integrate GitHub Actions with AWS.<\/li>\n\n\n\n<li>Understand Kubernetes deployment automation.<\/li>\n\n\n\n<li>Automate Terraform workflows.<\/li>\n\n\n\n<li>Troubleshoot failed workflows.<\/li>\n\n\n\n<li>Optimize workflow performance and cost.<\/li>\n\n\n\n<li>Design production-ready CI\/CD pipelines.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">5. Day 1 \u2014 GitHub Actions Foundations &amp; CI<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Module 1 \u2014 GitHub Actions Fundamentals<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What is GitHub Actions?<\/li>\n\n\n\n<li>CI vs Continuous Delivery vs Continuous Deployment<\/li>\n\n\n\n<li>GitHub Actions use cases<\/li>\n\n\n\n<li>Event-driven automation<\/li>\n\n\n\n<li>Repository automation<\/li>\n\n\n\n<li>DevOps automation<\/li>\n\n\n\n<li>GitHub Actions architecture<\/li>\n\n\n\n<li>Execution model<\/li>\n\n\n\n<li>Workflow lifecycle<\/li>\n\n\n\n<li>Workflow run lifecycle<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Core Components<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflows<\/li>\n\n\n\n<li>Workflow runs<\/li>\n\n\n\n<li>Events<\/li>\n\n\n\n<li>Triggers<\/li>\n\n\n\n<li>Jobs<\/li>\n\n\n\n<li>Steps<\/li>\n\n\n\n<li>Actions<\/li>\n\n\n\n<li>Runners<\/li>\n\n\n\n<li>Commands<\/li>\n\n\n\n<li>Scripts<\/li>\n\n\n\n<li>Artifacts<\/li>\n\n\n\n<li>Caches<\/li>\n\n\n\n<li>Variables<\/li>\n\n\n\n<li>Secrets<\/li>\n\n\n\n<li>Contexts<\/li>\n\n\n\n<li>Expressions<\/li>\n\n\n\n<li>Environments<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These core concepts are explicitly included in the supplied curriculum.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Create Your First GitHub Actions Workflow<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants will:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Create a GitHub repository.<\/li>\n\n\n\n<li>Create <code>.github\/workflows\/<\/code>.<\/li>\n\n\n\n<li>Create a YAML workflow.<\/li>\n\n\n\n<li>Trigger it on <code>push<\/code>.<\/li>\n\n\n\n<li>Execute shell commands.<\/li>\n\n\n\n<li>Inspect workflow logs.<\/li>\n\n\n\n<li>Re-run a workflow.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 2 \u2014 Workflow YAML &amp; Syntax<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>YAML fundamentals<\/li>\n\n\n\n<li>Workflow structure<\/li>\n\n\n\n<li><code>name<\/code><\/li>\n\n\n\n<li><code>run-name<\/code><\/li>\n\n\n\n<li><code>on<\/code><\/li>\n\n\n\n<li><code>permissions<\/code><\/li>\n\n\n\n<li><code>env<\/code><\/li>\n\n\n\n<li><code>defaults<\/code><\/li>\n\n\n\n<li><code>concurrency<\/code><\/li>\n\n\n\n<li><code>jobs<\/code><\/li>\n\n\n\n<li><code>runs-on<\/code><\/li>\n\n\n\n<li><code>steps<\/code><\/li>\n\n\n\n<li><code>uses<\/code><\/li>\n\n\n\n<li><code>run<\/code><\/li>\n\n\n\n<li><code>with<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Job Configuration<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Job IDs<\/li>\n\n\n\n<li><code>needs<\/code><\/li>\n\n\n\n<li><code>if<\/code><\/li>\n\n\n\n<li><code>runs-on<\/code><\/li>\n\n\n\n<li><code>environment<\/code><\/li>\n\n\n\n<li><code>outputs<\/code><\/li>\n\n\n\n<li><code>timeout-minutes<\/code><\/li>\n\n\n\n<li><code>continue-on-error<\/code><\/li>\n\n\n\n<li><code>container<\/code><\/li>\n\n\n\n<li><code>services<\/code><\/li>\n\n\n\n<li><code>strategy<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Step Configuration<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Step IDs<\/li>\n\n\n\n<li><code>uses<\/code><\/li>\n\n\n\n<li><code>run<\/code><\/li>\n\n\n\n<li><code>shell<\/code><\/li>\n\n\n\n<li><code>with<\/code><\/li>\n\n\n\n<li><code>env<\/code><\/li>\n\n\n\n<li>Working directories<\/li>\n\n\n\n<li>Conditions<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The supplied curriculum specifically separates workflow-, job-, and step-level syntax, making this a natural foundation for the first day.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Build \u2192 Test \u2192 Package<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Checkout Code\n     \u2193\nInstall Dependencies\n     \u2193\nRun Lint\n     \u2193\nRun Tests\n     \u2193\nBuild Application\n     \u2193\nUpload Artifact<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 3 \u2014 Events &amp; Workflow Triggers<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub events<\/li>\n\n\n\n<li><code>push<\/code><\/li>\n\n\n\n<li><code>pull_request<\/code><\/li>\n\n\n\n<li><code>workflow_dispatch<\/code><\/li>\n\n\n\n<li><code>schedule<\/code><\/li>\n\n\n\n<li><code>workflow_call<\/code><\/li>\n\n\n\n<li><code>workflow_run<\/code><\/li>\n\n\n\n<li><code>repository_dispatch<\/code><\/li>\n\n\n\n<li>Release