Memory hook: Copy a starter; call a workflow; compose steps in an action.
Must remember
A starter workflow is a scaffold copied into a repository and then maintained there. A reusable workflow is called through a job-level uses reference and a workflow_call interface. A composite action packages steps and is invoked within a job. Choose the unit that matches ownership and execution requirements.
Declare reusable inputs, secrets and outputs as an interface. Callers pass supported values explicitly or use permitted secret inheritance. Workflow-level env does not automatically become the called workflow's environment. Map outputs back through the reusable interface when a caller needs a result.
Private/non-public templates and reusable workflows need suitable visibility/access settings. Both caller policy and the called repository's sharing configuration matter. A nested call cannot elevate the caller's token permissions. Pin approved versions and test upgrades with representative consumers before broad rollout.
Organization/enterprise policies can restrict allowed actions, require approved sources and control runner access. A Marketplace listing alone does not satisfy a company's trust policy. Central reuse reduces drift, but a central mistake affects many repositories; staged release and rollback remain necessary.
Use meaningful template metadata so developers can discover suitable starters. Treat a copied starter as independent code thereafter: fixing the central template does not automatically update every existing repository. Track adoption and update paths explicitly rather than assuming all consumers are current.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Standardize a full multi-job pipeline | Reusable workflow. |
| Package a few repeated steps | Composite action. |
| Give teams an editable starting example | Starter workflow/template. |
Traps
- A template update does not automatically patch existing copies.
- A nested workflow cannot increase token permissions beyond its caller.
Active recall
1. Where is a reusable workflow called?
At job level, not as an ordinary step.
2. Why define an interface?
To make inputs, secrets and outputs explicit and maintainable.
3. Why can a private call fail?
Caller policy or called-repository sharing/access may deny it.
4. What is the centralization trade-off?
Less drift but a larger blast radius for faulty shared changes.
5. How should a breaking shared change ship?
Version it, test consumers and provide a controlled migration/rollback path.