DevOps7 min read

CI/CD for Small Teams: GitHub Actions + AWS

A lean pipeline that gives small teams safe, fast deploys without a platform team to run it.

DM

Deep Mehta

Founder & Cloud Engineer · Updated August 24, 2026

You do not need a platform team or a Kubernetes cluster to deploy safely. A small team can get fast, reliable deploys with GitHub Actions and a few AWS services. Here is a lean setup that scales with you.

What "good" looks like for a small team

  • Every push runs tests automatically
  • Merges to main deploy to staging without manual steps
  • Production deploys are one click (or one approval)
  • Rolling back is fast and obvious

The pipeline shape

Keep it boring. Three stages, test, build, deploy, triggered by git events. Use OIDC so GitHub Actions assumes an AWS role instead of you storing long-lived keys as secrets.

yaml
name: deploy
on:
  push:
    branches: [main]
permissions:
  id-token: write   # OIDC, no stored AWS keys
  contents: read
jobs:
  test:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: npm ci && npm test
  deploy:
    needs: test
    runs-on: ubuntu-latest
    steps:
      - uses: aws-actions/configure-aws-credentials@v4
        with:
          role-to-assume: arn:aws:iam::123:role/deploy
          aws-region: us-east-1
      - run: ./deploy.sh

Use OIDC, not stored keys

The single most common CI/CD security mistake is pasting AWS access keys into repo secrets. GitHub Actions supports OIDC: it exchanges a short-lived token for a scoped AWS role. No long-lived credentials to leak.

If your CI has permanent AWS keys in its secrets, that is the first thing to fix, before anything about speed.

Make rollback trivial

Deploy immutable artifacts (a container image or versioned bundle) so rolling back is redeploying the previous version, not reverting code and rebuilding. On ECS or App Runner, that is pointing back at the last known-good image.

Do not over-build it

A small team does not need canary analysis, service meshes, or a bespoke internal platform on day one. Start with test → build → deploy plus easy rollback. Add complexity only when a real problem demands it.

If you want this set up cleanly the first time, OIDC, staged deploys, and a rollback you have actually tested, that is what our CI/CD work delivers.

#DevOps#CI/CD#GitHub Actions
DM

About the author

Deep Mehta

Deep is the founder of 3 Dices Technology, a cloud engineering studio. He has shipped AWS architecture, DevOps automation, and production AI systems for startups and SMBs, and writes about the practical version of that work, not the conference-talk version.

Connect on LinkedIn

Frequently Asked Questions

Do small teams need Kubernetes for CI/CD?
No. A test → build → deploy pipeline on ECS, App Runner, or a single host is enough for most small teams. Kubernetes is only worth its complexity at a certain scale.
Why use OIDC instead of AWS access keys in CI?
OIDC exchanges a short-lived token for a scoped AWS role, so there are no long-lived credentials stored in repo secrets to leak. It is the single biggest CI security win.
How do I make rollbacks safe?
Deploy immutable artifacts (a container image or versioned bundle). Rolling back is then redeploying the previous version, not reverting code and rebuilding.

Have a Question This Didn't Answer?

Ask us directly, we're happy to share what we know about your specific situation.