Getting started¶
Requirements¶
| Component | Version / notes |
|---|---|
| Linux server | Debian/Ubuntu x86_64 (amd64), root access. Tested on Debian 12. |
| Docker Engine + Compose plugin | docker compose version must work. |
| nginx | Sites in /etc/nginx/sites-available + sites-enabled (Debian layout). |
| certbot | With the nginx plugin (python3-certbot-nginx); an account already registered (certbot register). |
| PostgreSQL | 15+; the provided compose file runs postgres:17-alpine on 127.0.0.1:5450. |
| DNS provider | IONOS DNS API (built in). Your domain's zone must be hosted there. |
| Authentik | Optional but recommended: 2025.x, with the embedded outpost. Needed for SSO. |
| A wildcard of free subdomains | Deployer gives each app <name>.<your domain>. |
Why on the host and not in a container
Deployer writes nginx sites, runs nginx -t, reloads nginx, runs certbot and docker compose for every app.
Running it as a host service keeps those operations simple and visible; it listens on 127.0.0.1 only and is
reached through nginx.
1. Build the binary¶
The production artifact is one static binary that embeds the web interface.
git clone https://git.example.com/you/deployer.git && cd deployer
cd web && pnpm install --frozen-lockfile && pnpm build && cd ..
rm -rf api/internal/webui/dist/* && cp -r web/build/. api/internal/webui/dist/
cd api && CGO_ENABLED=0 go build -trimpath -ldflags="-s -w" -o ../dist/deployer ./cmd/deployer
Toolchain: Go 1.26+, Node 22+ with pnpm. The repository's scripts/build.sh does the same inside a development
container and also runs the type check, go vet and the test suite.
2. Database¶
sudo mkdir -p /opt/deployer/{bin,data,backups,secrets}
openssl rand -base64 32 | tr -d '\n' | sudo tee /opt/deployer/secrets/db_password >/dev/null
sudo chmod 600 /opt/deployer/secrets/db_password
sudo cp deploy/docker-compose.yml /opt/deployer/
cd /opt/deployer && sudo docker compose up -d
This starts deployer-db (PostgreSQL on 127.0.0.1:5450) and deployer-backup (a daily compressed pg_dump kept
14 days in /opt/deployer/backups). Adjust the network subnet in the compose file if 10.250.5.0/24 is used on
your host.
3. Configuration and service¶
sudo install -m 0755 dist/deployer /opt/deployer/bin/deployer
sudo mkdir -p /etc/deployer && sudo chmod 700 /etc/deployer
sudo tee /etc/deployer/env >/dev/null <<'EOF'
DEPLOYER_DATABASE_URL=postgres://deployer:<password>@127.0.0.1:5450/deployer?sslmode=disable
DEPLOYER_PUBLIC_URL=https://deploy.example.com
DEPLOYER_LISTEN=127.0.0.1:8150
DEPLOYER_DOMAIN=example.com
DEPLOYER_SERVER_IP=203.0.113.10
DEPLOYER_IONOS_ZONE=<your zone id>
DEPLOYER_IONOS_KEY_FILE=/etc/deployer/ionos.key
DEPLOYER_IONOS_NS=<authoritative name server>:53
DEPLOYER_AUTHENTIK_PUBLIC_URL=https://auth.example.com
EOF
sudo chmod 600 /etc/deployer/env
sudo cp deploy/deployer.service /etc/systemd/system/
sudo systemctl daemon-reload && sudo systemctl enable --now deployer
Every variable is described in Configuration. The IONOS key file contains
prefix.secret on one line, mode 600.
On first start Deployer:
- creates
/etc/deployer/master.key(AES-256, mode 600): back it up, it decrypts the secrets stored in the database; - applies the database migrations;
- prints a one-time setup token in the journal and writes it to
/etc/deployer/setup_token.
4. Publish it with nginx¶
sudo cp deploy/nginx.conf /etc/nginx/sites-available/deploy.example.com # edit server_name
sudo ln -s ../sites-available/deploy.example.com /etc/nginx/sites-enabled/
sudo nginx -t && sudo systemctl reload nginx
sudo certbot --nginx -d deploy.example.com
The provided site disables buffering for /api/runs/<id>/events (live run logs use Server-Sent Events).
5. First login¶
- Open
https://deploy.example.com: the setup wizard appears. - Enter the setup token (
sudo cat /etc/deployer/setup_token). - Create the first administrator (email, name, password of at least 10 characters).
- Optional, recommended: enable two-factor on the Account page; set
DEPLOYER_REQUIRE_MFA=1to make it mandatory for every action. - Optional: Settings → Authentik → Connect automatically creates a service account and API token in Authentik (or paste an admin API token), then choose the outpost and flows.
- System shows whether the DNS API and Authentik answer and which tool versions are found.
You are ready to create your first app: New app on the dashboard. See Using Deployer.