DevOps30-45 min
GitHub Actions CI Pipeline
Create a CI workflow that installs dependencies from lockfile, caches package downloads, and blocks broken pull requests before merge.
GitHub ActionsNode.jsCI/CD
Prerequisites
- A GitHub repository.
- Working local commands for lint, test, and build.
- A committed package lockfile.
1
Plan the implementation
Start by choosing the exact page, route, API, or deployment surface you want to improve. A narrow target makes the implementation measurable and easier to verify.
- Write down the current behavior and the user-facing problem it creates.
- Pick one measurable success signal such as bundle size, latency, error rate, security coverage, or UI responsiveness.
- Identify the files, routes, providers, and environment variables involved.
- Create a rollback note before changing production-sensitive configuration.
2
Set up the required tools
Install or configure only the tools needed for this implementation. Keep config close to the feature so future developers can find the moving parts quickly.
Implementation snippet
mkdir -p .github/workflowsChecklist
- Dependencies are added to the correct workspace package.
- Environment variables are documented in `.env.example` when needed.
- Local development still starts without production-only secrets.
- The change is small enough to review in one pull request.
3
Implement the core pattern
- Create a workflow file under `.github/workflows`.
- Use `actions/checkout` and `actions/setup-node`.
- Install dependencies with `npm ci`.
- Run lint, tests, and build in the same order developers run locally.
- Protect the main branch with the CI check when ready.
Implementation snippet
name: CI
on: [push, pull_request]
jobs:
test:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
with:
node-version: 20
cache: npm
- run: npm ci
- run: npm run lint --if-present
- run: npm test --if-present
- run: npm run build4
Handle edge cases
Checklist
- CI uses the same Node major version as production.
- Secrets are used only for steps that require them.
- The workflow fails on broken builds.
- Pull requests show a clear status check.
5
Verify before production
- Run the app locally and test the normal success path.
- Test one failure path, one empty state, and one slow-network or retry path.
- Run the project build and any related unit or integration tests.
- Check browser console, server logs, and network responses for hidden warnings.
- Document the final behavior, commands used, and any follow-up work.