Home/Blog/How to Draft a GitHub Actions Workflow YAML from a Job List
Blog

How to Draft a GitHub Actions Workflow YAML from a Job List

P
promptstudio
How to Draft a GitHub Actions Workflow YAML from a Job List

Workflow YAML invents setup-python. uses: only from the allowlist.

The matching generator is the GitHub Actions Workflow YAML from a Job List (No Invented Actions beyond Allowlist) (Github Actions Workflow Yaml From Job List No Invented Actions Beyond Allowlist) prompt. Browse related cards in the PromptDig library (Browse more prompts). When a filled run survives, share the version you actually use (Share a prompt).

Lock the runner and triggers from Inputs

Draft a GitHub Actions workflow YAML from a pasted job list. Never invent actions beyond the allowlist or unlisted secrets. Start by filling Inputs, not by asking the model to remember last week's run. If a field is blank, write NONE or NOT IN INPUTS and leave it blank through Generate. The card is built so the model cannot honestly invent a number, owner, URL, or command that you did not paste.

Paste these fields before you hit run:

Pasted job list (name, steps in plain language): [Jobs]
Action allowlist (owner/name@ref or NONE): [Allow]
Runner I lock (or NONE): [Runner]
Triggers I lock: [On]
Secrets I may name (exact list or NONE): [Secrets]
Words I must not use: [Banned]
What I must never invent: [Never]
Output format: [Format]
Language: [Lang]
Max jobs: [Max]

That inventory is the honesty ledger. Anything that does not appear there is forbidden in the draft. If you catch yourself adding a nice-to-have after the run, you are no longer using the card. You are ghostwriting. Put the extra fact in Inputs and run again.

Check every uses line against Allow

Generate is numbered on purpose. Do not skip a step because the first paragraph looked done. The early steps exist to stop later prose from smuggling claims.

Walk the Generate list in order:

  1. Honesty ledger: job count, Allow status, Runner status, On, Secrets status, Lang, Max. Forbidden: invented actions, invented secrets.
  2. Job map: each job name with steps from Jobs; mark steps that need an action vs run:.
  3. Workflow YAML: name, on from On, jobs up to Max. uses: only if the action is on Allow. If Allow NONE, use run: only.
  4. Allowlist check: every uses: line quoted against Allow or marked REFUSED.
  5. Refuse list: invented docker/login-action, invented github.token scopes, invented environments.
  6. Diff notes: Banned/Never cuts.
  7. Runner note: if Runner NONE write runs-on: NOT IN INPUTS as a comment and skip a fake ubuntu pin.
  8. Compliance pass: Banned/Never hits. Job count vs Max. Gaps list of five. Format as Format.

If a step asks for a version lock, quote the version from Inputs in the output. If a step asks for a refuse list, keep the refuse list in the published artifact, not in a sidebar you delete. Reviewers should see what the model was not allowed to do.

Leave secrets unnamed when Secrets is NONE

Most failures are the same shape: a missing field gets a confident fill. A conversion rate appears. A Gradle task appears. A flash point appears. A caption appears on a job that asked for slide text only. Your review is to search the draft for numbers, names, and commands, then grep Inputs. No match means cut.

Honor the constraints as hard stops, not vibes:

  • Workflow YAML from Jobs + Allow only. Not Dependabot and not a matrix-from-test-plan card.
  • Never invent actions beyond Allow or secrets beyond Secrets.
  • Stay at or under Max jobs.
  • No emojis.

When the card says not legal advice, not certification, not an exam dump, or not a caption engine, that sentence belongs at the top of the output. Deleting it to look more finished is how you inherit risk.

Refuse invented cache keys and services

Finish with the compliance pass the prompt already asks for. Quote the banned-word hits. Cut them. Print character counts when the job has a cap. Print word counts when the job has a budget. List gaps as gaps. Five missing facts are more useful than one smooth paragraph.

Tags on the card (github actions workflow, no invented actions, actions yaml from job list) are a reminder of the job shape, not an invitation to wander into a neighboring cluster. If you need a different surface, open a different PromptDig card rather than stretching this one.

Fill the card, then run

Replace every bracket. Run on ChatGPT, Claude, or Gemini. Read the ledger first, then the artifact. If the model invents a commit, KPI, DOI, PEL, bid, or logo, discard the run. Tighten Inputs. Run again. Share the filled card that survived, not the first draft that sounded done.