You need A GitHub account, csph signed in, and your lab project and environment IDs (lesson 5.1.1).
Why two tokens?
The ComputeSphere token (csph_…) lets the workflow deploy. The GitHub pull token lets ComputeSphere pull your private image from GitHub's registry, today and whenever it starts a spherelet later. The workflow's own GITHUB_TOKEN pushes the image, but it expires when the job ends, so ComputeSphere can't use it.
Fork the sample and turn on Actions
Fork computesphere-nodejs-example, a small Express app with a Dockerfile, on port 3000. GitHub turns Actions off in forks: open the fork's Actions tab and enable workflows.
You should seeYour fork's Actions tab lets you run workflows.
Create a ComputeSphere token
In the console: Settings, Accounts, your account, Tokens, New token. Name it
gh-actions-deploy, choose Project access and your lab project, set an expiry, choose Create token. It's shown once.You should seeA token starting csph_, copied.
Create a GitHub pull token
On GitHub: your profile's Settings, Developer settings, Personal access tokens, Tokens (classic). Generate one with only
read:packages.You should seeA classic token with only read:packages, copied.
Store both in the fork
In the fork: Settings, Secrets and variables, Actions. Add secrets
COMPUTESPHERE_API_TOKENandGHCR_PULL_TOKEN, and variablesCOMPUTESPHERE_PROJECT_IDandCOMPUTESPHERE_ENV_ID.You should seeTwo secrets and two variables listed.
Add the workflow and commit to main
In the fork on GitHub, choose Add file, then Create new file, name it
.github/workflows/deploy.yaml, paste this, and commit tomain:name: Deploy on: push: branches: [main] workflow_dispatch: permissions: contents: read packages: write jobs: deploy: runs-on: ubuntu-latest steps: - uses: actions/checkout@v4 - id: image run: echo "ref=ghcr.io/${GITHUB_REPOSITORY,,}:${GITHUB_SHA::12}" >> "$GITHUB_OUTPUT" - uses: docker/login-action@v3 with: registry: ghcr.io username: ${{ github.actor }} password: ${{ secrets.GITHUB_TOKEN }} - uses: docker/build-push-action@v6 with: context: . push: true tags: ${{ steps.image.outputs.ref }} - id: deploy uses: computesphere/deploy@v1 with: token: ${{ secrets.COMPUTESPHERE_API_TOKEN }} image: ${{ steps.image.outputs.ref }} name: nodejs-ci port: "3000" registry-url: https://ghcr.io registry-username: ${{ github.actor }} registry-password: ${{ secrets.GHCR_PULL_TOKEN }} project: ${{ vars.COMPUTESPHERE_PROJECT_ID }} environment: ${{ vars.COMPUTESPHERE_ENV_ID }} - run: echo "${{ steps.deploy.outputs.status }} → ${{ steps.deploy.outputs.service-url }}"You should seeA Deploy run starts in the Actions tab.
Watch it go live
Open the running Deploy workflow. The build takes a minute or two, then the deploy step waits for Running. Open the URL it prints.
Check yourself
You should seeA green run whose last step prints created and your URL.
Change something
Edit
public/home.html, change some visible text, and commit tomain. The old version serves until the new one is healthy; reload once the run is green.You should seeThe last step says updated, with the same URL, and the page shows your change.
What the workflow does
- The
imagestep names the image after your repository in lower case (,,lowercases it in bash) and tags it with the first 12 characters of the commit. packages: writelets the job push to your registry with its short-livedGITHUB_TOKEN.- The deploy step deploys that image as web service
nodejs-cion port 3000, with your lasting pull token.
When you're done, stop nodejs-ci, revoke gh-actions-deploy in the console, and delete the GitHub pull token.
Check your work
If this doesn't pass
Open the red step's log. An authentication error means a secret is missing or misnamed; an image-pull error means the pull token lacks read:packages.
If this doesn't pass
If it ended Failed, open its deploy log. The port must be 3000, the port the sample listens on.
If this doesn't pass
Commit a change to main so the workflow runs again, and wait for the run to go green.