<< All versions
Skill v1.0.0
currentAutomated scan100/100ghosteken/agent-harness/github-actions-templates
──Details
PublishedSeptember 27, 2026 at 11:58 PM
Content Hashsha256:85b48122bcc12ac4...
Git SHA3dbf855ca8ed
──Files
Files (1 file, 7.6 KB)
SKILL.md7.6 KBactive
SKILL.md · 350 lines · 7.6 KB
version: "1.0.0" name: github-actions-templates description: Production-ready GitHub Actions workflow patterns for testing, building, and deploying applications.
GitHub Actions Templates
Production-ready GitHub Actions workflow patterns for testing, building, and deploying applications.
Do not use this skill when
- The task is unrelated to github actions templates
- You need a different domain or tool outside this scope
Instructions
- Clarify goals, constraints, and required inputs.
- Apply relevant best practices and validate outcomes.
- Provide actionable steps and verification.
- If detailed examples are required, open
resources/implementation-playbook.md.
Purpose
Create efficient, secure GitHub Actions workflows for continuous integration and deployment across various tech stacks.
Use this skill when
- Automate testing and deployment
- Build Docker images and push to registries
- Deploy to Kubernetes clusters
- Run security scans
- Implement matrix builds for multiple environments
Common Workflow Patterns
Pattern 1: Test Workflow
yaml
name: Teston:push:branches: [ main, develop ]pull_request:branches: [ main ]jobs:test:runs-on: ubuntu-lateststrategy:matrix:node-version: [18.x, 20.x]steps:- uses: actions/checkout@v4- name: Use Node.js ${{ matrix.node-version }}uses: actions/setup-node@v4with:node-version: ${{ matrix.node-version }}cache: 'npm'- name: Install dependenciesrun: npm ci- name: Run linterrun: npm run lint- name: Run testsrun: npm test- name: Upload coverageuses: codecov/codecov-action@v3with:files: ./coverage/lcov.info
Reference: See assets/test-workflow.yml
Pattern 2: Build and Push Docker Image
yaml
name: Build and Pushon:push:branches: [ main ]tags: [ 'v*' ]env:REGISTRY: ghcr.ioIMAGE_NAME: ${{ github.repository }}jobs:build:runs-on: ubuntu-latestpermissions:contents: readpackages: writesteps:- uses: actions/checkout@v4- name: Log in to Container Registryuses: docker/login-action@v3with:registry: ${{ env.REGISTRY }}username: ${{ github.actor }}password: ${{ secrets.GITHUB_TOKEN }}- name: Extract metadataid: metauses: docker/metadata-action@v5with:images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}tags: |type=ref,event=branchtype=ref,event=prtype=semver,pattern={{version}}type=semver,pattern={{major}}.{{minor}}- name: Build and pushuses: docker/build-push-action@v5with:context: .push: truetags: ${{ steps.meta.outputs.tags }}labels: ${{ steps.meta.outputs.labels }}cache-from: type=ghacache-to: type=gha,mode=max
Reference: See assets/deploy-workflow.yml
Pattern 3: Deploy to Kubernetes
yaml
name: Deploy to Kuberneteson:push:branches: [ main ]jobs:deploy:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v4- name: Configure AWS credentialsuses: aws-actions/configure-aws-credentials@v4with:aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}aws-region: us-west-2- name: Update kubeconfigrun: |aws eks update-kubeconfig --name production-cluster --region us-west-2- name: Deploy to Kubernetesrun: |kubectl apply -f k8s/kubectl rollout status deployment/my-app -n productionkubectl get services -n production- name: Verify deploymentrun: |kubectl get pods -n productionkubectl describe deployment my-app -n production
Pattern 4: Matrix Build
yaml
name: Matrix Buildon: [push, pull_request]jobs:build:runs-on: ${{ matrix.os }}strategy:matrix:os: [ubuntu-latest, macos-latest, windows-latest]python-version: ['3.9', '3.10', '3.11', '3.12']steps:- uses: actions/checkout@v4- name: Set up Pythonuses: actions/setup-python@v5with:python-version: ${{ matrix.python-version }}- name: Install dependenciesrun: |python -m pip install --upgrade pippip install -r requirements.txt- name: Run testsrun: pytest
Reference: See assets/matrix-build.yml
Workflow Best Practices
- Use specific action versions (@v4, not @latest)
- Cache dependencies to speed up builds
- Use secrets for sensitive data
- Implement status checks on PRs
- Use matrix builds for multi-version testing
- Set appropriate permissions
- Use reusable workflows for common patterns
- Implement approval gates for production
- Add notification steps for failures
- Use self-hosted runners for sensitive workloads
Reusable Workflows
yaml
# .github/workflows/reusable-test.ymlname: Reusable Test Workflowon:workflow_call:inputs:node-version:required: truetype: stringsecrets:NPM_TOKEN:required: truejobs:test:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v4- uses: actions/setup-node@v4with:node-version: ${{ inputs.node-version }}- run: npm ci- run: npm test
Use reusable workflow:
yaml
jobs:call-test:uses: ./.github/workflows/reusable-test.ymlwith:node-version: '20.x'secrets:NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
Security Scanning
yaml
name: Security Scanon:push:branches: [ main ]pull_request:branches: [ main ]jobs:security:runs-on: ubuntu-lateststeps:- uses: actions/checkout@v4- name: Run Trivy vulnerability scanneruses: aquasecurity/trivy-action@masterwith:scan-type: 'fs'scan-ref: '.'format: 'sarif'output: 'trivy-results.sarif'- name: Upload Trivy results to GitHub Securityuses: github/codeql-action/upload-sarif@v2with:sarif_file: 'trivy-results.sarif'- name: Run Snyk Security Scanuses: snyk/actions/node@masterenv:SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
Deployment with Approvals
yaml
name: Deploy to Productionon:push:tags: [ 'v*' ]jobs:deploy:runs-on: ubuntu-latestenvironment:name: productionurl: https://app.example.comsteps:- uses: actions/checkout@v4- name: Deploy applicationrun: |echo "Deploying to production..."# Deployment commands here- name: Notify Slackif: success()uses: slackapi/slack-github-action@v1with:webhook-url: ${{ secrets.SLACK_WEBHOOK }}payload: |{"text": "Deployment to production completed successfully!"}
Reference Files
assets/test-workflow.yml- Testing workflow templateassets/deploy-workflow.yml- Deployment workflow templateassets/matrix-build.yml- Matrix build templatereferences/common-workflows.md- Common workflow patterns
Related Skills
secrets-management- For secrets handling
Limitations
- Use this skill only when the task clearly matches the scope described above.
- Do not treat the output as a substitute for environment-specific validation, testing, or expert review.
- Stop and ask for clarification if required inputs, permissions, safety boundaries, or success criteria are missing.