Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Michael Kaufmann, Rob Bos, Marcel de Vries

Rating No ratings yet

No description

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide for DevOps engineers and developers who want to master GitHub Actions as a full automation platform—not just for CI/CD—covering everything from writing your first workflow to building secure, self-hosted runner infrastructure. 【Book Arc】 - **Opening (~0%–10%)**: Introduces the GitHub ecosystem and positions GitHub Actions as more than a CI/CD tool—a complete automation platform. Covers hosting options (GitHub.com, GHEC, GHES) and pricing, setting the stage for practical learning. - **Early (~10%–23%)**: First hands-on lab: creating a repository, writing a simple workflow with `run` and `echo`, using the workflow editor with error checking, and pulling actions from the marketplace. Establishes the core workflow anatomy. - **Early (~23%–32%)**: Deep dive into workflow syntax: triggers (push, pull_request, workflow_dispatch), inputs, expressions, contexts, jobs, steps, and shells. Explains how to reference actions via `uses` with tags, branches, or SHAs. - **Middle (~32%–48%)**: Covers workflow authoring and debugging, including job summaries, GITHUB_TOKEN permissions, and fork security considerations. Introduces the three action types (Docker, JavaScript, composite) and best practices for sharing actions internally or publicly. - **Middle (~48%–end of sample)**: Focuses on action development: release management with semantic versioning, compatibility with GitHub Enterprise Server, and a hands-on lab for building a Docker container action. Sets up for Part 2 on runners and Part 3 on CI/CD implementation. 【Key Takeaways】 - **GitHub Actions is a general automation platform, not just CI/CD** (Opening): You can automate any workflow—builds, releases, issue triage, or custom tasks—making it a versatile tool for DevOps. This reframing helps you see beyond pipelines. - **Start with a public repo for free minutes** (Early): Creating a public repository gives you unlimited Action minutes, ideal for learning. The hands-on approach—writing a "Hello World" workflow—builds confidence quickly. - **The workflow editor is your safety net** (Early): It highlights structural errors, unexpected values, and conflicts (e.g., invalid shells) with suggestions. Use it to debug before running, saving time and frustration. - **Triggers and inputs give you control** (Early): Use `on: [push, pull_request]` for automation, and `workflow_dispatch` with custom inputs for manual runs via UI or CLI (`gh workflow run`). This flexibility is key for testing and production use. - **Reference actions by tag, not branch** (Early): Pinning to a version tag (e.g., `@v3`) ensures stability, while branches (`@main`) or SHAs offer bleeding-edge or immutable references. Choose based on your risk tolerance. - **GITHUB_TOKEN permissions are a security lever** (Middle): Default is read-only; grant write access only at job/workflow level when needed. Fork-triggered workflows always get read-only, protecting your repo from malicious PRs. - **Three action types serve different needs** (Middle): Docker actions (Linux-only) for custom environments, JavaScript for cross-platform speed, and composite actions to bundle multiple steps. Pick based on your platform and complexity needs. - **Plan for enterprise compatibility** (Middle): Use `GITHUB_API_URL` and `GITHUB_GRAPHQL_URL` environment variables instead of hardcoding URLs to keep actions working on GitHub Enterprise Server. This future-proofs your shared actions. 【Reading Tips】 - **Skim the GitHub ecosystem overview (~0–10%)**: If you're already familiar with GitHub, jump ahead to Chapter 2 for the first hands-on lab—you can always return for hosting/pricing details. - **Deep-read the workflow syntax chapter (~23–32%)**: This is the backbone of the book. Pay special attention to triggers, contexts, and expressions; they're used in every subsequent chapter. - **Follow the hands-on labs in order**: The labs in Chapters 2 and 4 build on each other. Don't skip the Docker container action lab—it solidifies your understanding of action anatomy. - **Watch for security notes**: The GITHUB_TOKEN and fork-related warnings are easy to miss but critical for production. Highlight them for later reference. - **Use the book as a reference, not a novel**: After the first pass, return to specific sections (e.g., action types, runner setup) when you need to implement something new. 【Coverage Limits】 This guide covers the sample through the action development chapter (~48% of the book). The excerpts do not cover Part 2 (runners, including self-hosted setup and security) or Part 3 (CI/CD implementation with GitHub Flow, deployment strategies, and security hardening), which are outlined in the table of contents but not detailed here.
Page 14
Hub Actions, the GitHub universe has quickly expanded from a place that we go to get open source code to one where we build, create, and release open source...
View in text
Excerpt 2
ities are detected in any of the dependencies you’re using. Furthermore, GitHub can scan your repository to detect secrets, and it boasts a sophisticated cod...
View in text
Excerpt 3
sh. The default on windows is pwsh with a fallback to cmd. You can also configure a custom shell with the with the syntax shell: command [options] {0}. The p...
View in text
Excerpt 4
what type of action it is. 4.1.1 Docker container actions Docker container actions contain all their dependencies and are, therefore, very consis- tent. They...
View in text
Excerpt 5
deprecated, GitHub announces that up front and will start generating warnings in the runner logs to urge users to start upgrading. We have seen this, for exa...
View in text
Excerpt 6
xisting runner with the same name. This defaults to false. 96 chapter 6 Self-hosted runners The OAuth credentials that are used to authenticate the connectio...
View in text
Excerpt 7
he runner to a different group 7.2 Monitoring your runners You can view the available runners on the organization or repository level by going into Settings...
View in text
Excerpt 8
d authenticity of changes during the entire delivery cycle. Chapter 12, the final chapter of this book, briefly addresses some tips and tricks to improve the...
View in text
Tags
AI categories
DevOpsCloud NativeBackend
Publish Year: 2024
Language: English
Pages: 257
File Format: PDF
File Size: 4.5 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…