OpenSearch: 4. GitHub Actions

This documentation is part of the GitHub Actions & GitLab CI guide. View the full guide here: Spin up a real OpenSearch service from your GitHub Actions or GitLab CI pipeline, run your tests against it, and tear it down automatically.

👋 Welcome to the Stackhero documentation!

Stackhero provides a fully managed OpenSearch cloud environment designed for both performance and security:

  • High performance and strong security on a private, dedicated infrastructure.
  • Use your own custom domain name, protected with HTTPS by default.
  • Built-in OpenSearch Dashboards for easy data exploration and visualization.

Cut out setup and maintenance hassles: you can be up and running with OpenSearch cloud hosting from Stackhero in just a few minutes.

To get started, you can save the following as .github/workflows/ci.yml. From now on, every push and pull request will run tests against a real OpenSearch instance.

name: CI with OpenSearch

on: [push, pull_request]

jobs:
  test:
    runs-on: ubuntu-latest
    env:
      STACKHERO_TOKEN: ${{ secrets.STACKHERO_TOKEN }}
      STACK_NAME: ci-opensearch-${{ github.run_id }}-${{ github.run_attempt }}
      INSTANCE: "20G"   # Change this as needed (see step 3)
      REGION: europe
    steps:
      - uses: actions/checkout@v4

      - name: Install the Stackhero CLI and the client
        run: |
          curl -fsSL https://www.stackhero.io/install.sh | sh
          apt-get update && apt-get install -y --no-install-recommends jq curl

      - name: Create the OpenSearch service
        run: |
          set -euo pipefail
          STACK_ID=$(stackhero --format=script stack-create --name="$STACK_NAME")
          echo "STACK_ID=$STACK_ID" >> "$GITHUB_ENV"
          SERVICE_ID=$(stackhero --format=script service-add \
            --stack="$STACK_ID" \
            --service-store="opensearch" \
            --instance="$INSTANCE" \
            --region="$REGION")
          echo "SERVICE_ID=$SERVICE_ID" >> "$GITHUB_ENV"
          stackhero service-wait-for --service="$SERVICE_ID"

      - name: Run tests against OpenSearch
        run: |
          set -euo pipefail
          config=$(stackhero service-configuration-get --service="$SERVICE_ID" --format=json)
          host=$(echo "$config" | jq -r '.configuration.domain')
user=$(echo "$config" | jq -r '.configuration.credentials.login')
password=$(echo "$config" | jq -r '.configuration.credentials.password')
          # Call the cluster health endpoint.
          curl -fsS -u "$user:$password" "https://$host:9200/_cluster/health" | grep -q '"status"'
          echo "✅ OpenSearch is reachable from CI."
          # You can run your own test suite here using the credentials above ...

      - name: Tear down (always, even on failure)
        if: always()
        run: |
          if [ -n "${SERVICE_ID:-}" ]; then
            stackhero service-delete --service="$SERVICE_ID" --confirm
            stackhero service-wait-for --service="$SERVICE_ID"
          fi
          if [ -n "${STACK_ID:-}" ]; then
            stackhero stack-delete --stack="$STACK_ID" --confirm
          fi

The teardown step is configured with if: always() so it runs no matter what, making sure your OpenSearch instance is deleted and you are not billed for unused resources.