Hands-on
Labs
Guided exercises you run on your own machine, against your own repository, with a clear finish line: something that builds, passes its tests, and that you can explain.
Standalone labs
Self-contained builds with their own prerequisites, validation commands and cleanup. Each one ends with something you can run — and a check that can fail.
- BeginnerMedium labBuild Your First GitHub Copilot ProjectA guided build of a small, tested Python CLI using GitHub Copilot — writing the instruction file first, then letting Copilot work inside it, and verifying every step with commands you run yourself.Needs: Python 3.11 or later on your machine
- IntermediateMedium labBuild an API With GitHub Copilot Agent ModeUse agent mode to build a small FastAPI service across multiple files, then review what it actually changed — including the two things it will get wrong unless you tell it not to.Needs: Python 3.11 or later
- IntermediateMedium labBuild Infrastructure With GitHub Copilot and TerraformWrite a validated Terraform module with Copilot without ever running apply — using variable validation, plan review and a security pass to catch what valid HCL does not.Needs: Terraform 1.9 or later, or OpenTofu 1.7+
- AdvancedExtended labBuild an MCP Integration for GitHub CopilotWrite a small Model Context Protocol server, connect it to Copilot read-only first, and learn why tool output is data rather than instructions.Needs: Python 3.11 or later
- AdvancedMedium labBuild a Custom GitHub Copilot AgentDesign an agent by restriction rather than instruction — a read-only security reviewer whose tool list makes the guidance in its body unnecessary.Needs: A Copilot client supporting custom agents from .github/agents/*.agent.md
Plus 31 exercises inside the lessons themselves.
Practical work that belongs to a specific lesson ships inside it rather than as a separate page that would have to be kept in sync. Everything below is live now.
Guided walkthroughs
Numbered steps, start to finish. Closest to a classic lab — follow them in order and you end with something running.
- Your first Copilot session13 steps
Get access, install, authenticate, then build a small Python project with completions and chat.
Finish lineA first suggestion you accepted and a test suite you ran yourself.
- Install and verify in VS Code11 steps
Install and authenticate in VS Code, then check completion, chat and agent mode each actually work.
Finish lineEvery feature verified individually, so a later failure has a known-good baseline.
- A REST API with agent mode7 steps
An empty folder to a working REST API, supervising the agent loop through planning, tool approval and checkpoints.
Finish lineTests pass, and you approved every tool call that got them there.
- Idea to pull request16 steps
A one-line requirement carried all the way to a reviewed pull request, with the steps that are yours marked as yours.
Finish lineA pull request you can defend line by line in review.
- A first Copilot CLI session10 steps
Trust a directory, ask before changing anything, review the diff, run the tests — on a throwaway project.
Finish lineA reviewed diff and a green test run, without leaving the terminal.
Reference files:
examples/cluster-5/tutorial(3 files) - Harden a Bash script4 steps
Write a health-check script with Copilot CLI, then apply quoting, exit status, traps and ShellCheck to it.
Finish lineShellCheck clean — and you found the two bugs it does not catch.
Reference files:
examples/cluster-5/bash-health-check(2 files)
Build and verify
25 exercises where you generate something with Copilot and then prove it is correct — usually by running a linter, a validator or a test against known ground truth. Each lesson carries the file tree, the exact prompt and the code inline, so there is nothing to download.
DevOps & Infrastructure12 exercises
- Containerise an applicationA multi-stage Dockerfile with a non-root user — then measure the first draft against the reviewed version.
examples/cluster-4/docker8 files - Compose a multi-service stackHealth-gated startup and dependencies that actually wait — and find the service quietly published to the network.
examples/cluster-4/docker-compose11 files - Write Kubernetes manifestsProbes, limits, securityContext and NetworkPolicy, against a manifest that passed strict schema validation with twenty-one findings still in it.
examples/cluster-4/kubernetes8 files - Write and plan TerraformGenerate HCL, validate it, and read the plan properly — before anything reaches an apply.
examples/cluster-4/terraform9 files - Encrypt OpenTofu stateThe same work as Terraform, plus a state file you cannot read without its passphrase.
examples/cluster-4/opentofu6 files - Lint an Ansible playbookIdempotent roles, handlers and validated templates — run the linter that found nineteen problems in the draft.
examples/cluster-4/ansible12 files - Secure a GitHub Actions workflowLeast-privilege permissions, SHA-pinned actions and OIDC — plus the script-injection vector hiding in a pull request title.
examples/cluster-4/github-actions12 files - Check an IAM policyIAM least privilege and OIDC for CI, run through a local checker that catches the wildcards Copilot leaves in.
examples/cluster-4/aws8 files - Deploy with Bicep and RBACBicep and role assignment by GUID — and the subscription context that decides which environment a generated command changes.
examples/cluster-4/azure4 files - Ship a Cloud Run serviceA dedicated service account, and the single IAM binding that turns a private service public.
examples/cluster-4/google-cloud3 files - Debug a Linux hostsystemd, logs, networking and diagnostics — plus two bugs in a health-check script that neither ShellCheck nor set -euo pipefail caught.
examples/cluster-4/linux4 files - Build the whole pipelineOne repository where Copilot writes every artefact and validates none — application, image, Terraform, manifests and workflow, behind gates that ran for real.
examples/cluster-4/ai-cicd-pipeline21 files
Copilot CLI5 exercises
- Run a Python project from the terminalVirtual environments, a failing test, pytest, Ruff and type checks — the whole loop without leaving the shell.
examples/cluster-5/python-project1 file - Layer custom instructionsEvery instruction file Copilot CLI loads, how they combine — and how to see which one actually applied.
examples/cluster-5/instructions-demo2 files - Build a CLI custom agentAn .agent.md file with a restricted tool list and one clear role, alongside the six built-in agents you already have.
examples/cluster-5/custom-agents2 files - Review code against known defectsRun /review and /security-review against a project with four deliberate defects, and judge the output against ground truth.
examples/cluster-5/code-review-demo2 files - Automate the CLI in Actionscopilot-requests permissions, GITHUB_TOKEN auth, narrow tool policies and forked-PR handling that does not leak.
examples/cluster-5/actions-demo2 files
Agents, MCP & Agentic Development5 exercises
- Build your first agent skillA repository-ready API testing skill — directory layout, frontmatter, reference material, a template and a validation script you can run.
examples/cluster-7/api-testing-skill5 files - Build a DevOps agentAn infrastructure agent that validates and never applies — profile, skill and instructions as one coherent configuration.
examples/cluster-7/devops-agent5 files - Build a code review agentA reviewer that is read-only by construction, checked against five planted defects so silence is distinguishable from success.
examples/cluster-7/code-review-agent3 files - Build a documentation agentThe lowest-risk agent worth building — and the rules that stop it inventing APIs, parameters and command output.
examples/cluster-7/documentation-agent1 file - Run an agentic workflowA markdown automation compiled into a GitHub Actions workflow — frontmatter, safe outputs and the read-only default.
examples/cluster-7/capstone4 files
Security, Code Review & Enterprise3 exercises
- Audit a Copilot code reviewFive planted defects and one clean negative control, so you can tell a review that found nothing from one that never ran.
examples/cluster-8/security-review-demo5 files - Keep secrets out of promptsA bad configuration and its corrected twin — and what secret scanning does not see. Placeholders only, deliberately obvious ones.
examples/cluster-8/secrets-demo4 files - Govern MCP serversAn allowlist in managed settings, and the surface a private registry does not reach.
examples/cluster-8/mcp-policy2 files