GITHUB COPILOT TUTORIALCopilot CLI:7 DevOps andSecurity WorkflowsPlan mode, custom agents, hooks,and headless runs in CI$ copilot> audit nginx.conf for TLS and header misconfigs[Explore] scanning 14 files[Task] nginx -t … OKFound 3 issues: – TLSv1.0 enabled – no HSTS header – server_tokens onApply fixes? [y/N]THA-SHED.COM
the shed // GITHUB COPILOT TUTORIAL

GitHub Copilot CLI is a full coding agent that lives in your terminal: it plans, delegates to sub-agents, obeys hooks you write, and runs headless in CI. Here are seven workflows DevOps and security folks can put to work today.

See the workflow in action, tap through the tabs below:




copilot-cli-devops.sh

// install, launch, generate repo instructions

npm install -g @github/copilot
cd ~/src/acme-infra
copilot
# inside the session:
/login
/init

// .github/agents/sec-audit.agent.md, then invoke it

---
name: sec-audit
description: Read-only security review of infra and app code
tools: ['read', 'search', 'shell(grep:*)', 'shell(trivy:*)']
---
You are a security reviewer. Never edit files. Check for hardcoded
secrets, permissive IAM, missing TLS settings, unpinned images, and
shell injection in CI scripts. Report a table: file, line, severity, fix.

$ copilot --agent=sec-audit -p 'Review @infra/ and @.github/workflows/'

// non-interactive review step for a pipeline

copilot -p '/review the changes on this branch compared to main. Focus on bugs and security issues. Reply with a severity table and exit non-zero if anything is HIGH.' \
  -s --allow-tool='shell(git:*)' --no-ask-user | tee review.md

// preToolUse hook: block destructive shell commands

#!/usr/bin/env bash
# .github/hooks/deny-danger.sh (wired via a preToolUse hook)
input=$(cat)
if echo "$input" | grep -Eq 'rm -rf|terraform destroy|kubectl delete ns|DROP TABLE'; then
  echo '{"permissionDecision":"deny","permissionDecisionReason":"Blocked by policy hook"}'
  exit 0
fi
echo '{}'

Trust prompt is not decoration. Copilot can read, edit, and execute anything under the folder you trust. Never “remember this folder” for a directory that holds cloned third-party repos.

“Approve for the session” is a blast radius decision. Approving rm or terraform for the whole session means no more prompts for those tools. Prefer per-call approval, or write a hook.

Headless runs need least privilege. Use –allow-tool and –allow-url with narrow patterns. Save –allow-all-tools for a throwaway sandbox.

Budget. Since June 2026 usage bills as GitHub AI Credits, per token, so a long autopilot session on a frontier model costs more than a quick Explore query. Check /usage and set user budgets in org settings.

What GitHub Copilot CLI actually is

Forget the autocomplete you remember from 2023. GitHub Copilot CLI, generally available since February 2026, is a terminal-native coding agent. You type a goal, it plans, edits files, runs commands, checks its own work, and iterates until the job is done or it needs a decision from you. It ships with GitHub's MCP server built in, supports custom MCP servers, plugins, skills, hooks, and custom agents, and it can hand work off to the Copilot cloud agent when you'd rather not tie up your terminal.

For DevOps and security people that matters because the terminal is already where we live. No tab switching to a chat window, no pasting logs into a browser. Copilot sits in the same shell as kubectl, terraform, and git, and it can call all three.

It runs on macOS, Linux, and Windows, and it is included with Copilot Pro, Pro+, Business, and Enterprise. Business and Enterprise admins have to enable it from the Policies page first.

Copilot CLI workflow: from prompt to reviewed change01PLANShift+Tab, agreeon the approach02DELEGATEExplore, Task,Code Review agents03GUARDpreToolUse hooksdeny risky calls04REVIEW/diff and /reviewbefore commit05SHIPPR via built-inGitHub MCPLoop: reject a tool call with feedback and Copilot re-plans without losing context.Esc-Esc rewinds file changes to any earlier snapshot in the session.(Illustration with example data)THA-SHED.COM

Quick setup

Pick your installer. npm works everywhere, Homebrew and WinGet auto-update:

npm install -g @github/copilot
# or
brew install --cask copilot-cli
# or
winget install GitHub.Copilot
# or
curl -fsSL https://gh.io/copilot-install | bash

Then cd into a repo and run copilot. You'll get a trust prompt for the folder (more on that below), then /login to authenticate, then /init to generate a .github/copilot-instructions.md tailored to the project. Do the /init step. It is the difference between an agent that guesses your conventions and one that reads them.

