Production-style GitHub Actions workflows demonstrating a complete container build → test → deploy pipeline for Kubernetes.
| Workflow | Trigger | What It Does |
|---|---|---|
build-and-push-docker.yml |
Push to main, version tags, PRs |
Builds a Docker image, tags it (branch/semver/SHA), and pushes to GitHub Container Registry |
deploy-to-k8s.yml |
After a successful build, or manual dispatch | Deploys the new image to Kubernetes via Helm, then verifies the rollout |
helm-lint-test.yml |
Pull requests touching chart files | Lints and template-renders every Helm chart to catch broken YAML before merge |
| Secret | Used By | Purpose |
|---|---|---|
GITHUB_TOKEN |
build-and-push-docker.yml |
Auto-provided by GitHub Actions; authenticates to GHCR |
KUBE_CONFIG |
deploy-to-k8s.yml |
Base64-encoded kubeconfig for the target cluster |
Add KUBE_CONFIG via: Repo Settings → Secrets and variables → Actions → New repository secret
cat ~/.kube/config | base64 -w 0
# paste the output as the secret valuedeploy-to-k8s.ymldeploys via Helm (not rawkubectl apply) so every release is versioned and instantly rollback-able withhelm rollback.helm-lint-test.ymlruns on every PR touching chart files, catching template errors before they reachmain.- Image tags include the Git SHA for traceability — every running Pod can be traced back to the exact commit that built it.
Pramod Ramesh Belal — AWS DevOps Engineer LinkedIn · pramodbelal29@gmail.com