| Workshop selection | Next: setup |
|---|
You're volunteering at the dog shelter. Its Flask API and Astro website pass their functional tests. Now you need to check what happens when a change leaves the debugger enabled, introduces a vulnerable package, or includes a credential.
You'll fix code, review a dependency change, and practice secret protection in your own public repository. The presenter demonstrates merge policy and a cloud-free release. The take-home labs include the instructions and files to perform those two exercises yourself afterward.
Important
Kit 0.1.2 is a Codespaces-first prerelease. Actual Codespaces and human walkthroughs remain pending; the readiness register records the access limitation and earlier terminal/Actions evidence separately.
Bring a laptop with internet access. Your GitHub.com account must be able to create and administer a public learner repository, run standard GitHub-hosted Actions, configure its security settings, and use Codespaces with sufficient included usage or approved sponsorship. Use only the shelter's public sample data.
The primary route uses browser-based VS Code in GitHub Codespaces. Git and Bash are already available there; you do not clone the learner repository again or install the application. You need no laptop Python, Node.js, Docker, or Git installation, and no Azure account, Copilot subscription, second reviewer, or pasted PAT. Use the default image and smallest suitable permitted machine, normally two cores, for editing and Git.
Codespaces compute and storage have usage limits and a payer; public repositories do not provide unlimited free Codespaces. Check access, quota, and who pays before starting. Standard Actions usage is separate. If policy, quota, or connectivity prevents the primary route, use the documented local Git or file-editor fallback.
Throughout these guides, editor and terminal mean the Codespaces editor and integrated Bash terminal unless labeled as a fallback. GitHub.com remains the place for PRs, settings, Actions dispatch/results, and approval. Application builds, tests, scans, and the optional token proof run in Actions, not Codespaces.
Complete Step 0 before the event. The opening eight minutes only verify readiness.
These are design budgets. No representative learner rehearsal has established the timing.
| Lesson | Event minutes | Budget | Format |
|---|---|---|---|
| 0. Setup checkpoint | 00-08 | 8 | Verify prework |
| 1. DevOps baseline | 08-15 | 7 | Shared discussion |
| 2. Security planning | 15-21 | 6 | Shared planning |
| 3. Code scanning | 21-38 | 17 | Individual fix and test |
| 4. Dependencies | 38-53 | 15 | Individual failure and repair |
| 5. Secrets | 53-65 | 12 | Individual block and clean retry |
| 6. Merge policy | 65-75 | 10 | Facilitator demonstration |
| 7. Delivery and response | 75-83 | 8 | Facilitator demonstration |
| 8. Closing | 83-90 | 7 | Evidence and questions |
The core totals 75 minutes; startup and closing bring the event to 90. Playwright, cloud deployment, and participant settings changes for lessons 6-7 are outside that core.
For optional practice afterward, prove a workflow's GitHub API permissions yourself: observe a denied request, then a separate narrowly authorized job and its closed training issue. The guide also points to OIDC for future cloud identity work. Neither extends core setup or replaces the secret-protection exercise.
Create a learner repository from the original Pets template, then open a codespace on your copy's main. From its existing checkout, fetch the versioned companion kit into a sibling under /workspaces. Step 0 gives the full sequence. The helper installs only two core workflows, without adding a remote or merging histories.
The companion is not an application template. If the original template changes incompatibly, the organizer must refresh and retest the companion kit. The versioned ZIP is an alternative way to obtain the same material.
Reuse one codespace for the learner repository. Saving is not committing or pushing. Keep the sibling kit under /workspaces, preserve intended work on GitHub, and stop the codespace explicitly when finished; closing its tab does not stop compute. Stopped storage still counts toward usage. Keep forwarded ports private; no app hosting is added.
The kit works as a local folder: all lesson, starter, solution, and take-home links are relative. External links to existing Pets material use the inspected source revision. Files introduced by this track are never linked to an upstream location where they do not exist.
| Your next task | Guide |
|---|---|
| Start from no setup | Step 0 |
| Return after the event or recover partial work | Resume |
| Find exact edits and explanations | Solutions |
| Track personal results | Evidence checklist |
| Run the event or build the companion archive | Facilitator guide |
| Diagnose a failed step | Troubleshooting |
| Review pins, advisories, and limitations | Technical sources |
The shelter needs evidence about both functionality and risk. Each lesson identifies the control, the person responsible, and the result that would justify moving forward. A pending check stays pending; watching the presenter's successful run does not complete your individual exercise.
GitHub flow explains the PR cycle. What is DevOps? introduces the delivery process. NIST's Secure Software Development Framework connects development to vulnerability response.
| Workshop selection | Next: setup |
|---|