Github Actions Templates

作者 wshobson46891e7e60da無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications. Use when setting up CI/CD with GitHub Actions, automating development workflows, or creating reusable workflow templates.

僅含說明DevOps & Cloud
AI 產生的概覽

提供可直接用於正式環境的 GitHub Actions 工作流程範本,用於測試、建置與部署應用程式。

功能
此技能提供可重複使用的 GitHub Actions 工作流程模式,涵蓋測試、Docker 映像建置、Kubernetes 部署、矩陣建置、可重複使用的工作流程、安全掃描,以及需審核的部署。它也列出工作流程最佳實務,並示範如何以輸入與密鑰呼叫可重複使用的工作流程。交付內容是 YAML 工作流程設定指引,而非可執行程式碼。
適用情境
適用於使用 GitHub Actions 建立 CI/CD、自動化測試與部署流程,或建立可重複使用工作流程範本的情境。也適合為流程加入矩陣建置、安全掃描或審核關卡的團隊。
執行需求
不隨附指令碼,僅有說明文件與 YAML 範例。套用這些範例需要一個已啟用 Actions 的 GitHub 儲存庫,部分模式還涉及 GITHUB_TOKEN、AWS 憑證、NPM_TOKEN、SNYK_TOKEN 與 Slack webhook 等密鑰。

GitHub Actions Templates

Production-ready GitHub Actions workflow patterns for testing, building, and deploying applications.

Purpose

Create efficient, secure GitHub Actions workflows for continuous integration and deployment across various tech stacks.

When to Use

  • Automate testing and deployment
  • Build Docker images and push to registries
  • Deploy to Kubernetes clusters
  • Run security scans
  • Implement matrix builds for multiple environments

Common Workflow Patterns

Pattern 1: Test Workflow

yaml
name: Test
on:  push:    branches: [main, develop]  pull_request:    branches: [main]
jobs:  test:    runs-on: ubuntu-latest
    strategy:      matrix:        node-version: [18.x, 20.x]
    steps:      - uses: actions/checkout@v4
      - name: Use Node.js ${{ matrix.node-version }}        uses: actions/setup-node@v4        with:          node-version: ${{ matrix.node-version }}          cache: "npm"
      - name: Install dependencies        run: npm ci
      - name: Run linter        run: npm run lint
      - name: Run tests        run: npm test
      - name: Upload coverage        uses: codecov/codecov-action@v4        with:          files: ./coverage/lcov.info

Pattern 2: Build and Push Docker Image

yaml
name: Build and Push
on:  push:    branches: [main]    tags: ["v*"]
env:  REGISTRY: ghcr.io  IMAGE_NAME: ${{ github.repository }}
jobs:  build:    runs-on: ubuntu-latest    permissions:      contents: read      packages: write
    steps:      - uses: actions/checkout@v4
      - name: Log in to Container Registry        uses: docker/login-action@v3        with:          registry: ${{ env.REGISTRY }}          username: ${{ github.actor }}          password: ${{ secrets.GITHUB_TOKEN }}
      - name: Extract metadata        id: meta        uses: docker/metadata-action@v5        with:          images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}          tags: |            type=ref,event=branch            type=ref,event=pr            type=semver,pattern={{version}}            type=semver,pattern={{major}}.{{minor}}
      - name: Build and push        uses: docker/build-push-action@v5        with:          context: .          push: true          tags: ${{ steps.meta.outputs.tags }}          labels: ${{ steps.meta.outputs.labels }}          cache-from: type=gha          cache-to: type=gha,mode=max

Pattern 3: Deploy to Kubernetes

yaml
name: Deploy to Kubernetes
on:  push:    branches: [main]
jobs:  deploy:    runs-on: ubuntu-latest
    steps:      - uses: actions/checkout@v4
      - name: Configure AWS credentials        uses: aws-actions/configure-aws-credentials@v4        with:          aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}          aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}          aws-region: us-west-2
      - name: Update kubeconfig        run: |          aws eks update-kubeconfig --name production-cluster --region us-west-2
      - name: Deploy to Kubernetes        run: |          kubectl apply -f k8s/          kubectl rollout status deployment/my-app -n production          kubectl get services -n production
      - name: Verify deployment        run: |          kubectl get pods -n production          kubectl describe deployment my-app -n production

Pattern 4: Matrix Build

yaml
name: Matrix Build
on: [push, pull_request]
jobs:  build:    runs-on: ${{ matrix.os }}
    strategy:      matrix:        os: [ubuntu-latest, macos-latest, windows-latest]        python-version: ["3.9", "3.10", "3.11", "3.12"]
    steps:      - uses: actions/checkout@v4
      - name: Set up Python        uses: actions/setup-python@v5        with:          python-version: ${{ matrix.python-version }}
      - name: Install dependencies        run: |          python -m pip install --upgrade pip          pip install -r requirements.txt
      - name: Run tests        run: pytest

Workflow Best Practices

  1. Use specific action versions (@v4, not @latest)
  2. Cache dependencies to speed up builds
  3. Use secrets for sensitive data
  4. Implement status checks on PRs
  5. Use matrix builds for multi-version testing
  6. Set appropriate permissions
  7. Use reusable workflows for common patterns
  8. Implement approval gates for production
  9. Add notification steps for failures
  10. Use self-hosted runners for sensitive workloads

Reusable Workflows

yaml
# .github/workflows/reusable-test.ymlname: Reusable Test Workflow
on:  workflow_call:    inputs:      node-version:        required: true        type: string    secrets:      NPM_TOKEN:        required: true
jobs:  test:    runs-on: ubuntu-latest    steps:      - uses: actions/checkout@v4      - uses: actions/setup-node@v4        with:          node-version: ${{ inputs.node-version }}      - run: npm ci      - run: npm test

Use reusable workflow:

yaml
jobs:  call-test:    uses: ./.github/workflows/reusable-test.yml    with:      node-version: "20.x"    secrets:      NPM_TOKEN: ${{ secrets.NPM_TOKEN }}

Security Scanning

yaml
name: Security Scan
on:  push:    branches: [main]  pull_request:    branches: [main]
jobs:  security:    runs-on: ubuntu-latest
    steps:      - uses: actions/checkout@v4
      - name: Run Trivy vulnerability scanner        uses: aquasecurity/[email protected]        with:          scan-type: "fs"          scan-ref: "."          format: "sarif"          output: "trivy-results.sarif"
      - name: Upload Trivy results to GitHub Security        uses: github/codeql-action/upload-sarif@v3        with:          sarif_file: "trivy-results.sarif"
      - name: Run Snyk Security Scan        uses: snyk/actions/[email protected]        env:          SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}

Deployment with Approvals

yaml
name: Deploy to Production
on:  push:    tags: ["v*"]
jobs:  deploy:    runs-on: ubuntu-latest    environment:      name: production      url: https://app.example.com
    steps:      - uses: actions/checkout@v4
      - name: Deploy application        run: |          echo "Deploying to production..."          # Deployment commands here
      - name: Notify Slack        if: success()        uses: slackapi/slack-github-action@v1        with:          webhook-url: ${{ secrets.SLACK_WEBHOOK }}          payload: |            {              "text": "Deployment to production completed successfully!"            }

Related Skills

  • gitlab-ci-patterns - For GitLab CI workflows
  • deployment-pipeline-design - For pipeline architecture
  • secrets-management - For secrets handling

來源與署名

來源:wshobson/agents位於plugins/cicd-automation/skills/github-actions-templates提交46891e7

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架