GitHub Actions — Level by Level
Start with workflows, events and your first pipeline, then build real pipelines: matrix builds, reusable workflows, container images pushed by digest, deployments handed to GitOps, OIDC instead of stored cloud keys, signed and attested artifacts, self-hosted runners on Kubernetes, and an air-gapped variant with Gitea/Forgejo.
What you'll be able to do
- Write workflows that react to the right events and run the right jobs
- Build, test and publish container images, and hand deployments to GitOps
- Run Actions Runner Controller on your own cluster
- Remove long-lived CI secrets with OIDC federation
- Sign, attest and verify every artifact you ship
Before you start
Git for Engineers (Level 1), Docker & Containers (Level 1).
How it works
Each lesson: plain-language idea → how it really works → hands-on. Each section ends with a cheat sheet & self-check.
Curriculum
Lessons marked “Read” are ready; the rest are on the way.
Level 1 — Foundations
- 01Workflows, events and your first pipelineWorkflow files, triggers, jobs, steps, actions, secrets and variablesRead →
- 02The execution modelRunners, jobs, contexts, cachingRead →
- 03Real pipelinesMatrix builds, reusable workflowsRead →
- 04Build, test and publish container imagesBuildx, caching, tags and digests, GHCR/ECR, scanning, updating the GitOps repoRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 13 questions to check yourself.Open →
Level 2 — Secure and scale
- 05Actions Runner ControllerSelf-hosted runners on KubernetesRead →
- 06OIDC federation & secret hygieneNo more static cloud keysRead →
- 07Supply chain: sign, attest, scan, verifycosign, SLSA, SBOMRead →
- 08Hardening the runnerIsolation, ephemeral runnersRead →
- 📋Cheat sheet & self-checkEvery command from this section on one page, then 12 questions to check yourself.Open →
Level 3 — Special environments
Real-world scenarios
Work through each one: symptom → misleading signal → evidence → root cause → prevention.
Designing CI that isn't a single point of failure.
Mutable tags, and how digests save you.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.