Chapter 06 · GitHub Actions
Deploy automatically from GitHub
Turn the manual git push → SSH → git pull process into a repeatable deployment every time the main branch changes.
Create and push the portfolio
Create a project with index.html, style.css, and script.js, then initialize Git and push it to a GitHub repository.
mkdir my-portfolio
cd my-portfolio
git init
git add .
git commit -m "Initial portfolio"
git branch -M main
git remote add origin https://github.com/USERNAME/student-portfolio.git
git push -u origin mainDeploy to EC2 once manually
On Ubuntu, install Git, clear the Apache document root, and clone the repository. Use a public repository for this classroom exercise so git pull does not need another credential.
sudo apt update
sudo apt install git -y
cd /var/www/html
sudo rm -rf /var/www/html/*
sudo git clone https://github.com/USERNAME/student-portfolio.git .
sudo chown -R ubuntu:ubuntu /var/www/htmlCreate a deployment key
Generate a dedicated key on your local computer, add its public key to ~/.ssh/authorized_keys on EC2, and verify that the new key can connect before touching GitHub Actions.
ssh-keygen -t ed25519 -C "github-actions-deploy"
cat ~/.ssh/github-actions-deploy.pub
ssh -i ~/.ssh/github-actions-deploy ubuntu@EC2_PUBLIC_IPssh-keygen -t ed25519 -C "github-actions-deploy"
Get-Content $HOME\.ssh\github-actions-deploy.pub
ssh -i $HOME\.ssh\github-actions-deploy ubuntu@EC2_PUBLIC_IPAdd GitHub repository secrets
In Settings → Secrets and variables → Actions, create EC2_HOST with the public IP, EC2_USER with ubuntu, and EC2_SSH_KEY with the complete private key. Never commit private keys.
Add the workflow
Create .github/workflows/deploy.yml and commit it to the main branch.
name: Deploy Portfolio
on:
push:
branches:
- main
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- name: Deploy to EC2
uses: appleboy/ssh-action@v1
with:
host: ${{ secrets.EC2_HOST }}
username: ${{ secrets.EC2_USER }}
key: ${{ secrets.EC2_SSH_KEY }}
script: |
cd /var/www/html
git pull origin maingit add ., git commit -m "Update portfolio", and git push. Watch the Actions tab, then refresh http://EC2_PUBLIC_IP.Jenkins alternative
If you prefer a self-hosted automation server, install Jenkins on a separate Ubuntu host, install the Git and SSH Agent plugins, then create a Pipeline job connected to your GitHub repository. Store the EC2 private key in Jenkins Credentials as an SSH credential and never paste it into the Jenkinsfile.
sudo apt update
sudo apt install fontconfig openjdk-21-jre -y
sudo wget -O /etc/apt/keyrings/jenkins-keyring.asc https://pkg.jenkins.io/debian-stable/jenkins.io-2023.key
echo "deb [signed-by=/etc/apt/keyrings/jenkins-keyring.asc] https://pkg.jenkins.io/debian-stable binary/" | sudo tee /etc/apt/sources.list.d/jenkins.list
sudo apt update
sudo apt install jenkins -y
sudo systemctl enable --now jenkinspipeline {
agent any
stages {
stage("Deploy") {
steps {
sshagent(["ec2-deploy-key"]) {
sh "ssh -o StrictHostKeyChecking=no ubuntu@${EC2_HOST} \"cd /var/www/html && git pull origin main\""
}
}
}
}
}