events<\/li>\n\n\n\n<li>Issue events<\/li>\n\n\n\n<li>Tag events<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Trigger Filters<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Branch filters<\/li>\n\n\n\n<li>Tag filters<\/li>\n\n\n\n<li>Path filters<\/li>\n\n\n\n<li>Activity types<\/li>\n\n\n\n<li><code>branches<\/code><\/li>\n\n\n\n<li><code>branches-ignore<\/code><\/li>\n\n\n\n<li><code>tags<\/code><\/li>\n\n\n\n<li><code>tags-ignore<\/code><\/li>\n\n\n\n<li><code>paths<\/code><\/li>\n\n\n\n<li><code>paths-ignore<\/code><\/li>\n\n\n\n<li>Glob patterns<\/li>\n\n\n\n<li>Combined filters<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Manual Workflows<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>workflow_dispatch<\/code><\/li>\n\n\n\n<li>Workflow inputs<\/li>\n\n\n\n<li>String inputs<\/li>\n\n\n\n<li>Boolean inputs<\/li>\n\n\n\n<li>Choice inputs<\/li>\n\n\n\n<li>Required inputs<\/li>\n\n\n\n<li>Default values<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create a workflow that:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Runs on Pull Request<\/li>\n\n\n\n<li>Runs on <code>main<\/code><\/li>\n\n\n\n<li>Runs only when application files change<\/li>\n\n\n\n<li>Supports manual execution<\/li>\n\n\n\n<li>Accepts deployment environment as an input<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The source curriculum includes the full event and filtering model, including manual, scheduled and external triggers.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 4 \u2014 Jobs, Dependencies &amp; Conditions<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Sequential jobs<\/li>\n\n\n\n<li>Parallel jobs<\/li>\n\n\n\n<li>Job dependencies<\/li>\n\n\n\n<li><code>needs<\/code><\/li>\n\n\n\n<li>Fan-out<\/li>\n\n\n\n<li>Fan-in<\/li>\n\n\n\n<li>Job outputs<\/li>\n\n\n\n<li>Step outputs<\/li>\n\n\n\n<li>Conditional jobs<\/li>\n\n\n\n<li>Conditional steps<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Status Functions<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>success()<\/code><\/li>\n\n\n\n<li><code>failure()<\/code><\/li>\n\n\n\n<li><code>cancelled()<\/code><\/li>\n\n\n\n<li><code>always()<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>         \u250c\u2500\u2500 Unit Tests \u2500\u2500\u2510\nCode \u2500\u2500\u2500\u2500\u2500\u2524                \u251c\u2500\u2500 Package\n          \u2514\u2500\u2500 Security \u2500\u2500\u2500\u2500\u2518<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Then implement:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Build\n  \u2193\nTest\n  \u2193\nSecurity Scan\n  \u2193\nPackage<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">with conditional execution.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 5 \u2014 Runners<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Actions runner architecture<\/li>\n\n\n\n<li>GitHub-hosted runners<\/li>\n\n\n\n<li>Ubuntu runners<\/li>\n\n\n\n<li>Windows runners<\/li>\n\n\n\n<li>macOS runners<\/li>\n\n\n\n<li>ARM runners<\/li>\n\n\n\n<li>Runner labels<\/li>\n\n\n\n<li>Runner workspace<\/li>\n\n\n\n<li>Temporary directories<\/li>\n\n\n\n<li>Tool cache<\/li>\n\n\n\n<li>Runner lifecycle<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Self-Hosted Runners<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Architecture<\/li>\n\n\n\n<li>Installation<\/li>\n\n\n\n<li>Registration<\/li>\n\n\n\n<li>Labels<\/li>\n\n\n\n<li>Runner groups<\/li>\n\n\n\n<li>Repository-level runners<\/li>\n\n\n\n<li>Organization-level runners<\/li>\n\n\n\n<li>Security considerations<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The supplied material includes both GitHub-hosted and self-hosted runner architecture, networking, security and lifecycle management.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Configure a Self-Hosted Runner<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Participants:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Provision a Linux VM.<\/li>\n\n\n\n<li>Register the runner.<\/li>\n\n\n\n<li>Add labels.<\/li>\n\n\n\n<li>Execute a workflow.<\/li>\n\n\n\n<li>Verify runner logs.<\/li>\n\n\n\n<li>Remove the runner safely.