CI/CD DevOps Tools That Are Better Than GitHub Actions

Опубликовано: 05 Ноябрь 2024
на канале: Cloud Posse
198
7

Cloud Posse holds public "Office Hours" every Wednesday at 11:30am PST to answer questions on all things related to DevOps, Terraform, Kubernetes, CICD. Basically, it's like an interactive "Lunch & Learn" session where we get together for about an hour and talk shop. These are totally free and just an opportunity to ask us (or our community of experts) any questions you may have.

You can register here: https://cloudposse.com/office-hours

This discussion revolves around Continuous Deployment (CD) tools, with participants expressing preferences, frustrations, and recommendations. GitHub Actions emerges as a popular choice, mainly because it integrates seamlessly with GitHub, a widely-used platform. Users appreciate the extensive marketplace of actions available for various platforms and tools, though there are concerns about its reliability and security. The marketplace is compared to early NPM, where actions are available, but their quality and security are questionable. Users often have to vet the actions themselves, checking contributors, stars, and the code itself, which can be time-consuming.

Security concerns with GitHub Actions are highlighted, particularly regarding the ease with which actions can be published without verification, leading to potential vulnerabilities. Users express the need for better security practices, like pinning dependencies or reviewing the underlying code of actions. There's also frustration with the marketplace's lack of curation, leading to a free-for-all environment where finding trustworthy actions is challenging.

GitLab CI is mentioned as an alternative, though it requires self-hosting, which might not be ideal for everyone. Jenkins, while free and open-source, is considered outdated and not favoured by many users. Other emerging tools like Tecton are noted but seem less mature or widely adopted.

The discussion closes with a recognition of the convenience of using GitHub Actions despite its flaws, with some participants contemplating a fallback to custom scripts for better control and security. There’s also a mention of YAML as a preferred configuration language despite its occasional complexity, due to its consistency and simplicity.

While GitHub Actions is favoured for its integration and extensive marketplace, significant concerns remain regarding its security and the quality of actions available, leading some users to consider alternatives or custom solutions. Marketplaces in the DevOps space are broadly viewed as unreliable, necessitating a careful approach to tool selection and usage.

Join the conversation:
https://slack.cloudposse.com/

Find out how we can help your company:
https://cloudposse.com/quiz
https://cloudposse.com/accelerate/

Learn more about Cloud Posse:
https://cloudposse.com
https://github.com/cloudposse
https://sweetops.com/
https://newsletter.cloudposse.com
https://podcast.cloudposse.com/