App Builder CI/CD Pipeline
Set up CI/CD pipelines for Adobe App Builder projects — GitHub Actions (primary), Azure DevOps, GitLab CI. Uses OAuth S2S credentials with IMS authentication. Repository secrets only (no environment secrets).
Pattern Quick-Reference
| User wants |
Template |
| GitHub Actions deploy-to-stage |
assets/deploy-stage.yml |
| GitHub Actions deploy-to-prod |
assets/deploy-prod.yml |
| GitHub Actions PR tests |
assets/pr-test.yml |
| Extract secrets from workspace |
assets/fetch-secrets.sh |
| Azure DevOps / GitLab CI / Jenkins |
references/generic-pipeline-guide.md |
| Secrets setup guide |
references/secrets-management.md |
| Debugging deploy failures |
references/debugging.md |
Fast Path (for clear requests)
When the user says "set up CI/CD for my App Builder project" and they use GitHub, generate all 3 workflow files + secrets guide immediately:
- Copy
assets/deploy-stage.yml → .github/workflows/deploy_stage.yml
- Copy
assets/deploy-prod.yml → .github/workflows/deploy_prod.yml
- Copy
assets/pr-test.yml → .github/workflows/pr_test.yml
- Guide secrets setup using
references/secrets-management.md
If user specifies Azure DevOps, GitLab CI, or Jenkins → use references/generic-pipeline-guide.md.
Quick Reference
- Workflow location:
.github/workflows/ at repository root
- Bootstrap command:
aio app add ci generates starter workflow files
- Official actions:
adobe/aio-cli-setup-action@3 (CLI install) + adobe/aio-apps-action@3.3.0 (build/test/deploy)
- Auth model: OAuth Server-to-Server (S2S) with IMS — the
auth command in aio-apps-action is DEPRECATED (JWT). Do not use it.
- Secrets scope: Repository secrets only. App Builder does NOT support GitHub environment secrets.
- Secrets per workspace: 14 secrets with workspace suffix (
_STAGE, _PROD)
- Prerequisite: Add "I/O Management API" to each workspace in Developer Console before extracting secrets
- Workspace config: Run
aio app use <workspace.json> to configure .aio and .env files
Full Workflow (for ambiguous or complex requests)
- Check existing setup: Look for
.github/workflows/ (from aio app add ci or manual). Check if workflows already exist.
- Determine CI/CD platform: GitHub Actions is default. Ask if user needs Azure DevOps, GitLab CI, or Jenkins.
- Generate workflow files: Copy templates from
assets/ to .github/workflows/. Customize triggers, branch names, and environment suffixes as needed.
- **Guide secrets setup:**a. Ensure "I/O Management API" is added to the workspace in Developer Consoleb. Download
workspace.json from Developer Consolec. Run aio app use <workspace.json> to configure local .aio and .envd. Run assets/fetch-secrets.sh to extract credential valuese. Guide user to add each secret to GitHub repository secrets (NOT environment secrets)f. Add _STAGE or _PROD suffix to each secret name
- Add custom secrets: If the app uses custom env vars, add them under the
env key in the Deploy step
- Validate: Run through
references/checklist.md before merge
- Troubleshoot: If deploy fails, consult
references/debugging.md for common scenarios
- Test: Push to a branch and verify workflow runs successfully
Inputs To Request
- Current repository path and CI/CD platform preference
- Target Adobe organization, project, and workspace names
- Whether Stage, Production, or both workspaces need CI/CD
- Any custom secrets the application requires
Deliverables
- Workflow YAML files in
.github/workflows/
- Secrets extraction output for repository configuration
- Pre-merge validation against
references/checklist.md
Quality Bar
- All workflow YAML must be syntactically valid
- Secrets must use repository scope, never environment scope
- OAuth S2S credentials only — no JWT auth references
- Each workspace gets its own secret set with correct suffix
- Workflows must use pinned action versions (
@3, @3.3.0)
References
- Use
references/github-actions-guide.md for GitHub Actions workflow patterns and secrets table.
- Use
references/generic-pipeline-guide.md for Azure DevOps, GitLab CI, and Jenkins patterns.