<\/li>\n<\/ol>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 6 \u2014 Variables, Contexts &amp; Expressions<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Variables<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflow variables<\/li>\n\n\n\n<li>Job variables<\/li>\n\n\n\n<li>Step variables<\/li>\n\n\n\n<li>Repository variables<\/li>\n\n\n\n<li>Organization variables<\/li>\n\n\n\n<li>Environment variables<\/li>\n\n\n\n<li>Variable precedence<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Contexts<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>github<\/code><\/li>\n\n\n\n<li><code>env<\/code><\/li>\n\n\n\n<li><code>vars<\/code><\/li>\n\n\n\n<li><code>job<\/code><\/li>\n\n\n\n<li><code>jobs<\/code><\/li>\n\n\n\n<li><code>steps<\/code><\/li>\n\n\n\n<li><code>runner<\/code><\/li>\n\n\n\n<li><code>secrets<\/code><\/li>\n\n\n\n<li><code>strategy<\/code><\/li>\n\n\n\n<li><code>matrix<\/code><\/li>\n\n\n\n<li><code>needs<\/code><\/li>\n\n\n\n<li><code>inputs<\/code><\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Expressions<\/h3>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">${{ }}<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Operators:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>==<\/code><\/li>\n\n\n\n<li><code>!=<\/code><\/li>\n\n\n\n<li><code>><\/code><\/li>\n\n\n\n<li><code>&lt;<\/code><\/li>\n\n\n\n<li><code>>=<\/code><\/li>\n\n\n\n<li><code>&lt;=<\/code><\/li>\n\n\n\n<li><code>&amp;&amp;<\/code><\/li>\n\n\n\n<li><code>||<\/code><\/li>\n\n\n\n<li><code>!<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Functions:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>contains()<\/code><\/li>\n\n\n\n<li><code>startsWith()<\/code><\/li>\n\n\n\n<li><code>endsWith()<\/code><\/li>\n\n\n\n<li><code>format()<\/code><\/li>\n\n\n\n<li><code>join()<\/code><\/li>\n\n\n\n<li><code>toJSON()<\/code><\/li>\n\n\n\n<li><code>fromJSON()<\/code><\/li>\n\n\n\n<li><code>hashFiles()<\/code><\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These contexts and expression capabilities are directly represented in the source curriculum.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create branch-specific behavior:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">feature\/* \u2192 test only\ndevelop   \u2192 test + build\nmain      \u2192 test + build + deploy<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 7 \u2014 Secrets &amp; GITHUB_TOKEN<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository secrets<\/li>\n\n\n\n<li>Organization secrets<\/li>\n\n\n\n<li>Environment secrets<\/li>\n\n\n\n<li>Secret access policies<\/li>\n\n\n\n<li>Secret masking<\/li>\n\n\n\n<li>Secret rotation<\/li>\n\n\n\n<li>Least privilege<\/li>\n\n\n\n<li><code>secrets<\/code> context<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">GITHUB_TOKEN<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Automatic token generation<\/li>\n\n\n\n<li>Token lifecycle<\/li>\n\n\n\n<li>Permissions<\/li>\n\n\n\n<li><code>permissions<\/code><\/li>\n\n\n\n<li>Read vs write access<\/li>\n\n\n\n<li><code>contents<\/code><\/li>\n\n\n\n<li><code>actions<\/code><\/li>\n\n\n\n<li><code>packages<\/code><\/li>\n\n\n\n<li><code>deployments<\/code><\/li>\n\n\n\n<li><code>id-token<\/code><\/li>\n\n\n\n<li>Security best practices<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The source curriculum specifically covers <code>GITHUB_TOKEN<\/code>, permission scopes and least-privilege design.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Secure CI workflow<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">with:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Repository secret<\/li>\n\n\n\n<li>Environment secret<\/li>\n\n\n\n<li>Restricted <code>GITHUB_TOKEN<\/code><\/li>\n\n\n\n<li>Secret masking<\/li>\n\n\n\n<li>No secrets committed to Git<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Day 1 Capstone<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Build a Production-Style CI Pipeline<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Participants create:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Developer\n   \u2502\n   \u25bc\nGitHub Pull Request\n   \u2502\n   \u25bc\nGitHub Actions\n   \u2502\n   \u251c\u2500\u2500 Lint\n   \u251c\u2500\u2500 Unit Test\n   \u251c\u2500\u2500 Security Scan\n   \u251c\u2500\u2500 Build\n   \u2514\u2500\u2500 Package\n          \u2502\n          \u25bc\n      Artifact<\/code><\/span><\/pre>\n\n\n<h3 class=\"wp-block-heading\">Day 1 Outcome<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Participants finish Day 1 with a working CI pipeline.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Day 2 \u2014 Advanced CI\/CD, Security &amp; Cloud Deployment<\/h1>\n\n\n\n<h1 class=\"wp-block-heading\">Module 8 \u2014 Matrix Builds<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>strategy.matrix<\/code><\/li>\n\n\n\n<li>OS matrix<\/li>\n\n\n\n<li>Runtime matrix<\/li>\n\n\n\n<li>Multi-dimensional matrix<\/li>\n\n\n\n<li><code>include<\/code><\/li>\n\n\n\n<li><code>exclude<\/code><\/li>\n\n\n\n<li>Dynamic matrices<\/li>\n\n\n\n<li>JSON-based matrices<\/li>\n\n\n\n<li><code>max-parallel<\/code><\/li>\n\n\n\n<li><code>fail-fast<\/code><\/li>\n\n\n\n<li>Matrix outputs<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Test an application against:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Ubuntu + Node 20\nUbuntu + Node 22\nWindows + Node 20\nWindows + Node 22<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The source material specifically covers multidimensional matrices, dynamic matrices, parallelism and failure controls.