Lesson 22 / 25

Environments, Approvals and Releases

Gate deployments.

Protection rules and deployment history

An environment (staging, production) holds its own secrets and variables and can require reviewers to approve, wait timers, and restrictions on which branches or tags may deploy. Jobs reference it with environment: production; GitHub records deployments and their URLs. Combine with tag-triggered release workflows, a concurrency group per environment, and smoke tests after deployment, with a documented rollback path.

A gated production deployment

Not linted or run here; check the GitHub Actions documentation for current syntax.

jobs:
  deploy-production:
    needs: deploy-staging
    runs-on: ubuntu-latest
    environment:
      name: production
      url: https://shop.example.com
    concurrency:
      group: deploy-production
      cancel-in-progress: false
    steps:
      - run: ./scripts/deploy.sh production
      - run: ./scripts/smoke-test.sh https://shop.example.com

Restrict production to tags or main

Environment deployment branch rules stop feature branches from deploying to production.

Quick check: What can an environment protection rule require?

  • A different YAML syntax
  • A faster runner
  • A larger cache
  • Approval from designated reviewers before the job runs
Answer

Approval from designated reviewers before the job runs — Human gates for sensitive deploys.