How do I set up a GitHub Actions workflow for deployment?

Updated October 2026 · How we answer

Short answerCreate a YAML file in .github/workflows, set a trigger such as a push to main, add steps for checkout and deploy, and store secrets in repository settings.

Create the workflow file

Add a file such as .github/workflows/deploy.yml to your repository. The file starts with a name and an on block that sets the trigger, such as a push to the main branch. Under jobs, define a job that runs on a hosted runner such as ubuntu-latest.

Use the actions/checkout step first so the job has your code. Then add steps that run your build or deploy commands. Keep each step small and clearly named so failures are easy to read in the Actions tab.

  • on: push with branches: [main]
  • runs-on: ubuntu-latest
  • uses: actions/checkout (check the current major version)
  • run: your build or deploy command

Handle secrets and access

Store server addresses, SSH keys and tokens under the repository settings in Secrets and variables, then Actions. Reference them in the workflow as secrets.NAME inside the expression syntax. Never print secrets in logs or commit them to the repository.

For SSH deploys, use a dedicated deploy key with limited permissions. Test the workflow on a staging branch before pointing it at production. Run the workflow manually while you are still testing, so you do not need a new commit every time you adjust a step.

Common mistakes

  • Hardcoding passwords or keys directly in the YAML file.
  • Deploying on every push to every branch, which can ship unfinished code.
  • Skipping the test step, so broken builds reach the server.
From our shopsCASEONYX: Dark-luxe tough phone cases.