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 9 \u2014 Caching &amp; Artifacts<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Dependency Caching<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>actions\/cache<\/code><\/li>\n\n\n\n<li>Cache keys<\/li>\n\n\n\n<li>Restore keys<\/li>\n\n\n\n<li>Cache hits<\/li>\n\n\n\n<li>Cache misses<\/li>\n\n\n\n<li>Package-manager caching<\/li>\n\n\n\n<li>npm<\/li>\n\n\n\n<li>Maven<\/li>\n\n\n\n<li>Gradle<\/li>\n\n\n\n<li>pip<\/li>\n\n\n\n<li>Cache security<\/li>\n\n\n\n<li>Cache poisoning<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Artifacts<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Upload artifacts<\/li>\n\n\n\n<li>Download artifacts<\/li>\n\n\n\n<li>Artifact naming<\/li>\n\n\n\n<li>Retention<\/li>\n\n\n\n<li>Artifact sharing<\/li>\n\n\n\n<li>Build artifacts<\/li>\n\n\n\n<li>Test artifacts<\/li>\n\n\n\n<li>Deployment artifacts<\/li>\n\n\n\n<li>Artifact digests<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Build\n  \u2193\nCreate Artifact\n  \u2193\nUpload\n  \u2193\nDownload\n  \u2193\nDeploy<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The source distinguishes dependency caching from workflow artifacts and includes their security, retention and sharing models.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 10 \u2014 Reusable Workflows<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li><code>workflow_call<\/code><\/li>\n\n\n\n<li>Caller workflow<\/li>\n\n\n\n<li>Called workflow<\/li>\n\n\n\n<li>Inputs<\/li>\n\n\n\n<li>Secrets<\/li>\n\n\n\n<li>Outputs<\/li>\n\n\n\n<li><code>secrets: inherit<\/code><\/li>\n\n\n\n<li>Nested workflows<\/li>\n\n\n\n<li>Cross-repository workflows<\/li>\n\n\n\n<li>Workflow versioning<\/li>\n\n\n\n<li>Workflow permissions<\/li>\n\n\n\n<li>Workflow templates<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Central CI Workflow\n        \u2191\n \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n \u2502      \u2502      \u2502\nApp A  App B  App C<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">This introduces participants to enterprise-style centralized CI\/CD architecture.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 11 \u2014 Environments &amp; Deployment Protection<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Development environment<\/li>\n\n\n\n<li>Staging environment<\/li>\n\n\n\n<li>UAT environment<\/li>\n\n\n\n<li>Production environment<\/li>\n\n\n\n<li>Environment variables<\/li>\n\n\n\n<li>Environment secrets<\/li>\n\n\n\n<li>Required reviewers<\/li>\n\n\n\n<li>Deployment approvals<\/li>\n\n\n\n<li>Wait timers<\/li>\n\n\n\n<li>Branch restrictions<\/li>\n\n\n\n<li>Deployment history<\/li>\n\n\n\n<li>Environment concurrency<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-1\" data-shcb-language-name=\"CSS\" data-shcb-language-slug=\"css\"><span><code class=\"hljs language-css\"><span class=\"hljs-selector-tag\">DEV<\/span>\n \u2193\n<span class=\"hljs-selector-tag\">STAGING<\/span>\n \u2193\n<span class=\"hljs-selector-attr\">&#91;Approval]<\/span>\n \u2193\n<span class=\"hljs-selector-tag\">PRODUCTION<\/span><\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-1\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">CSS<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">css<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The source curriculum includes environment protection, reviewers, deployment restrictions, wait timers and deployment history.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 12 \u2014 Docker CI\/CD<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Docker builds<\/li>\n\n\n\n<li>Buildx<\/li>\n\n\n\n<li>BuildKit<\/li>\n\n\n\n<li>Multi-platform builds<\/li>\n\n\n\n<li>Docker layer caching<\/li>\n\n\n\n<li>Registry authentication<\/li>\n\n\n\n<li>GitHub Container Registry<\/li>\n\n\n\n<li>Image tagging<\/li>\n\n\n\n<li>Image metadata<\/li>\n\n\n\n<li>Image publishing<\/li>\n\n\n\n<li>Image scanning<\/li>\n\n\n\n<li>Image signing<\/li>\n\n\n\n<li>Image attestations<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">GitHub\n   \u2193\nGitHub Actions\n   \u2193\nDocker Build\n   \u2193\nSecurity Scan\n   \u2193\nGHCR<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The supplied curriculum includes Docker Buildx\/BuildKit, registry publishing, image scanning, signing and attestations.