Hermetic Networks Hermetic Networks

Technicians - Git and GitHub - Session 02

GitHub, and How This Site Actually Gets Published

Git lives on one laptop at a time. GitHub is where a copy of the repository lives so other people, and other systems, can reach it. This session follows one real commit from this laptop to the page you read it on.

1Git lives on your laptop. GitHub does not.

Session 01 called a repository a folder git is tracking, with its whole history stored in a hidden .git folder on that one machine. Nothing about that requires a network connection, an account, or another person. A repository can live its entire life on a single laptop and still get full value from git: every commit, every history lookup, every lab in session 01 worked exactly that way.

GitHub is a website that stores a copy of a repository's history on its own servers, reachable over the internet, and adds tools for people to work on it together: a place to discuss a change before it is accepted, a record of who reviewed what, and a trigger other systems can watch for. GitHub did not invent git and is not the only company that hosts it. It is one host among a few, and the one Hermetic uses.

The distinction in one line

Git is the tool that records history. GitHub is a place that tool can send a copy of that history to, so it exists somewhere other than one hard drive.

2Remotes, in enough depth for today

A repository can know about other copies of itself living elsewhere. Git calls each of those a remote. A freshly created repository has none; the moment it is connected to a copy on GitHub, that connection gets a name, almost always origin by convention. Run git remote -v inside HN - Training and git reports exactly one remote, named origin, pointing at https://github.com/Hermetic-Networks/Training.git.

Two commands move commits between your laptop and a remote. Push sends commits your laptop has that the remote does not. Pull brings in commits the remote has that your laptop does not. Session 03 covers both as part of the daily loop; today the only thing to hold onto is that origin is simply a name for "the copy of this repo on GitHub," and push and pull are how commits travel to and from it.

3From a commit on this laptop to the page you're reading

This training site is not copied to a web server by hand. A chain of systems does it automatically, and the chain has exactly one trigger: a push to the main branch of the Hermetic-Networks/Training repository on GitHub.

Your laptopgit commit, thengit pushGitHubHermetic-Networks/Training, main branchCloudflare PagesRebuilds the sitefrom the new commitEntra IDChecks you're signed inas Hermetic staffNothing in this chain runs until something is pushed to main. Nothing after Entra runs until you sign in.
Four systems, one trigger. Push to main is the only thing that starts the first three boxes; signing in is the only thing that gets past the fourth.

Walk it in order. You edit a file and commit, exactly as in session 01. You push, which sends that commit to origin, the copy on GitHub. GitHub notices the push landed on main and tells Cloudflare Pages, which already knows to watch this repository. Cloudflare Pages checks out the new commit and rebuilds the site from it, the same HTML, CSS and images you have been reading all session. Once that build finishes, the new version is live at the site's address, but live here does not mean open: Entra ID, Hermetic's sign-in system, sits in front of the whole site and will not show a single page to a browser that has not signed in as Hermetic staff. A commit can finish its entire trip through GitHub and Cloudflare Pages and still be invisible to anyone outside the company, because Entra is the last door and it is never skipped.

Two separate locks, not one

The GitHub repository has its own privacy setting, independent of Entra, covering who can see the source history itself rather than the published pages. Session 07 covers that lock in full. The point to take now is that this pipeline has two separate gates: one on the repository, one on the published site, and losing either one is a real problem even if the other stays shut.

4What GitHub adds besides hosting

A copy of the history living on a server is the minimum GitHub does. Three more things come with it, named here so later sessions can build on the vocabulary rather than introduce it cold.

Pull requests

A page on GitHub proposing that one branch's commits be merged into another, usually into main. It is where a change gets reviewed and discussed before it goes live. Session 05 covers merging a branch in full, pull requests included.

Issues

A page on GitHub describing one piece of work or one problem, that people can comment on and link a pull request to. Not used heavily yet on this repository, but the mechanism behind "somebody filed a bug" on most software teams.

Access and permissions

GitHub decides, person by person, who can read a repository, who can push to it directly, and who can only propose a change for someone else to accept. This is the setting session 07 returns to when it covers why the repository has to stay private.

6Try it: trace your own copy

Read-only again, same as session 01.

  1. In HN - Training, run git remote -v. Confirm the one remote is named origin and points at the URL in section 2.
  2. Run git log -1. Note the hash of the current commit.
  3. If you have access to github.com/Hermetic-Networks/Training, open it and find that same hash on the commits page. It is the identical snapshot, viewed from the other end of the pipeline in section 3.
  4. Open the training site itself in a browser you are not already signed into. Watch for the Entra sign-in screen before anything else loads. That screen is the fourth box in the diagram, doing its job.

7Check for understanding

  1. A solo developer uses git every day to track a personal project, with no GitHub account at all. Is this possible?
    Answer

    Git needs nothing beyond the local machine to track history. A remote, and an account with whatever service hosts it, is something you add when you want a copy of that history to live somewhere else or be reachable by other people.

  2. In the pipeline in section 3, what is the one event that starts Cloudflare Pages rebuilding the site?
    Answer

    Nothing happens until a push lands on main. Editing and even committing are entirely local events; the first point any other system notices is the push, and Cloudflare Pages reacts specifically to a push on the branch it is watching.

  3. A commit finishes its full trip through GitHub and Cloudflare Pages, and the rebuild succeeds. Can someone outside Hermetic see the result?
    Answer

    A successful build only means the page exists and is ready to serve. Entra ID is the separate, final gate that decides whether a given browser gets to see it, and it checks every time, not once per device or once per build.

  4. What is origin, as git uses the word?
    Answer

    Origin is a name, by convention the default one, for a remote: a connection this repository has to a copy of itself living somewhere else, in this case the Hermetic-Networks/Training repository on GitHub. Run git remote -v to see it by name and address.

  5. Why does the lesson say the pipeline has "two separate gates", not one?
    Answer

    The repository's privacy setting on GitHub controls who can see the source and its history. Entra ID's sign-in gate controls who can view the published pages. They are configured in different systems and neither one implies the other, which is exactly why session 07 treats repository privacy as its own topic rather than something Entra already covers.

8Before session 03

  • Have your practice folder from session 01 ready; session 03's lab makes its first real commit there.
  • Think of one small, genuinely true change you could make to a file in your practice folder, so you have something real to commit rather than a placeholder edit.

9Glossary

Remote
A named connection from a repository to a copy of itself living elsewhere, most often on a host like GitHub.
Origin
The conventional name for a repository's primary remote.
Push
Sending commits from your local repository to a remote.
Pull
Bringing commits from a remote into your local repository.
Pull request
A GitHub page proposing that one branch's commits be merged into another, used for review and discussion before a merge.
Cloudflare Pages
The service that rebuilds and serves this training site whenever a push lands on the main branch.
Entra ID
Microsoft's identity service, used here to require a Hermetic sign-in before any page of the published site is shown.

10Sources

  • GitHub, What is GitHub?, GitHub Docs, for the official description of what GitHub adds on top of git.
  • GitHub, About pull requests, GitHub Docs.
  • Cloudflare, Cloudflare Pages documentation, for how a connected GitHub repository triggers a build.
  • The pipeline description reflects this project's own setup as configured by Hermetic Networks: GitHub repository Hermetic-Networks/Training, connected to Cloudflare Pages, gated by Microsoft Entra ID.