1Git lives on your laptop. GitHub does not.
Session 01 called a repository a folder git is tracking, with its whole history stored in a hidden
.git folder on that one machine. Nothing about that requires a network connection, an
account, or another person. A repository can live its entire life on a single laptop and still get
full value from git: every commit, every history lookup, every lab in session 01 worked exactly that
way.
GitHub is a website that stores a copy of a repository's history on its own servers, reachable over the internet, and adds tools for people to work on it together: a place to discuss a change before it is accepted, a record of who reviewed what, and a trigger other systems can watch for. GitHub did not invent git and is not the only company that hosts it. It is one host among a few, and the one Hermetic uses.
Git is the tool that records history. GitHub is a place that tool can send a copy of that history to, so it exists somewhere other than one hard drive.
2Remotes, in enough depth for today
A repository can know about other copies of itself living elsewhere. Git calls each of those a
remote. A freshly created repository has none; the moment it is connected to a copy on
GitHub, that connection gets a name, almost always origin by convention. Run
git remote -v inside HN - Training and git reports exactly one remote, named
origin, pointing at
https://github.com/Hermetic-Networks/Training.git.
Two commands move commits between your laptop and a remote. Push sends commits
your laptop has that the remote does not. Pull brings in commits the remote has that
your laptop does not. Session 03 covers both as part of the daily loop; today the only thing to hold
onto is that origin is simply a name for "the copy of this repo on GitHub," and push and
pull are how commits travel to and from it.
3From a commit on this laptop to the page you're reading
This training site is not copied to a web server by hand. A chain of systems does it automatically,
and the chain has exactly one trigger: a push to the main branch of the
Hermetic-Networks/Training repository on GitHub.
Walk it in order. You edit a file and commit, exactly as in session 01. You push, which sends that
commit to origin, the copy on GitHub. GitHub notices the push landed on main
and tells Cloudflare Pages, which already knows to watch this repository. Cloudflare Pages checks out
the new commit and rebuilds the site from it, the same HTML, CSS and images you have been reading all
session. Once that build finishes, the new version is live at the site's address, but live here
does not mean open: Entra ID, Hermetic's sign-in system, sits in front of the whole site and
will not show a single page to a browser that has not signed in as Hermetic staff. A commit can finish
its entire trip through GitHub and Cloudflare Pages and still be invisible to anyone outside the
company, because Entra is the last door and it is never skipped.
The GitHub repository has its own privacy setting, independent of Entra, covering who can see the source history itself rather than the published pages. Session 07 covers that lock in full. The point to take now is that this pipeline has two separate gates: one on the repository, one on the published site, and losing either one is a real problem even if the other stays shut.
4What GitHub adds besides hosting
A copy of the history living on a server is the minimum GitHub does. Three more things come with it, named here so later sessions can build on the vocabulary rather than introduce it cold.
Pull requests
A page on GitHub proposing that one branch's commits be merged into another, usually into
main. It is where a change gets reviewed and discussed before it goes live. Session 05
covers merging a branch in full, pull requests included.
Issues
A page on GitHub describing one piece of work or one problem, that people can comment on and link a pull request to. Not used heavily yet on this repository, but the mechanism behind "somebody filed a bug" on most software teams.
Access and permissions
GitHub decides, person by person, who can read a repository, who can push to it directly, and who can only propose a change for someone else to accept. This is the setting session 07 returns to when it covers why the repository has to stay private.
6Try it: trace your own copy
Read-only again, same as session 01.
- In
HN - Training, rungit remote -v. Confirm the one remote is namedoriginand points at the URL in section 2. - Run
git log -1. Note the hash of the current commit. - If you have access to github.com/Hermetic-Networks/Training, open it and find that same hash on the commits page. It is the identical snapshot, viewed from the other end of the pipeline in section 3.
- Open the training site itself in a browser you are not already signed into. Watch for the Entra sign-in screen before anything else loads. That screen is the fourth box in the diagram, doing its job.
7Check for understanding
-
Answer
Git needs nothing beyond the local machine to track history. A remote, and an account with whatever service hosts it, is something you add when you want a copy of that history to live somewhere else or be reachable by other people.
-
Answer
Nothing happens until a push lands on main. Editing and even committing are entirely local events; the first point any other system notices is the push, and Cloudflare Pages reacts specifically to a push on the branch it is watching.
-
Answer
A successful build only means the page exists and is ready to serve. Entra ID is the separate, final gate that decides whether a given browser gets to see it, and it checks every time, not once per device or once per build.
-
Answer
Origin is a name, by convention the default one, for a remote: a connection this repository has to a copy of itself living somewhere else, in this case the Hermetic-Networks/Training repository on GitHub. Run git remote -v to see it by name and address.
-
Answer
The repository's privacy setting on GitHub controls who can see the source and its history. Entra ID's sign-in gate controls who can view the published pages. They are configured in different systems and neither one implies the other, which is exactly why session 07 treats repository privacy as its own topic rather than something Entra already covers.
8Before session 03
- Have your practice folder from session 01 ready; session 03's lab makes its first real commit there.
- Think of one small, genuinely true change you could make to a file in your practice folder, so you have something real to commit rather than a placeholder edit.
9Glossary
- Remote
- A named connection from a repository to a copy of itself living elsewhere, most often on a host like GitHub.
- Origin
- The conventional name for a repository's primary remote.
- Push
- Sending commits from your local repository to a remote.
- Pull
- Bringing commits from a remote into your local repository.
- Pull request
- A GitHub page proposing that one branch's commits be merged into another, used for review and discussion before a merge.
- Cloudflare Pages
- The service that rebuilds and serves this training site whenever a push lands on the main branch.
- Entra ID
- Microsoft's identity service, used here to require a Hermetic sign-in before any page of the published site is shown.
10Sources
- GitHub, What is GitHub?, GitHub Docs, for the official description of what GitHub adds on top of git.
- GitHub, About pull requests, GitHub Docs.
- Cloudflare, Cloudflare Pages documentation, for how a connected GitHub repository triggers a build.
- The pipeline description reflects this project's own setup as configured by Hermetic Networks: GitHub repository Hermetic-Networks/Training, connected to Cloudflare Pages, gated by Microsoft Entra ID.