github-actions-templates
wshobson/agents
Production-ready GitHub Actions workflow templates for CI/CD, testing, building, and deployment.
What is github-actions-templates?
A collection of battle-tested GitHub Actions workflow patterns for continuous integration and deployment. Use this skill when setting up automated testing, building Docker images, deploying to Kubernetes, running security scans, or creating reusable workflow templates across your projects.
- Generate test workflows with matrix builds for multiple Node.js/Python versions
- Create Docker build and push workflows with registry authentication and caching
- Deploy applications to Kubernetes clusters with AWS EKS integration
- Run security scans using Trivy and Snyk with SARIF reporting
- Build reusable workflows for common CI/CD patterns
- Implement approval gates and notifications for production deployments
How to install github-actions-templates
npx skills add https://github.com/wshobson/agents --skill github-actions-templates- GitHub repository with Actions enabled
- Docker Hub or container registry credentials (for build/push workflows)
- AWS credentials and EKS cluster access (for Kubernetes deployment patterns)
- Snyk or Trivy API tokens (for security scanning workflows)
How to use github-actions-templates
- 1.Choose the workflow pattern that matches your use case (test, build, deploy, or matrix)
- 2.Copy the YAML template into your repository's .github/workflows/ directory
- 3.Replace placeholder values (repository name, AWS region, cluster name, etc.) with your environment details
- 4.Add required secrets to your GitHub repository settings (GITHUB_TOKEN, AWS credentials, SNYK_TOKEN, etc.)
- 5.Commit and push the workflow file to trigger the automation on your specified events (push, pull_request, tags)
Use cases
- Automate testing across multiple Node.js versions on every push and pull request
- Build and push Docker images to container registries on tag creation
- Deploy applications to Kubernetes with rollout status verification
- Run multi-platform builds across Ubuntu, macOS, and Windows runners
- Scan dependencies and filesystem for vulnerabilities before deployment
- DevOps engineers setting up CI/CD pipelines
- Backend developers automating application testing and deployment
- Platform teams creating standardized workflow templates
- Teams deploying containerized applications to Kubernetes
- Security-focused teams implementing automated vulnerability scanning
github-actions-templates FAQ
The test pattern runs a single job with matrix strategy for Node.js versions. The matrix build pattern tests across multiple operating systems (Ubuntu, macOS, Windows) and Python versions simultaneously, useful for cross-platform compatibility.
Yes, sensitive data like AWS credentials, container registry tokens, and API keys must be added to your GitHub repository settings under Settings > Secrets and variables > Actions before the workflows can run.
Yes, the build and push pattern uses docker/login-action which supports any registry. Update the REGISTRY environment variable and provide appropriate credentials in secrets.
Use the 'on' trigger configuration with branches and tags filters. For example, 'on: push: branches: [main] tags: [v*]' runs on main branch pushes and version tags.
Reusable workflows are defined once and called from multiple workflows, reducing duplication. Use them when you have common patterns (like testing) needed across multiple jobs or repositories.
Full instructions (SKILL.md)
Source of truth, from wshobson/agents.
name: github-actions-templates description: Create production-ready GitHub Actions workflows for automated testing, building, and deploying applications. Use when setting up CI/CD with GitHub Actions, automating development workflows, or creating reusable workflow templates.
GitHub Actions Templates
Production-ready GitHub Actions workflow patterns for testing, building, and deploying applications.
Purpose
Create efficient, secure GitHub Actions workflows for continuous integration and deployment across various tech stacks.
When to Use
- Automate testing and deployment
- Build Docker images and push to registries
- Deploy to Kubernetes clusters
- Run security scans
- Implement matrix builds for multiple environments
Common Workflow Patterns
Pattern 1: Test Workflow
name: Test
on:
push:
branches: [main, develop]
pull_request:
branches: [main]
jobs:
test:
runs-on: ubuntu-latest
strategy:
matrix:
node-version: [18.x, 20.x]
steps:
- uses: actions/checkout@v4
- name: Use Node.js ${{ matrix.node-version }}
uses: actions/setup-node@v4
with:
node-version: ${{ matrix.node-version }}
cache: "npm"
- name: Install dependencies
run: npm ci
- name: Run linter
run: npm run lint
- name: Run tests
run: npm test
- name: Upload coverage
uses: codecov/codecov-action@v4
with:
files: ./coverage/lcov.info
