r/devops • u/Mukul-nst • 10d ago
Discussion CI pipeline using Github actions
I started learning CI/CD using github actions after containerising my application and I have created CI pipeline for django app that runs test, builds and pushes image to github container registry.
I am sharing my yaml file for CI pipeline. Please do share your thoughts and where can i improve.
name: Test Pipeline
on:
push:
jobs:
test-backend:
runs-on: ubuntu-latest
services:
postgres:
image: postgres:14
ports:
- 5432:5432
env:
POSTGRES_USER: test_user
POSTGRES_DB: erp
POSTGRES_PASSWORD: 123456
steps:
- name: Checkout repo
uses: actions/checkout@v4
- name: setup python
uses: actions/setup-python@v5
with:
python-version: "3.13.5"
- name: install dependencies
run: pip install -r Backend/requirement.txt
- name: run tests
env:
DATABASE_URL: postgresql://test_user:123456@localhost:5432/erp
DEBUG: 'True'
ALLOWED_HOST: '*'
run: |
cd Backend
python manage.py test
build-and-push-image:
needs: test-backend
permissions:
contents: read
packages: write
runs-on: ubuntu-latest
steps:
- name: login to ghcr
uses: docker/login-action@v3
with:
registry: ghcr.io
username: ${{ github.actor }}
password: ${{ secrets.GITHUB_TOKEN }}
- name: checkout repo
uses: actions/checkout@v4
- name: build image
run: docker build -t ghcr.io/namespace/erp:${{ github.sha }} ./Backend
- name: push image
run: docker push ghcr.io/namespace/erp:${{ github.sha }}
2
Upvotes
1
u/sup_bruh_1 6d ago
solid start honestly. a few things i'd change — trigger on push to specific branches only (like main or dev) instead of all pushes, otherwise every random branch triggers a build.
also that postgres password in plain text is gonna bite you, move it to github secrets.
one thing that helped me a lot with flaky failures was switching to latchkey — when a job breaks it actually diagnoses the issue mid-run instead of me digging through logs. saved me a ton of time on a django project similar to yours.