The cleanest way to "deploy on green": your CI runs the tests and then asks the deployer to deploy, with a token that can do nothing else.
1. A token for the project
On the project's CI page, create a token with the scopes deploy and read. It works
only for that project and is shown once; store it as a CI secret, e.g. DEPLOYER_TOKEN. On the server,
root can also create one: sudo deployer api-token create --name ci --project shop --scope deploy,read.
2. Make pushes wait for CI (optional)
Set the project's deploy trigger to CI only (project settings). Webhook deliveries are then still verified and logged, but only your CI starts deploys.
3. Deploy from the pipeline
curl -fsS -X POST \
-H "Authorization: Bearer $DEPLOYER_TOKEN" \
-H 'Content-Type: application/json' \
-d "{\"sha\": \"$COMMIT_SHA\"}" \
https://deploy.brakkit.com/api/v1/projects/shop/deploys
sha is optional; when given, it must be a commit on the project's branch. A deploy that is still queued
is replaced by the newer one. The answer:
{"deploy_id": "…", "number": 12, "url": "https://deploy.brakkit.com/projects/shop/deploys/12", "deploy": {…}}
4. Wait for the result
curl -fsS -H "Authorization: Bearer $DEPLOYER_TOKEN" https://deploy.brakkit.com/api/v1/deploys/$ID | jq -r .state
# queued → fetching → building → starting → health_checking → switching → live
# or: failed, rolled_back, cancelled, superseded
The live log is a Server-Sent Events stream: curl -N -H "Authorization: Bearer $DEPLOYER_TOKEN" https://deploy.brakkit.com/api/v1/deploys/$ID/log.
Examples
GitHub Actions
deploy:
needs: test
if: github.ref == 'refs/heads/main'
runs-on: ubuntu-latest
steps:
- run: |
curl -fsS -X POST \
-H "Authorization: Bearer ${{ secrets.DEPLOYER_TOKEN }}" \
-H 'Content-Type: application/json' \
-d "{\"sha\": \"$GITHUB_SHA\"}" \
https://deploy.brakkit.com/api/v1/projects/shop/deploys
GitLab CI
deploy:
stage: deploy
rules:
- if: $CI_COMMIT_BRANCH == "main"
script:
- >
curl -fsS -X POST -H "Authorization: Bearer $DEPLOYER_TOKEN"
-H 'Content-Type: application/json' -d "{\"sha\": \"$CI_COMMIT_SHA\"}"
https://deploy.brakkit.com/api/v1/projects/shop/deploys
Rollback and other calls
# roll back to release r41 (scope: deploy)
curl -fsS -X POST -H "Authorization: Bearer $DEPLOYER_TOKEN" -H 'Content-Type: application/json' \
-d '{"release": 41}' https://deploy.brakkit.com/api/v1/projects/shop/rollback
# cancel a deploy
curl -fsS -X POST -H "Authorization: Bearer $DEPLOYER_TOKEN" https://deploy.brakkit.com/api/v1/deploys/$ID/cancel
The whole registration can be scripted as well, with a global token that has the admin scope (created on
your account page).