Hands-on

Labs

Guided exercises you run on your own machine, against your own repository, with a clear finish line: something that builds, passes its tests, and that you can explain.

Standalone labs

Self-contained builds with their own prerequisites, validation commands and cleanup. Each one ends with something you can run — and a check that can fail.

Plus 31 exercises inside the lessons themselves.

Practical work that belongs to a specific lesson ships inside it rather than as a separate page that would have to be kept in sync. Everything below is live now.

Guided walkthroughs

Numbered steps, start to finish. Closest to a classic lab — follow them in order and you end with something running.

  • Your first Copilot session13 steps

    Get access, install, authenticate, then build a small Python project with completions and chat.

    Finish lineA first suggestion you accepted and a test suite you ran yourself.

  • Install and verify in VS Code11 steps

    Install and authenticate in VS Code, then check completion, chat and agent mode each actually work.

    Finish lineEvery feature verified individually, so a later failure has a known-good baseline.

  • A REST API with agent mode7 steps

    An empty folder to a working REST API, supervising the agent loop through planning, tool approval and checkpoints.

    Finish lineTests pass, and you approved every tool call that got them there.

  • Idea to pull request16 steps

    A one-line requirement carried all the way to a reviewed pull request, with the steps that are yours marked as yours.

    Finish lineA pull request you can defend line by line in review.

  • A first Copilot CLI session10 steps

    Trust a directory, ask before changing anything, review the diff, run the tests — on a throwaway project.

    Finish lineA reviewed diff and a green test run, without leaving the terminal.

    Reference files: examples/cluster-5/tutorial (3 files)

  • Harden a Bash script4 steps

    Write a health-check script with Copilot CLI, then apply quoting, exit status, traps and ShellCheck to it.

    Finish lineShellCheck clean — and you found the two bugs it does not catch.

    Reference files: examples/cluster-5/bash-health-check (2 files)

Build and verify

25 exercises where you generate something with Copilot and then prove it is correct — usually by running a linter, a validator or a test against known ground truth. Each lesson carries the file tree, the exact prompt and the code inline, so there is nothing to download.

DevOps & Infrastructure12 exercises

  • Containerise an applicationA multi-stage Dockerfile with a non-root user — then measure the first draft against the reviewed version.examples/cluster-4/docker 8 files
  • Compose a multi-service stackHealth-gated startup and dependencies that actually wait — and find the service quietly published to the network.examples/cluster-4/docker-compose 11 files
  • Write Kubernetes manifestsProbes, limits, securityContext and NetworkPolicy, against a manifest that passed strict schema validation with twenty-one findings still in it.examples/cluster-4/kubernetes 8 files
  • Write and plan TerraformGenerate HCL, validate it, and read the plan properly — before anything reaches an apply.examples/cluster-4/terraform 9 files
  • Encrypt OpenTofu stateThe same work as Terraform, plus a state file you cannot read without its passphrase.examples/cluster-4/opentofu 6 files
  • Lint an Ansible playbookIdempotent roles, handlers and validated templates — run the linter that found nineteen problems in the draft.examples/cluster-4/ansible 12 files
  • Secure a GitHub Actions workflowLeast-privilege permissions, SHA-pinned actions and OIDC — plus the script-injection vector hiding in a pull request title.examples/cluster-4/github-actions 12 files
  • Check an IAM policyIAM least privilege and OIDC for CI, run through a local checker that catches the wildcards Copilot leaves in.examples/cluster-4/aws 8 files
  • Deploy with Bicep and RBACBicep and role assignment by GUID — and the subscription context that decides which environment a generated command changes.examples/cluster-4/azure 4 files
  • Ship a Cloud Run serviceA dedicated service account, and the single IAM binding that turns a private service public.examples/cluster-4/google-cloud 3 files
  • Debug a Linux hostsystemd, logs, networking and diagnostics — plus two bugs in a health-check script that neither ShellCheck nor set -euo pipefail caught.examples/cluster-4/linux 4 files
  • Build the whole pipelineOne repository where Copilot writes every artefact and validates none — application, image, Terraform, manifests and workflow, behind gates that ran for real.examples/cluster-4/ai-cicd-pipeline 21 files

Copilot CLI5 exercises

  • Run a Python project from the terminalVirtual environments, a failing test, pytest, Ruff and type checks — the whole loop without leaving the shell.examples/cluster-5/python-project 1 file
  • Layer custom instructionsEvery instruction file Copilot CLI loads, how they combine — and how to see which one actually applied.examples/cluster-5/instructions-demo 2 files
  • Build a CLI custom agentAn .agent.md file with a restricted tool list and one clear role, alongside the six built-in agents you already have.examples/cluster-5/custom-agents 2 files
  • Review code against known defectsRun /review and /security-review against a project with four deliberate defects, and judge the output against ground truth.examples/cluster-5/code-review-demo 2 files
  • Automate the CLI in Actionscopilot-requests permissions, GITHUB_TOKEN auth, narrow tool policies and forked-PR handling that does not leak.examples/cluster-5/actions-demo 2 files

Agents, MCP & Agentic Development5 exercises

  • Build your first agent skillA repository-ready API testing skill — directory layout, frontmatter, reference material, a template and a validation script you can run.examples/cluster-7/api-testing-skill 5 files
  • Build a DevOps agentAn infrastructure agent that validates and never applies — profile, skill and instructions as one coherent configuration.examples/cluster-7/devops-agent 5 files
  • Build a code review agentA reviewer that is read-only by construction, checked against five planted defects so silence is distinguishable from success.examples/cluster-7/code-review-agent 3 files
  • Build a documentation agentThe lowest-risk agent worth building — and the rules that stop it inventing APIs, parameters and command output.examples/cluster-7/documentation-agent 1 file
  • Run an agentic workflowA markdown automation compiled into a GitHub Actions workflow — frontmatter, safe outputs and the read-only default.examples/cluster-7/capstone 4 files

Security, Code Review & Enterprise3 exercises

  • Audit a Copilot code reviewFive planted defects and one clean negative control, so you can tell a review that found nothing from one that never ran.examples/cluster-8/security-review-demo 5 files
  • Keep secrets out of promptsA bad configuration and its corrected twin — and what secret scanning does not see. Placeholders only, deliberately obvious ones.examples/cluster-8/secrets-demo 4 files
  • Govern MCP serversAn allowlist in managed settings, and the surface a private registry does not reach.examples/cluster-8/mcp-policy 2 files