Pattern 2: Build and Push Docker Image
name: Build and Push
on:
push:
branches: [main]
tags: ["v*"]
env:
REGISTRY: ghcr.io
IMAGE_NAME: ${{ github.repository }}
jobs:
build:
runs-on: ubuntu-latest
permissions:
contents: read
packages: write
steps:
- uses: actions/checkout@v4
- name: Log in to Container Registry
uses: docker/login-action@v3
with:
registry: ${{ env.REGISTRY }}
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: Extract metadata
id: meta
uses: docker/metadata-action@v5
with:
images: ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
tags: |
type=ref,event=branch
type=ref,event=pr
type=semver,pattern={{version}}
type=semver,pattern={{major}}.{{minor}}
- name: Build and push
uses: docker/build-push-action@v5
with:
context: .
push: true
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
cache-from: type=gha
cache-to: type=gha,mode=max
Pattern 3: Deploy to Kubernetes
name: Deploy to Kubernetes
on:
push:
branches: [main]
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Configure AWS credentials
uses: aws-actions/configure-aws-credentials@v4
with:
aws-access-key-id: ${{ secrets.AWS_ACCESS_KEY_ID }}
aws-secret-access-key: ${{ secrets.AWS_SECRET_ACCESS_KEY }}
aws-region: us-west-2
- name: Update kubeconfig
run: |
aws eks update-kubeconfig --name production-cluster --region us-west-2
- name: Deploy to Kubernetes
run: |
kubectl apply -f k8s/
kubectl rollout status deployment/my-app -n production
kubectl get services -n production
- name: Verify deployment
run: |
kubectl get pods -n production
kubectl describe deployment my-app -n production
Pattern 4: Matrix Build
name: Matrix Build
on: [push, pull_request]
jobs:
build:
runs-on: ${{ matrix.os }}
strategy:
matrix:
os: [ubuntu-latest, macos-latest, windows-latest]
python-version: ["3.9", "3.10", "3.11", "3.12"]
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: ${{ matrix.python-version }}
- name: Install dependencies
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt
- name: Run tests
run: pytest
Workflow Best Practices
- Use specific action versions (@v4, not @latest)
- Cache dependencies to speed up builds
- Use secrets for sensitive data
- Implement status checks on PRs
- Use matrix builds for multi-version testing
- Set appropriate permissions
- Use reusable workflows for common patterns
- Implement approval gates for production
- Add notification steps for failures
- Use self-hosted runners for sensitive workloads
Reusable Workflows
# .github/workflows/reusable-test.yml
name: Reusable Test Workflow
on:
workflow_call:
inputs:
node-version:
required: true
type: string
secrets:
NPM_TOKEN:
required: true
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: ${{ inputs.node-version }}
- run: npm ci
- run: npm test
Use reusable workflow:
jobs:
call-test:
uses: ./.github/workflows/reusable-test.yml
with:
node-version: "20.x"
secrets:
NPM_TOKEN: ${{ secrets.NPM_TOKEN }}
Security Scanning
name: Security Scan
on:
push:
branches: [main]
pull_request:
branches: [main]
jobs:
security:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.28.0
with:
scan-type: "fs"
scan-ref: "."
format: "sarif"
output: "trivy-results.sarif"
- name: Upload Trivy results to GitHub Security
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: "trivy-results.sarif"
- name: Run Snyk Security Scan
uses: snyk/actions/node@0.4.0
env:
SNYK_TOKEN: ${{ secrets.SNYK_TOKEN }}
Deployment with Approvals
name: Deploy to Production
on:
push:
tags: ["v*"]
jobs:
deploy:
runs-on: ubuntu-latest
environment:
name: production
url: https://app.example.com
steps:
- uses: actions/checkout@v4
- name: Deploy application
run: |
echo "Deploying to production..."
# Deployment commands here
- name: Notify Slack
if: success()
uses: slackapi/slack-github-action@v1
with:
webhook-url: ${{ secrets.SLACK_WEBHOOK }}
payload: |
{
"text": "Deployment to production completed successfully!"
}
Related Skills
gitlab-ci-patterns- For GitLab CI workflowsdeployment-pipeline-design- For pipeline architecturesecrets-management- For secrets handling
Related skills
More from wshobson/agents and the wider catalog.

gitlab-ci-patterns
Build scalable GitLab CI/CD pipelines with multi-stage workflows, caching, and Kubernetes deployment patterns.

gitops-workflow
Implement GitOps workflows with ArgoCD and Flux for automated, declarative Kubernetes deployments.

go-concurrency-patterns
Master Go concurrency with goroutines, channels, sync primitives, and context management.

godot-gdscript-patterns
Master Godot 4 GDScript patterns: signals, scenes, state machines, and optimization for game development.

grafana-dashboards
Create and manage production Grafana dashboards for real-time system and application metric visualization.

grpo-rlvr-training
Train reasoning models with GRPO and reinforcement learning from verifiable rewards when task success is algorithmically checkable.