Lesson 2: CI/CD Pipelines (GitHub Actions)
🧠 The Concept (Explain Like I'm 5)
A CI/CD Pipeline is a car assembly line. When a developer finishes a piece of code, it goes onto the conveyor belt. Robots automatically check if the code works (Testing), if it's safe (Security Scanning), and then automatically drive the finished car to the dealership (Deployment).
🏢 The Enterprise Context
- Reusable Workflows: Platform teams build centralized GitHub Actions templates (e.g.,
build-go-app.yml). Development teams just reference this template, ensuring every app across the company follows the exact same security and build steps. - Runners: Enterprises don't use public GitHub runners for sensitive code. They deploy Self-Hosted Runners (often using actions-runner-controller) inside their own Kubernetes clusters.
🗺️ Visual Architecture: The Enterprise CI Pipeline
flowchart LR
Commit["git push"] --> Lint["Lint & Unit Tests"]
Lint --> Sonar["SonarQube<br/>(Code Quality)"]
Sonar --> Build["Docker Build"]
Build --> Trivy["Trivy Image Scan"]
Trivy --> Push["Push to ECR"]
Push --> GitOps["Update Helm/Kustomize Repo"]