GitHub Actions turns repository events into repeatable jobs on fresh hosted runners. This hands-on course uses a real GitHub repository to move from a first push-triggered workflow to Node.js testing, container publishing, secret references, and an ordered CI/build/deploy pipeline.
You will watch a Jest test pass and intentionally fail, build a Docker image and publish it to GitHub Container Registry, and verify that repository secrets are masked in logs. Deployment exercises introduce manual triggers and job dependencies, but deliberately use printed commands rather than connecting to a real staging or production server.
What You Will Learn
- Create a GitHub repository and place workflow YAML in
.github/workflows - Configure event and manual triggers, jobs, hosted runners, and shell steps
- Compose workflows with checkout and Node.js setup actions
- Install dependencies, run Jest in CI, and inspect a deliberately failed run
- Build and publish a Docker image to GHCR with scoped package permissions
- Reference a repository secret through an environment variable and verify masking
- Model a manual deployment workflow and explain its simulated safety check
- Chain
ci,build, anddeployjobs withneedsin an end-to-end workflow
Who This Course Is For
This intermediate course is for developers, Linux users, and DevOps learners who know basic Git and want practical experience authoring and running GitHub Actions workflows.
Prerequisites: A GitHub account, comfort with Git commits and pushes, Linux shell commands, YAML indentation, basic Node.js/npm concepts, and introductory Docker knowledge. HTTPS pushes may require a GitHub Personal Access Token.
Learning environment: A browser signed in to GitHub plus a Linux terminal for cloning and editing a public practice repository. Workflows run on GitHub-hosted ubuntu-latest runners and publish a practice image to GHCR.
Frequently Asked Questions
Do the workflows actually run on GitHub?
Yes. You create and push to your own github-actions-basics repository, inspect runs in the Actions tab, create a repository secret, and publish a container package. This is not only offline YAML validation.
Will the course deploy an application to a real staging or production server?
No. The deployment job prints mock SSH, pull, and restart steps. It does not connect to a server, run a container remotely, configure a GitHub Environment, or enforce an approval gate.
What security practices are covered?
You scope GITHUB_TOKEN package permissions, reference a repository secret, and observe log masking. The lab intentionally echoes a sample secret to demonstrate masking; production workflows should avoid printing secrets and require broader threat modeling than this course covers.