Two more things worth doing on day one: press Shift+Tab to see plan mode, and type /agent to see the built-in agents (Explore, Task, General purpose, Code review, Research). You'll use both constantly.

The mindset: you are the approver, not the typist

Copilot CLI has a permission dial. At one end you approve every file write and every shell command. At the other end, autopilot mode lets it run the whole task without stopping. The productive place for infrastructure work is in the middle: let it read and explore freely, approve writes and commands per call, and encode your hard limits as hooks so you never have to remember them under pressure.

Treat every prompt like a ticket you'd hand a sharp junior engineer. State the goal, the constraints, and how you'll know it's done. Point it at files with @path/to/file. Then let it plan first. A two-minute plan review saves a twenty-minute cleanup.

7 workflows for DevOps and security

1. Plan mode for a Terraform change you're nervous about

Hit Shift+Tab, then describe the change. Copilot asks clarifying questions and writes a structured plan before touching anything.

Add a read-only IAM role for the audit team that can describe EC2, RDS, and S3 but cannot read object contents. Follow the naming in @infra/iam/roles.tf. Plan only, do not apply.

Review the plan, edit it in place, approve. Then ask it to run terraform plan and read the diff back to you.

2. A read-only security audit agent

Custom agents are Markdown profiles in .github/agents/ (repo scope) or ~/.copilot/agents/ (user scope). Give one a locked-down tool list and it becomes a reviewer that physically cannot edit anything.

copilot --agent=sec-audit -p 'Review @infra/ and @.github/workflows/ and report findings as a table'

Check the agent profile in the widget above. The frontmatter tools list is the real safety control; the prose is just guidance.

Custom agent profile: .github/agents/sec-audit.agent.mdsec-audit.agent.md---name: sec-auditdescription: Read-only security review of infra and app codetools: ['read', 'search', 'shell(grep:*)', 'shell(trivy:*)']---You are a security reviewer for the acme-payments repo.Never edit files. Never run anything that writes to disk.Check for: hardcoded secrets, permissive IAM, missingTLS settings, unpinned container images, and shellinjection in CI scripts.Report as a table: file, line, severity, fix.$ copilot --agent=sec-audit -p 'Review @infra/ and @.github/workflows/'(Illustration with example data)THA-SHED.COM

3. Headless code review in CI

Programmatic mode (-p) runs one prompt and exits, which makes it a pipeline step. Pair it with narrow permissions.

copilot -p '/review the changes on this branch compared to main. Focus on bugs and security issues.' \
  -s --allow-tool='shell(git:*)' --no-ask-user | tee review.md

Use -s for quiet output and wrap it in an if when you want a yes/no gate. GitHub's own docs recommend giving minimal permissions here and reserving --allow-all-tools for sandboxes.

4. Incident triage without leaving the shell

The Task agent runs commands and summarizes; the Explore agent reads without polluting your main context. Point both at a live problem.

The api deployment in namespace payments is crash-looping. Use kubectl to pull the last 200 log lines and the pod events, then tell me the most likely cause and the single safest next command. Do not apply anything.

Approve the kubectl get and kubectl logs calls one at a time. Decline anything that mutates state and tell it why; it will re-plan with that feedback instead of stopping cold.

5. Policy hooks that say no for you

Hooks run shell commands at lifecycle points. A preToolUse hook can deny or rewrite a tool call before it happens, which is exactly the place to put "never terraform destroy from an agent" rules. The widget's tab 04 shows a minimal deny script. Wire it up once and it applies to every session in the repo, including headless ones.

6. Scheduled prompts for boring recurring checks

Inside a session, /every repeats a prompt on an interval and /after runs one later.

/every 1h Run the integration tests and report any failures
/after 30m Check whether the staging cert renewal job finished and summarize

This is a dev-box convenience, not a replacement for real schedulers, but it is fantastic during a long migration afternoon.

