| image | https://learn.microsoft.com/en-us/media/learn/certification/badges/github-actions.svg |
|---|---|
| tags | GH-200, Reference |
| GA | G-DXYJBX6BH8 |
Build, test, package, deploy, troubleshoot, secure, and govern software-development automation with GitHub Actions.
:::success Date: 20260903 Course ID: 109066 :::
:::info Post Course Survey: https://aka.ms/gh200survey :::
Course GH-200 English version Course GH-200 简体中文版本 Course GH-200 正體中文版本
Learner Experience Portal ESI Support
ESI Labs :::success Training key: 53F35FFC16441C69 :::
Exercise - Create and run a basic GitHub Actions workflow
Exercise - Create the CI workflow on GitHub
Exercise - Create a workflow that deploys a web app to Azure
Exercise - Work with workflow artifacts in GitHub Actions
Exercise - Deploy a containerized app to Azure with GitHub Actions
Exercise - Publish to a GitHub Packages registry
Exercise - Create a custom JavaScript GitHub action
Understanding GitHub Actions and its components
Variables and default environment variables
GitHub Actions billing and usage
Finding and customizing actions
Manual workflow_dispatch events
Workflow commands, GITHUB_ENV, and GITHUB_OUTPUT
Manage environments and protection rules
Using secrets in GitHub Actions
Authenticate to Azure from GitHub Actions with OIDC
Microsoft Entra federated identity credential trust
Artifact and log retention policy
Using GITHUB_TOKEN for authentication
GITHUB_TOKEN permissions and security
Publish Docker images with GitHub Actions
Publish Node.js packages with GitHub Actions
Package permissions and visibility
Artifact attestations and provenance
Create a Docker container action
Publish actions in GitHub Marketplace
Immutable action releases and tags
GitHub Enterprise Cloud enterprise accounts
Organization Actions policies and allow-lists
Organization workflow templates
Require workflows to pass before merging with rulesets
Reusable workflow configurations and YAML anchors
Runner groups and access management
Private networking for runners
Managing Actions secrets through the REST API
Secure Actions use and full-SHA pinning
| No. | Name | Module | Link |
|---|---|---|---|
| 1 | Course Preview — GH-200 — Automate your workflow with GitHub Actions | Foundations | youtu.be/wuHiemCckNo |
| 2 | How to use GitHub Actions — GitHub for Beginners | M1 | youtu.be/BQrohJ3PT7I |
| 3 | 5 ways to automate everyday workflows with GitHub Actions | M2 | youtu.be/2p1D29zJdBI |
| 4 | Securely building GitHub on GitHub | M5 | youtu.be/eig5tJUl688 |
# GH-200
## Foundations & cross-cutting
- [Workflow, job, step, action, runner, and event](https://docs.github.com/en/actions/get-started/understand-github-actions)
- [Workflow syntax](https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax), [expressions](https://docs.github.com/en/actions/reference/workflows-and-actions/expressions), [contexts](https://docs.github.com/en/actions/reference/workflows-and-actions/contexts)
- **GitHub-hosted** vs **larger** vs **self-hosted runners**
- Usage, billing, and governance
## M01 - Automate development tasks
- Trigger automation from repository, manual, scheduled, and webhook events
- Container / JavaScript / composite [custom actions](https://docs.github.com/en/actions/concepts/workflows-and-actions/custom-actions)
- Workflow structure and action discovery
- **Lab**: create and run a basic workflow
## M02 - Continuous integration
- [Matrix strategies](https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#jobsjob_idstrategy) and [service containers](https://docs.github.com/en/actions/tutorials/use-containerized-services/use-docker-service-containers)
- [Dependency caching](https://docs.github.com/en/actions/concepts/workflows-and-actions/dependency-caching) vs [workflow artifacts](https://docs.github.com/en/actions/concepts/workflows-and-actions/workflow-artifacts)
- GITHUB_ENV / GITHUB_OUTPUT / GITHUB_STEP_SUMMARY
- YAML anchors, concurrency, debug logging
- **Lab**: build and troubleshoot a CI workflow
## M03 - Deploy to Azure
- [Environments and protection rules](https://docs.github.com/en/actions/concepts/workflows-and-actions/deployment-environments)
- [Azure Login](https://github.com/Azure/login) and [Web Apps Deploy](https://github.com/Azure/webapps-deploy)
- **Long-lived secrets** vs [**OIDC federation**](https://learn.microsoft.com/en-us/azure/developer/github/connect-from-azure-openid-connect)
- Artifacts, conditionals, status badges, and retention
- **Labs**: Web App deployment, artifacts, containerized deployment
## M04 - GitHub Script
- [actions/github-script](https://github.com/actions/github-script) and [Octokit REST.js](https://octokit.github.io/rest.js/v22/)
- Issues, comments, projects, and REST API calls
- Expression-based job filtering
- [GITHUB_TOKEN](https://docs.github.com/en/actions/concepts/security/github_token) permissions
- **Lab**: automate GitHub with a script
## M05 - GitHub Packages
- [GitHub Packages](https://docs.github.com/en/packages): container / npm / NuGet registries
- Authentication, permissions, and visibility
- Publish packages from workflows
- [Artifact attestations](https://docs.github.com/en/actions/concepts/security/artifact-attestations) and provenance
- **Lab**: publish to a package registry
## M06 - Custom actions
- [action.yml metadata](https://docs.github.com/en/actions/reference/workflows-and-actions/metadata-syntax)
- **JavaScript** vs **Docker container** vs **composite action**
- Actions Toolkit and workflow commands
- Marketplace publishing and release versioning
- [Mutable tags](https://docs.github.com/en/actions/how-tos/create-and-publish-actions/using-immutable-releases-and-tags-to-manage-your-actions-releases) vs **immutable releases**
- **Lab**: create a JavaScript action
## M07 - Enterprise management
- GitHub Enterprise Cloud vs GitHub Enterprise Server
- Organization and enterprise [Actions policies](https://docs.github.com/en/organizations/managing-organization-settings/disabling-or-limiting-github-actions-for-your-organization)
- Enforce required checks with [organization rulesets](https://docs.github.com/en/enterprise-cloud@latest/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets#require-workflows-to-pass-before-merging)
- **Starter workflow** vs [**reusable workflow**](https://docs.github.com/en/actions/how-tos/reuse-automations/reuse-workflows) vs **composite action**
- [Runner groups](https://docs.github.com/en/actions/concepts/runners/runner-groups), private networking, and autoscaling
- **GITHUB_TOKEN** vs **PAT**; encrypted secrets and least privilege
- [Full-SHA pinning](https://docs.github.com/en/actions/reference/security/secure-use#using-third-party-actions) and [script-injection mitigation](https://docs.github.com/en/actions/concepts/security/script-injections)
GitHub: MoneyDemo 66666666 20260903-GH200 Demo
Exam duration and exam experience
Microsoft certification exam sandbox
Renew your Microsoft Certifications for free
SVG: exam.svg
- Money Yu
- Mail: Money.Yu@microsoft.com
- LinkedIn:
@abc12207

