GitHub Actions: automation, security, and operations
Seven lessons, 40 questions, and seven cases on workflows, actions, runners, artifacts, permissions, OIDC, and production delivery diagnosis.
Objectives and progression
Initial course with seven lessons and 47 original decisions, including seven fictional APS and technical-management cases. Internal assessment of 28 decisions in 60 minutes. Covers five domains at introductory depth; advanced enterprise policies, APIs, metrics, migrations, and executable labs need deeper study. GH-200: January 2026 objectives in the guide updated 2026-02-05. The official page states 100 minutes; passing starts at 700 on a 1000-point scale, without equivalence to 70%. Question count unconfirmed. The credential has two-year validity; consult current renewal and transition policy.
Audience: Development, platform, APS, and technical managers responsible for pipelines and delivery.
Prerequisites: Git, branches, and pull requests; basic YAML, shell, and build and deployment lifecycle.
375 estimated study minutes
- Explain why a workflow does not start and why a job is skipped.
- Pass values between steps and jobs through explicit contracts.
- Investigate a run while preserving input and output identity.
- Publish reusable components with explicit inputs, outputs, and compatibility.
- Relate queued jobs to eligibility and design a safe execution boundary.
- Trace authorization and credential passing across each workflow link.
- Keep untrusted code separate from production authorization.
Modules
- Events, filters, and dependencies
- Data, outputs, and service networking
- Reuse, artifacts, and troubleshooting
- Actions with contracts and versions
- Runners, capacity, and isolation
- Permissions, secrets, and approval
- Security, provenance, and promotion
Continue learning
References and version
GH-200 skills measured January2026;study guide updated2026-02-05
- GitHub Actions certification · 2026-09-30
- GH-200 January 2026 objectives · 2026-09-30
- Scaled exam scoring · 2026-09-30
- Workflow events · 2026-09-30
- Workflow syntax · 2026-09-30
- Workflow commands · 2026-09-30
- Dependency caching · 2026-09-30
- Job dependencies · 2026-09-30
- Reusable workflow configuration · 2026-09-30
- Action metadata · 2026-09-30
- JavaScript actions · 2026-09-30
- Composite actions · 2026-09-30
- Immutable action releases · 2026-09-30
- Custom action maintenance · 2026-09-30
- Self-hosted and ephemeral runners · 2026-09-30
- Runner labels and groups · 2026-09-30
- Hosted runners · 2026-09-30
- Secret scope and read time · 2026-09-30
- Secret access and review gates · 2026-09-30
- Secure use of Actions · 2026-09-30
- Concurrency groups and optional queue · 2026-09-30
- Triggering workflows · 2026-09-30
- Disable workflow without deleting history · 2026-09-30
- Nested workflows and secret passing · 2026-09-30
- Using secrets · 2026-09-30
- OIDC trust · 2026-09-30
- Artifact attestations · 2026-09-30
- Workflow artifacts · 2026-09-30
- Service container networking · 2026-09-30
- Immutable releases · 2026-09-30
What you will explore
0 / 7Events, filters, and dependencies
Explain why a workflow does not start and why a job is skipped.
Data, outputs, and service networking
Pass values between steps and jobs through explicit contracts.
Reuse, artifacts, and troubleshooting
Investigate a run while preserving input and output identity.
Actions with contracts and versions
Publish reusable components with explicit inputs, outputs, and compatibility.
Runners, capacity, and isolation
Relate queued jobs to eligibility and design a safe execution boundary.
Permissions, secrets, and approval
Trace authorization and credential passing across each workflow link.
Security, provenance, and promotion
Keep untrusted code separate from production authorization.