7. Delegate to the cloud agent and pick it up later

Prefix a prompt with & to hand the task to the Copilot cloud agent. It works in a GitHub-hosted environment and opens a PR. Your terminal is free immediately. Use /resume to jump between local and remote sessions.

& Pin every GitHub Action in .github/workflows/ to a full commit SHA and add a comment with the version tag. Open a PR titled "ci: pin actions to SHAs".
Headless run in CI: output from copilot -pci-review.log$ copilot -p '/review changes vs main, focus on security' -s \ --allow-tool='shell(git:*)' --no-ask-userReviewing 6 changed files on branch feat/rotate-keys ... HIGH deploy/k8s/api.yaml:41 container runs as root (runAsUser missing) HIGH scripts/rotate.sh:17 unquoted KEY_ID allows word splitting MED .github/workflows/ci.yml actions/checkout not pinned to a SHA LOW src/auth/token.py:88 log line includes token prefixSummary: 2 high, 1 medium, 1 low. Blocking merge on HIGH findings.exit code: 1Cost this run: 41 AI credits (example)(Illustration with example data)THA-SHED.COM

Safety and gotchas

The trust prompt is the whole security model for local files. When you start Copilot in a folder it asks whether to trust it, once or forever. "Forever" is fine for your own repo. It is not fine for a scratch directory full of cloned third-party code, because prompt injection hidden in a README can steer an agent that has shell access.

Session-wide tool approval is a blast radius decision. The docs say it plainly: approving rm for the session lets Copilot delete anything under the working directory without asking again. Approve per call for anything destructive, or write a hook.

Headless means nobody is watching. In CI use --allow-tool patterns like shell(git:*) and --allow-url allowlists. Keep secrets out of the prompt; the agent's output may end up in logs.

Rewind exists, use it. Esc twice rewinds file changes to an earlier snapshot in the session. /diff shows everything the session changed before you commit.

Content exclusions are now GA for the CLI, so org admins can keep specific paths (think secrets/, *.pem) out of Copilot's context entirely. Turn them on.

Usage and cost tips

As of June 2026 Copilot bills AI usage as GitHub AI Credits, metered per token rather than per request. Pro is $10 a month, Pro+ $39, Business $19 per user, Enterprise $39 per user, each with a monthly credit allowance; there is also a $100 Max tier for heavy individual use. Practical implications: the Explore agent on a fast model is cheap, a long autopilot session on a frontier model is not. Switch models with /model and use a smaller model for reads and summaries. GitHub notes that some models (GPT-5 mini and GPT-4.1 at GA time) are included without extra premium cost. Admins can set per-user budgets with expiry dates. Auto-compaction kicks in around 95% of the context window, so very long sessions won't crash, but they will cost more; start a fresh session for a fresh task.

If you're building the habit of agentic tooling across your whole stack, pair this with our Claude Code workflows for DevOps and security piece, and see our courses for the hands-on labs.

FAQ

Is GitHub Copilot CLI free?

No. Copilot CLI requires a Copilot Pro, Pro+, Business, or Enterprise plan. The Copilot Free tier covers IDE completions and chat with limited requests but does not include the CLI agent.

Can Copilot CLI run in GitHub Actions or another CI system?

Yes. Use programmatic mode (copilot -p "...") with explicit --allow-tool permissions and --no-ask-user. Authentication supports GitHub CLI token reuse and a CI-friendly GITHUB_ASKPASS flow.

How is Copilot CLI different from Claude Code or Gemini CLI?

The core loop is similar: an agent in your terminal that plans, edits, and runs commands. Copilot's edge is native GitHub integration (built-in GitHub MCP server, cloud agent handoff that opens PRs, org-level policies and content exclusions) and multi-vendor model choice from Anthropic, OpenAI, and Google inside one subscription.

Start today

Install it, run /init, and give it one real but low-stakes task from your backlog this week: pinning Actions to SHAs, adding a missing security header, writing the runbook nobody wrote. Keep your hand on the approval prompt and let it earn more rope. If you want structured practice with agentic DevOps and security tooling, check out our courses.