Lab: deploy from CI

Verified lab · 30 min · Module 8, lesson 5 of 635 min left in this module

Module 8 · Deploy as codeLesson 5 of 6

Self-checked for now. Automatic checking arrives with sign-in; until then, tick off each item under Check your work yourself.

Goal: Build an image in GitHub Actions and deploy it to ComputeSphere on every push to main, then watch a change go live.

You need A GitHub account, csph signed in, and your lab project and environment IDs (lesson 5.1.1).

Why two tokens?

The ComputeSphere token (csph_…) lets the workflow deploy. The GitHub pull token lets ComputeSphere pull your private image from GitHub's registry, today and whenever it starts a spherelet later. The workflow's own GITHUB_TOKEN pushes the image, but it expires when the job ends, so ComputeSphere can't use it.

  1. Fork the sample and turn on Actions

    Fork computesphere-nodejs-example, a small Express app with a Dockerfile, on port 3000. GitHub turns Actions off in forks: open the fork's Actions tab and enable workflows.

    You should seeYour fork's Actions tab lets you run workflows.

  2. Create a ComputeSphere token

    In the console: Settings, Accounts, your account, Tokens, New token. Name it gh-actions-deploy, choose Project access and your lab project, set an expiry, choose Create token. It's shown once.

    You should seeA token starting csph_, copied.

  3. Create a GitHub pull token

    On GitHub: your profile's Settings, Developer settings, Personal access tokens, Tokens (classic). Generate one with only read:packages.

    You should seeA classic token with only read:packages, copied.

  4. Store both in the fork

    In the fork: Settings, Secrets and variables, Actions. Add secrets COMPUTESPHERE_API_TOKEN and GHCR_PULL_TOKEN, and variables COMPUTESPHERE_PROJECT_ID and COMPUTESPHERE_ENV_ID.

    You should seeTwo secrets and two variables listed.

  5. Add the workflow and commit to main

    In the fork on GitHub, choose Add file, then Create new file, name it .github/workflows/deploy.yaml, paste this, and commit to main:

    name: Deploy
    on:
      push:
        branches: [main]
      workflow_dispatch:
    permissions:
      contents: read
      packages: write
    jobs:
      deploy:
        runs-on: ubuntu-latest
        steps:
          - uses: actions/checkout@v4
          - id: image
            run: echo "ref=ghcr.io/${GITHUB_REPOSITORY,,}:${GITHUB_SHA::12}" >> "$GITHUB_OUTPUT"
          - uses: docker/login-action@v3
            with:
              registry: ghcr.io
              username: ${{ github.actor }}
              password: ${{ secrets.GITHUB_TOKEN }}
          - uses: docker/build-push-action@v6
            with:
              context: .
              push: true
              tags: ${{ steps.image.outputs.ref }}
          - id: deploy
            uses: computesphere/deploy@v1
            with:
              token: ${{ secrets.COMPUTESPHERE_API_TOKEN }}
              image: ${{ steps.image.outputs.ref }}
              name: nodejs-ci
              port: "3000"
              registry-url: https://ghcr.io
              registry-username: ${{ github.actor }}
              registry-password: ${{ secrets.GHCR_PULL_TOKEN }}
              project: ${{ vars.COMPUTESPHERE_PROJECT_ID }}
              environment: ${{ vars.COMPUTESPHERE_ENV_ID }}
          - run: echo "${{ steps.deploy.outputs.status }} → ${{ steps.deploy.outputs.service-url }}"
    

    You should seeA Deploy run starts in the Actions tab.

  6. Watch it go live

    Open the running Deploy workflow. The build takes a minute or two, then the deploy step waits for Running. Open the URL it prints.

    Check yourself

    Every commit gets its own image tag. What does that give you?

    You should seeA green run whose last step prints created and your URL.

  7. Change something

    Edit public/home.html, change some visible text, and commit to main. The old version serves until the new one is healthy; reload once the run is green.

    You should seeThe last step says updated, with the same URL, and the page shows your change.

What the workflow does
  • The image step names the image after your repository in lower case (,, lowercases it in bash) and tags it with the first 12 characters of the commit.
  • packages: write lets the job push to your registry with its short-lived GITHUB_TOKEN.
  • The deploy step deploys that image as web service nodejs-ci on port 3000, with your lasting pull token.

When you're done, stop nodejs-ci, revoke gh-actions-deploy in the console, and delete the GitHub pull token.

Check your work

  • If this doesn't pass

    Open the red step's log. An authentication error means a secret is missing or misnamed; an image-pull error means the pull token lacks read:packages.

  • If this doesn't pass

    If it ended Failed, open its deploy log. The port must be 3000, the port the sample listens on.

  • If this doesn't pass

    Commit a change to main so the workflow runs again, and wait for the run to go green.

In the docs