Using Locally with GitHub Actions

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

Using Locally with GitHub Actions

Locally can be used in GitHub Actions to test your changes in pull requests. We recommend using the locallybuild/setup-locally action, which installs and starts Locally for you (see How it works below).

Locally authenticates using GitHub's built-in OIDC tokens, so you don't need to store any secrets in your repository. To set this up:

  1. Configure an OIDC Trust in your Locally Account. The trust needs to match the subject GitHub sends, which you'll find in your repository's OIDC settings at https://github.com/{owner}/{repository}/settings/actions/oidc-configuration.
  2. Add permissions: id-token: write to your workflow, so GitHub can issue OIDC tokens.
  3. Pass your Team's UUID to the action using the team-uuid input (or user-uuid, if your OIDC Trust belongs to your User).

Example Workflow

name: Locally

on:
  pull_request:
    types: ['opened', 'synchronize']

jobs:
  provision:
    runs-on: ubuntu-latest
    permissions:
      contents: read
      # Required: GitHub mints the OIDC token
      # that Locally signs in with.
      id-token: write
    steps:
      # This example doesn't use anything from the
      # repository, but if you're copying it and want
      # to use files from your repository (for example,
      # to run your tests), check it out first:
      #
      # - uses: actions/checkout@v7

      - name: Set up Locally (with Microsoft.Storage)
        uses: locallybuild/setup-locally@v1
        with:
          team-uuid: ${{ vars.LOCALLY_TEAM_UUID }}
          plugins: custom
          plugins-list: |
            Microsoft.Storage

      - name: Create a Resource Group using the Azure CLI
        run: locally run az group create -n example -l berlin

      - name: List the Resource Groups using the Azure CLI
        run: locally run az group list

      - name: Create a Storage Account using the Azure CLI
        run: |
          locally run az storage account create \
            -n account1 -g example -l berlin --sku Standard_LRS

      - name: Create a Container within that Storage Account
        run: |
          locally storage container create \
            --account account1 --name mydata

      - name: Tear down Locally
        uses: locallybuild/setup-locally/teardown@v1
        if: always()

Choosing a Plugin Set

By default the action installs the recommended plugin set. To install every available plugin, or just a specific list, use the plugins input:

- name: Setup Locally
  uses: locallybuild/setup-locally@v1
  with:
    team-uuid: ${{ vars.LOCALLY_TEAM_UUID }}
    plugins: custom
    plugins-list: |
      Microsoft.ServiceBus
      Microsoft.Storage

See the action README for the full input reference, including pinning a specific CLI version, controlling the plugin cache, and using the install-plugins subaction to install additional plugins later in a job.

How it works

When the setup-locally action runs, it:

  • Downloads and verifies the Locally CLI (against either an explicit expected-checksum or the published .sha256 sibling).
  • Generates short-lived TLS material and exports the LOCALLY_TLS_* and LOCALLY_WORKING_DIRECTORY environment variables for subsequent steps.
  • Installs the requested plugin set (cached between runs by default).
  • Starts locally ci in the background, which requests an OIDC token from GitHub, exchanges it with the Locally API against your configured OIDC trust, and waits until the local endpoints are ready.

The teardown subaction stops locally ci at the end of the job and, on failure, uploads ci.log as a workflow artifact for debugging. The if: always() ensures cleanup runs even if earlier steps fail.

Examples

This example repository runs the setup-locally action in a working GitHub Actions workflow you can copy:

Next steps

The Automation API lets later steps in your job look up Locally's endpoints. If you use Claude Code or another agent, the locally-ci skill in the Agent Skills can set up a workflow like this for you.

Should you encounter any issues, please take a look at the troubleshooting section.

Preview

Sign in during Public Preview to get the Team plan free, plus an early-adopter discount when we launch. Sign in

A local cloud for you and your agents.

Your Azure infrastructure, running on your machine. Deploy in seconds, break things freely, and ship to Azure when you're ready.