- Use
references/secrets-management.md for OAuth S2S credential extraction and GitHub secrets setup.
- Use
references/debugging.md for troubleshooting deploy failures, CI errors, and workspace promotion issues.
- Use
references/checklist.md for pre-merge CI readiness validation.
- Use
assets/deploy-stage.yml, assets/deploy-prod.yml, assets/pr-test.yml as workflow templates.
- Use
assets/fetch-secrets.sh to extract secret values from workspace configuration.
- Official Adobe docs: https://developer.adobe.com/app-builder/docs/guides/app_builder_guides/deployment/cicd-using-github-actions
Common Issues
- Workflow not triggering: Verify workflow files are committed to the default branch and triggers match your branching strategy.
- Deploy fails with auth error: The
auth command is deprecated. Ensure you are using OAuth S2S credentials, not JWT. Verify all 14 secrets are set correctly with the right workspace suffix.
- "I/O Management API not found": Add the I/O Management API service to the workspace in Developer Console before extracting secrets.
- Environment secrets not working: App Builder does NOT support GitHub environment secrets. Move all secrets to repository-level secrets.
- Missing secrets: Run
fetch-secrets.sh and compare output against the 14-secret table in references/github-actions-guide.md. Each value must be present and correctly suffixed.
- Custom env vars not available in action: Add custom secrets under the
env key in the Deploy step of the workflow, not just in GitHub secrets.
Chaining
- Chains FROM
appbuilder-action-scaffolder (after actions are implemented)
- Chains FROM
appbuilder-testing (automated test execution in CI)
- Standalone after setup (workflows run automatically on push/PR/release)
1---2name: appbuilder-cicd-pipeline3description: Generates CI/CD pipeline configurations for Adobe App Builder projects, including GitHub Actions workflows, Azure DevOps, and GitLab CI templates with OAuth S2S secrets injection and multi-workspace promotion.4license: Apache-2.05---6# App Builder CI/CD Pipeline78Set up CI/CD pipelines for Adobe App Builder projects — GitHub Actions (primary), Azure DevOps, GitLab CI. Uses OAuth S2S credentials with IMS authentication. Repository secrets only (no environment secrets).910## Pattern Quick-Reference1112| User wants | Template |13| --- | --- |14| GitHub Actions deploy-to-stage | assets/deploy-stage.yml |15| GitHub Actions deploy-to-prod | assets/deploy-prod.yml |16| GitHub Actions PR tests | assets/pr-test.yml |17| Extract secrets from workspace | assets/fetch-secrets.sh |18| Azure DevOps / GitLab CI / Jenkins | references/generic-pipeline-guide.md |19| Secrets setup guide | references/secrets-management.md |20| Debugging deploy failures | references/debugging.md |2122## Fast Path (for clear requests)2324When the user says "set up CI/CD for my App Builder project" and they use GitHub, generate all 3 workflow files + secrets guide immediately:25261. Copy `assets/deploy-stage.yml` → `.github/workflows/deploy_stage.yml`272. Copy `assets/deploy-prod.yml` → `.github/workflows/deploy_prod.yml`283. Copy `assets/pr-test.yml` → `.github/workflows/pr_test.yml`294. Guide secrets setup using `references/secrets-management.md`3031If user specifies Azure DevOps, GitLab CI, or Jenkins → use `references/generic-pipeline-guide.md`.3233## Quick Reference3435- **Workflow location:** `.github/workflows/` at repository root36- **Bootstrap command:** `aio app add ci` generates starter workflow files37- **Official actions:** `adobe/aio-cli-setup-action@3` (CLI install) + `adobe/aio-apps-action@3.3.0` (build/test/deploy)38- **Auth model:** OAuth Server-to-Server (S2S) with IMS — the `auth` command in `aio-apps-action` is **DEPRECATED** (JWT). Do not use it.39- **Secrets scope:** Repository secrets only. App Builder does **NOT** support GitHub environment secrets.40- **Secrets per workspace:** 14 secrets with workspace suffix (`_STAGE`, `_PROD`)41- **Prerequisite:** Add "I/O Management API" to each workspace in Developer Console before extracting secrets42- **Workspace config:** Run `aio app use <workspace.json>` to configure `.aio` and `.env` files4344## Full Workflow (for ambiguous or complex requests)45461. **Check existing setup:** Look for `.github/workflows/` (from `aio app add ci` or manual). Check if workflows already exist.472. **Determine CI/CD platform:** GitHub Actions is default. Ask if user needs Azure DevOps, GitLab CI, or Jenkins.483. **Generate workflow files:** Copy templates from `assets/` to `.github/workflows/`. Customize triggers, branch names, and environment suffixes as needed.494. **Guide secrets setup:**a. Ensure "I/O Management API" is added to the workspace in Developer Consoleb. Download `workspace.json` from Developer Consolec. Run `aio app use <workspace.json>` to configure local `.aio` and `.env`d. Run `assets/fetch-secrets.sh` to extract credential valuese. Guide user to add each secret to GitHub **repository** secrets (NOT environment secrets)f. Add `_STAGE` or `_PROD` suffix to each secret name505. **Add custom secrets:** If the app uses custom env vars, add them under the `env` key in the Deploy step516. **Validate:** Run through `references/checklist.md` before merge527. **Troubleshoot:** If deploy fails, consult `references/debugging.md` for common scenarios538. **Test:** Push to a branch and verify workflow runs successfully5455## Inputs To Request5657- Current repository path and CI/CD platform preference58- Target Adobe organization, project, and workspace names59- Whether Stage, Production, or both workspaces need CI/CD60- Any custom secrets the application requires6162## Deliverables6364- Workflow YAML files in `.github/workflows/`65- Secrets extraction output for repository configuration66- Pre-merge validation against `references/checklist.md`6768## Quality Bar6970- All workflow YAML must be syntactically valid71- Secrets must use repository scope, never environment scope72- OAuth S2S credentials only — no JWT auth references73- Each workspace gets its own secret set with correct suffix74- Workflows must use pinned action versions (`@3`, `@3.3.0`)7576## References7778- Use `references/github-actions-guide.md` for GitHub Actions workflow patterns and secrets table.79- Use `references/generic-pipeline-guide.md` for Azure DevOps, GitLab CI, and Jenkins patterns.80- Use `references/secrets-management.md` for OAuth S2S credential extraction and GitHub secrets setup.81- Use `references/debugging.md` for troubleshooting deploy failures, CI errors, and workspace promotion issues.82- Use `references/checklist.md` for pre-merge CI readiness validation.83- Use `assets/deploy-stage.yml`, `assets/deploy-prod.yml`, `assets/pr-test.yml` as workflow templates.84- Use `assets/fetch-secrets.sh` to extract secret values from workspace configuration.85- Official Adobe docs: [https://developer.adobe.com/app-builder/docs/guides/app_builder_guides/deployment/cicd-using-github-actions](https://developer.adobe.com/app-builder/docs/guides/app_builder_guides/deployment/cicd-using-github-actions)8687## Common Issues8889- **Workflow not triggering:** Verify workflow files are committed to the default branch and triggers match your branching strategy.90- **Deploy fails with auth error:** The `auth` command is deprecated. Ensure you are using OAuth S2S credentials, not JWT. Verify all 14 secrets are set correctly with the right workspace suffix.91- **"I/O Management API not found":** Add the I/O Management API service to the workspace in Developer Console before extracting secrets.92- **Environment secrets not working:** App Builder does NOT support GitHub environment secrets. Move all secrets to repository-level secrets.93- **Missing secrets:** Run `fetch-secrets.sh` and compare output against the 14-secret table in `references/github-actions-guide.md`. Each value must be present and correctly suffixed.94- **Custom env vars not available in action:** Add custom secrets under the `env` key in the Deploy step of the workflow, not just in GitHub secrets.9596## Chaining9798- Chains FROM `appbuilder-action-scaffolder` (after actions are implemented)99- Chains FROM `appbuilder-testing` (automated test execution in CI)100- Standalone after setup (workflows run automatically on push/PR/release)