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 13 \u2014 GitHub Actions Security<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This is an important DevOpsSchool differentiator for the course.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Least privilege<\/li>\n\n\n\n<li>Workflow permissions<\/li>\n\n\n\n<li>Job permissions<\/li>\n\n\n\n<li>Secret management<\/li>\n\n\n\n<li>Untrusted input<\/li>\n\n\n\n<li>Script injection<\/li>\n\n\n\n<li>Command injection<\/li>\n\n\n\n<li>Expression injection<\/li>\n\n\n\n<li>Shell injection<\/li>\n\n\n\n<li>Fork PR security<\/li>\n\n\n\n<li><code>pull_request<\/code><\/li>\n\n\n\n<li><code>pull_request_target<\/code><\/li>\n\n\n\n<li>Third-party action security<\/li>\n\n\n\n<li>Action provenance<\/li>\n\n\n\n<li>SHA pinning<\/li>\n\n\n\n<li>Supply-chain security<\/li>\n\n\n\n<li>Self-hosted runner security<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Anti-Patterns<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Participants will identify risks such as:<\/p>\n\n\n<pre class=\"wp-block-code\" aria-describedby=\"shcb-language-2\" data-shcb-language-name=\"PHP\" data-shcb-language-slug=\"php\"><span><code class=\"hljs language-php\">\u274c Secrets in workflow files\n\u274c Overprivileged GITHUB_TOKEN\n\u274c Unpinned actions\n\u274c Mutable action references\n\u274c Long-lived cloud credentials\n\u274c Unsafe pull_request_target\n\u274c Persistent <span class=\"hljs-keyword\">public<\/span> <span class=\"hljs-keyword\">self<\/span>-hosted runners<\/code><\/span><small class=\"shcb-language\" id=\"shcb-language-2\"><span class=\"shcb-language__label\">Code language:<\/span> <span class=\"shcb-language__name\">PHP<\/span> <span class=\"shcb-language__paren\">(<\/span><span class=\"shcb-language__slug\">php<\/span><span class=\"shcb-language__paren\">)<\/span><\/small><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The supplied curriculum contains a dedicated security-hardening section covering these risks and production controls.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 14 \u2014 OIDC &amp; Cloud Authentication<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What is OIDC?<\/li>\n\n\n\n<li>Federated authentication<\/li>\n\n\n\n<li>Short-lived credentials<\/li>\n\n\n\n<li>GitHub OIDC tokens<\/li>\n\n\n\n<li><code>id-token: write<\/code><\/li>\n\n\n\n<li>Token claims<\/li>\n\n\n\n<li>Repository claims<\/li>\n\n\n\n<li>Branch claims<\/li>\n\n\n\n<li>Environment claims<\/li>\n\n\n\n<li>Cloud trust policies<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">AWS<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>AWS IAM<\/li>\n\n\n\n<li>AWS STS<\/li>\n\n\n\n<li>AssumeRole<\/li>\n\n\n\n<li>GitHub OIDC provider<\/li>\n\n\n\n<li>IAM trust policy<\/li>\n\n\n\n<li>Credential-less deployments<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">GitHub Actions\n      \u2502\n      \u2502 OIDC\n      \u25bc\nAWS IAM\n      \u2502\n      \u25bc\nSTS AssumeRole\n      \u2502\n      \u25bc\nAWS Resource<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">OIDC, AWS authentication, IAM roles, STS and credential-less cloud deployment are specifically covered in the source curriculum.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 15 \u2014 Kubernetes &amp; GitHub Actions<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Kubernetes authentication<\/li>\n\n\n\n<li>kubeconfig<\/li>\n\n\n\n<li>Kubernetes manifests<\/li>\n\n\n\n<li><code>kubectl<\/code><\/li>\n\n\n\n<li>Helm<\/li>\n\n\n\n<li>Kustomize<\/li>\n\n\n\n<li>Namespace deployment<\/li>\n\n\n\n<li>Rollout verification<\/li>\n\n\n\n<li>Rollback<\/li>\n\n\n\n<li>EKS<\/li>\n\n\n\n<li>AKS<\/li>\n\n\n\n<li>GKE<\/li>\n\n\n\n<li>GitOps integration<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Hands-on Lab<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Developer\n   \u2193\nGitHub\n   \u2193\nGitHub Actions\n   \u2193\nDocker Build\n   \u2193\nContainer Registry\n   \u2193\nKubernetes\n   \u2193\nDeployment<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">The supplied curriculum explicitly includes Kubernetes authentication, Helm, Kustomize, kubectl, rollout verification, rollback and managed Kubernetes platforms.