All capabilities · Cloud, deployment & production

Automate builds, tests and deploys with CI/CD

GitHub Actions pipelines that test, build images and deploy on merge.

~6 focused hoursintermediate
Explore 3 tools for this project
Market relevance

Which roles ask for this — and how often

Share of job postings in India, per role, that name this capability.

What employers mean

You should be able to…

  1. Write a GitHub Actions workflow that runs tests on every push/PR
  2. Build and push a Docker image to a registry automatically on merge to main
  3. Fail a PR's checks if tests or linting fail, blocking a bad merge
  4. Store and use secrets (API keys, cloud credentials) safely in a workflow
  5. Deploy to staging/production automatically after CI passes, with a manual approval gate for prod
  6. Cache dependencies in CI so builds don't reinstall everything every run
  7. Debug a failing CI run from the logs without re-running blindly

Needs first: Containerize an application with Docker, Collaborate with Git and GitHub

Learn — free, link-checked

The few resources that matter

Tools for practice

Choose a tool for the job

Start with one tool for each part of your project. You don’t need to learn them all.

Go to the practice brief

3 tools to explore

GitHub Actions

Test · Deploy

Run checks and deployment steps automatically when project code changes.

Docker

Deploy · Build

Package a service with its dependencies and run a repeatable local environment.

Practices & references

  • Environment secrets
  • Branch protection
  • Rollback checks
Practice

Test-to-deploy pipeline for the ticket API

Add a GitHub Actions workflow to your containerized ticket-API repo that runs pytest and a linter on every pull request, builds and pushes a Docker image to GHCR tagged with the commit SHA on merge to main, and deploys only after a manual approval. Protect main so nothing merges with a red check. Actions minutes are free on public repos, so the whole pipeline costs nothing to run.

Start from

Your containerized ticket-API repo on GitHub — Actions minutes are free on public repositories

Milestones
  1. Workflow that runs pytest and the linter on every pull request · ~1h
  2. Build and push to GHCR on merge to main, tagged with the commit SHA · ~1.5h
  3. Add a deploy job gated behind a GitHub Environment with a required reviewer · ~1h
  4. Turn on branch protection and open a knowingly broken PR to prove it blocks · ~1h
Done when
  • PRs show required status checks (tests, lint) that must pass before merge is allowed
  • Merging to main triggers an automatic Docker build+push with a commit-sha or semver tag
  • Deploy to the live environment requires a manual approval step, visible in the Actions run
  • A deliberately broken PR is shown being blocked by failing CI, with a screenshot/link
Prove it

Evidence a recruiter can check

  • A blocked pull request: the failing check, the merge button greyed out, and the commit that turned it green
  • An Actions run paused on manual approval, then released to deploy, with both timestamps visible
  • GHCR tags matching commit SHAs, so any running image traces back to the exact commit that built it
  • The workflow run time before and after you added dependency caching
Signal it

Built a GitHub Actions pipeline gating every PR on tests and lint, publishing SHA-tagged images to GHCR on merge, and deploying only behind manual approval — with branch protection blocking red PRs from landing.

Interview

Questions you'll get asked

  1. Walk me through a GitHub Actions workflow that tests, builds and deploys a Python service.
  2. How do you store and use a cloud deploy credential securely in a GitHub Actions workflow?
  3. How would you set up a pipeline that requires manual approval before deploying to production?
  4. A CI run is failing only in the pipeline, not locally — how do you debug it?
  5. How do you speed up a slow CI pipeline that reinstalls all dependencies every run?
  6. How do you prevent a broken PR from being merged into main?