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 16 \u2014 Terraform with GitHub Actions<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Terraform formatting<\/li>\n\n\n\n<li>Terraform validation<\/li>\n\n\n\n<li>Terraform plan<\/li>\n\n\n\n<li>Terraform apply<\/li>\n\n\n\n<li>Terraform state<\/li>\n\n\n\n<li>Terraform Cloud<\/li>\n\n\n\n<li>Plan artifacts<\/li>\n\n\n\n<li>Approval workflows<\/li>\n\n\n\n<li>IaC security scanning<\/li>\n\n\n\n<li>Drift detection<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Recommended Pipeline<\/h3>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Pull Request\n     \u2193\nterraform fmt\n     \u2193\nterraform validate\n     \u2193\nterraform plan\n     \u2193\nPR Review\n     \u2193\nApproval\n     \u2193\nterraform apply<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">These Terraform automation topics are part of the supplied advanced curriculum.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 17 \u2014 Troubleshooting &amp; Debugging<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>YAML errors<\/li>\n\n\n\n<li>Workflow syntax errors<\/li>\n\n\n\n<li>Trigger problems<\/li>\n\n\n\n<li>Context debugging<\/li>\n\n\n\n<li>Expression debugging<\/li>\n\n\n\n<li>Runner problems<\/li>\n\n\n\n<li>Action failures<\/li>\n\n\n\n<li>Permission errors<\/li>\n\n\n\n<li>Authentication errors<\/li>\n\n\n\n<li>Secret problems<\/li>\n\n\n\n<li>Cache problems<\/li>\n\n\n\n<li>Artifact problems<\/li>\n\n\n\n<li>Matrix failures<\/li>\n\n\n\n<li>Deployment failures<\/li>\n\n\n\n<li>Network problems<\/li>\n\n\n\n<li>DNS problems<\/li>\n\n\n\n<li>Timeout issues<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Debugging Techniques<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflow logs<\/li>\n\n\n\n<li>Job logs<\/li>\n\n\n\n<li>Step logs<\/li>\n\n\n\n<li>Debug logging<\/li>\n\n\n\n<li>Re-running workflows<\/li>\n\n\n\n<li>Re-running failed jobs<\/li>\n\n\n\n<li>Annotations<\/li>\n\n\n\n<li>Job summaries<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These troubleshooting areas are explicitly included in the source reference.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Module 18 \u2014 Performance &amp; Cost Optimization<\/h1>\n\n\n\n<h3 class=\"wp-block-heading\">Topics<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Workflow runtime optimization<\/li>\n\n\n\n<li>Parallel jobs<\/li>\n\n\n\n<li>Matrix optimization<\/li>\n\n\n\n<li>Dependency caching<\/li>\n\n\n\n<li>Docker caching<\/li>\n\n\n\n<li>Artifact optimization<\/li>\n\n\n\n<li>Shallow checkout<\/li>\n\n\n\n<li>Sparse checkout<\/li>\n\n\n\n<li>Path filtering<\/li>\n\n\n\n<li>Runner selection<\/li>\n\n\n\n<li>Larger runners<\/li>\n\n\n\n<li>Self-hosted runners<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Cost Management<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>GitHub Actions minutes<\/li>\n\n\n\n<li>Runner billing<\/li>\n\n\n\n<li>Artifact storage<\/li>\n\n\n\n<li>Cache storage<\/li>\n\n\n\n<li>Matrix cost<\/li>\n\n\n\n<li>Retention optimization<\/li>\n\n\n\n<li>Usage monitoring<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The supplied curriculum includes both workflow performance and Actions cost optimization.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">Day 2 Capstone Project<\/h1>\n\n\n\n<h2 class=\"wp-block-heading\">Production CI\/CD Pipeline<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Participants build an end-to-end pipeline:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                   GitHub Repository\n                           \u2502\n                           \u25bc\n                    Pull Request\n                           \u2502\n                           \u25bc\n                  GitHub Actions CI\n                           \u2502\n             \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n             \u25bc             \u25bc             \u25bc\n           Lint          Tests        Security\n             \u2502             \u2502             \u2502\n             \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n                           \u25bc\n                         Build\n                           \u2502\n                           \u25bc\n                    Docker Image\n                           \u2502\n                           \u25bc\n                    Container Registry\n                           \u2502\n                           \u25bc\n                       Staging\n                           \u2502\n                     Approval Gate\n                           \u2502\n                           \u25bc\n                     Production\n                           \u2502\n                           \u25bc\n                    Verification\n                           \u2502\n                           \u25bc\n                       Rollback<\/code><\/pre>\n\n\n\n<h3 class=\"wp-block-heading\">Optional Cloud Extension<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For participants with AWS access:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">GitHub Actions\n      \u2502\n      \u25bc\n     OIDC\n      \u2502\n      \u25bc\nAWS IAM\n      \u2502\n      \u25bc\n    ECR\n      \u2502\n      \u25bc\n    EKS<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">6. Practical Labs<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">The course should be marketed as <strong>hands-on<\/strong>, rather than simply a theoretical GitHub Actions course.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 1<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create first GitHub Actions workflow.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 2<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build a CI pipeline.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 3<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configure PR and branch triggers.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 4<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Use variables, contexts and expressions.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 5<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configure secrets and <code>GITHUB_TOKEN<\/code>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 6<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement matrix testing.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 7<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement dependency caching.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 8<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create and consume artifacts.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 9<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Create reusable workflows.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 10<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configure environments and approvals.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 11<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Build and publish Docker images.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 12<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Implement GitHub Actions security controls.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 13<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Configure AWS OIDC.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 14<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Deploy to Kubernetes.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 15<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Automate Terraform plan\/apply.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Lab 16<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Troubleshoot intentionally broken workflows.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">7. Recommended Day-wise Schedule<\/h1>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Time<\/th><th>Day 1<\/th><th>Day 2<\/th><\/tr><\/thead><tbody><tr><td>09:00\u201309:30<\/td><td>GitHub Actions Introduction<\/td><td>Day 1 Recap<\/td><\/tr><tr><td>09:30\u201310:30<\/td><td>Architecture &amp; Components<\/td><td>Matrix Builds<\/td><\/tr><tr><td>10:30\u201310:45<\/td><td>Break<\/td><td>Break<\/td><\/tr><tr><td>10:45\u201312:00<\/td><td>YAML &amp; Workflow Syntax<\/td><td>Caching &amp; Artifacts<\/td><\/tr><tr><td>12:00\u201313:00<\/td><td>Hands-on Lab<\/td><td>Hands-on Lab<\/td><\/tr><tr><td>13:00\u201314:00<\/td><td>Lunch<\/td><td>Lunch<\/td><\/tr><tr><td>14:00\u201315:00<\/td><td>Events &amp; Triggers<\/td><td>Reusable Workflows<\/td><\/tr><tr><td>15:00\u201316:00<\/td><td>Jobs, Steps &amp; Conditions<\/td><td>Environments &amp; Approvals<\/td><\/tr><tr><td>16:00\u201316:15<\/td><td>Break<\/td><td>Break<\/td><\/tr><tr><td>16:15\u201317:15<\/td><td>Runners<\/td><td>Docker CI\/CD<\/td><\/tr><tr><td>17:15\u201318:00<\/td><td>Variables, Contexts &amp; Secrets<\/td><td>Security + OIDC<\/td><\/tr><tr><td>18:00\u201318:30<\/td><td>Day 1 CI Project<\/td><td>Cloud\/Kubernetes\/Terraform<\/td><\/tr><tr><td>18:30\u201319:00<\/td><td>Q&amp;A<\/td><td>Final Capstone &amp; Q&amp;A<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">8. Course Deliverables<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Participants receive:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Instructor-led training<\/li>\n\n\n\n<li>Presentation material<\/li>\n\n\n\n<li>GitHub Actions YAML examples<\/li>\n\n\n\n<li>Hands-on lab exercises<\/li>\n\n\n\n<li>Sample repositories<\/li>\n\n\n\n<li>CI\/CD pipeline templates<\/li>\n\n\n\n<li>Docker workflow examples<\/li>\n\n\n\n<li>Reusable workflow examples<\/li>\n\n\n\n<li>Security checklist<\/li>\n\n\n\n<li>AWS OIDC example<\/li>\n\n\n\n<li>Kubernetes deployment workflow<\/li>\n\n\n\n<li>Terraform workflow example<\/li>\n\n\n\n<li>Troubleshooting guide<\/li>\n\n\n\n<li>Production best-practices checklist<\/li>\n\n\n\n<li>Capstone project<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">9. Skills Participants Gain<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">After completing the program, participants should be able to work with:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>GitHub<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2192 Repositories<br>\u2192 Pull Requests<br>\u2192 Branches<br>\u2192 Releases<br>\u2192 Environments<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>GitHub Actions<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2192 Workflows<br>\u2192 Events<br>\u2192 Jobs<br>\u2192 Steps<br>\u2192 Actions<br>\u2192 Runners<br>\u2192 Secrets<br>\u2192 Contexts<br>\u2192 Expressions<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CI\/CD<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2192 Build<br>\u2192 Test<br>\u2192 Package<br>\u2192 Artifact<br>\u2192 Deploy<br>\u2192 Approve<br>\u2192 Verify<br>\u2192 Rollback<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Cloud\/DevOps<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u2192 Docker<br>\u2192 Container Registry<br>\u2192 AWS OIDC<br>\u2192 IAM<br>\u2192 Kubernetes<br>\u2192 Helm<br>\u2192 Terraform<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">10. Advanced Topics \u2014 Awareness \/ Take-Home<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Because this is only a <strong>2-day course<\/strong>, I would not attempt to teach every advanced topic in the supplied 1,800-line reference in depth.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead, these can be presented as <strong>advanced awareness topics \/ optional extensions<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Custom JavaScript Actions<\/li>\n\n\n\n<li>Docker Actions<\/li>\n\n\n\n<li>Composite Actions<\/li>\n\n\n\n<li>Artifact Attestations<\/li>\n\n\n\n<li>Package Publishing<\/li>\n\n\n\n<li>Advanced Release Automation<\/li>\n\n\n\n<li>Self-hosted runner architecture<\/li>\n\n\n\n<li>Actions Runner Controller<\/li>\n\n\n\n<li>Monorepo workflows<\/li>\n\n\n\n<li>Multi-repository orchestration<\/li>\n\n\n\n<li>Workflow chaining<\/li>\n\n\n\n<li>GitHub API automation<\/li>\n\n\n\n<li>Repository governance<\/li>\n\n\n\n<li>Organization governance<\/li>\n\n\n\n<li>Enterprise governance<\/li>\n\n\n\n<li>GitHub Actions Importer<\/li>\n\n\n\n<li><code>act<\/code><\/li>\n\n\n\n<li>Advanced deployment strategies<\/li>\n\n\n\n<li>Canary deployment<\/li>\n\n\n\n<li>Blue\/green deployment<\/li>\n\n\n\n<li>Progressive delivery<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The source material contains dedicated sections for custom actions, runner architecture, ARC, monorepos, multi-repository workflows, API integration, governance, testing, maintenance and migration.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">11. Course Positioning for DevOpsSchool<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">I would market this as:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>A practical 2-day GitHub Actions CI\/CD course that takes DevOps and engineering professionals from workflow fundamentals to production-ready CI\/CD automation, including Docker, security, AWS OIDC, Kubernetes and Terraform integration.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The key differentiator should be <strong>&#8220;Learn GitHub Actions by building production-style pipelines&#8221;<\/strong>, rather than presenting it as a GitHub Actions syntax course.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\"><\/h1>\n","protected":false},"excerpt":{"rendered":"<p>Course Duration 2 Days | 16 Hours Format: Instructor-Led Training + Hands-on Labs + Real-World CI\/CD Project Offered By DevOpsSchool Website: DevOpsSchool GitHub Actions \u2014 CI\/CD Automation&#8230; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[11138],"tags":[],"class_list":["post-78742","post","type-post","status-publish","format-standard","hentry","category-best-tools"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78742","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=78742"}],"version-history":[{"count":1,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78742\/revisions"}],"predecessor-version":[{"id":78743,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78742\/revisions\/78743"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=78742"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=78742"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=78742"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}