deploymate

self-hosted · one Go binary · Apache-2.0

Your own Heroku, on a server you own.

Push to GitHub and get a zero-downtime deploy on your own machine — with databases, certificates, rollbacks, monitoring, and an AI agent that can operate it for you. No cloud bill, no lock-in.

curl -fsSL https://deploymate.link/install | sudo bash

Ubuntu Linux, amd64 or arm64. The installer checks a SHA-256 before it runs anything.

Fleet 6 apps healthy · 1 needs attention · 1 stopped
Deploy log · web
Made-up apps on a demo server. The strips are 24 hours: a notch is a deploy, red is time the app wasn't answering.

How a deploy goes

From git push to serving traffic, without dropping a request.

Five stages, always in this order. Each one is visible in the dashboard while it happens, and each has a way back.

Connect

Link a repository with a read-only deploy key and a webhook. Or let GitHub Actions build and hand DeployMate the finished artifact.

git push origin main

Build

A Dockerfile, or pick a runtime — Node, Python, Go, Java and more — and DeployMate builds it for you. Or skip building on the server entirely.

railpack build with runtime Node.js 22

Swap

The new version starts beside the old one. Only when it answers its health check does traffic move. If it doesn't, nothing changes.

the previous container is still serving

Watch

Health, uptime, certificates, CPU and memory, live logs. When something breaks, a plain-words reason — and an alert to your webhook.

Running, but failing its health check.

Recover

Retry a failed deploy, redeploy with new settings, or roll back to a previous image in one click. Databases back up on a schedule.

Roll back to this

The dashboard

This is the real thing, on made-up data.

Not a mockup: these pages are the dashboard's own markup and styles, captured from a demo server. Click around — the tabs inside work.

deploymate.acme.example/projects

Is anything broken? One line answers it, and what needs you comes first. Each strip is 24 hours — a notch is a deploy, a red cell is time the app wasn't answering.

What you get

Everything a small team needs to ship, in one box.

Grouped by what you're trying to do. Every item here ships today.

Deploy

git, CI or image

  • Git deploys on every push — GitHub, GitLab or Gitea, with live build logs.
  • Prebuilt mode: GitHub Actions builds the JAR; DeployMate downloads, verifies and runs it. No big build on a small server.
  • A review page before dashboard deploys: the commits and files since what's live.
  • Dockerfile or no Dockerfile: Node, Python, Go, Ruby, PHP, Java, Rust, Deno, Elixir, .NET, static sites.

Run

zero downtime, any size

  • Zero-downtime swaps — the old version serves until the new one is healthy.
  • 1–5 replicas per app, load-balanced, rolled one at a time.
  • Postgres, MySQL and Redis in a click; apps in the same project and environment get the connection URL automatically.
  • dev, staging, production, each with its own services. A deploymate.yml in the repo provisions them for you.

Watch

know before your users do

  • Fleet board: what needs you, first. 24-hour strips per app.
  • Health checks every 30 s, uptime probes per domain, real certificate state and expiry.
  • Failures explained in plain words, with the container's own last output.
  • Alerts to any webhook (Slack-compatible), CPU and memory charts, live logs.

Recover

undo is a button

  • One-click rollback — the last five images are kept.
  • Retry a failed deploy, or redeploy with changed variables and no new build.
  • PostgreSQL backups on a schedule to any S3-compatible storage (S3, R2, MinIO), with typed-confirm restore.
  • Crashed containers are healed automatically.

Secure by default

small surface, encrypted at rest

  • The firewall opens only SSH, 80 and 443; the dashboard and Docker are never exposed.
  • Keys, secrets and variables are encrypted at rest (XChaCha20-Poly1305).
  • Automatic HTTPS through Let's Encrypt, with a staging mode so mistakes can't burn your rate limit.
  • API tokens are hashed, scoped and expiring.

Yours

no cloud, no lock-in

  • One Go binary and SQLite. No Kubernetes, no control plane to babysit.
  • Runs on a VPS, a mini PC, or an old laptop (there's a guide).
  • Apache-2.0. Read it, change it, run it.
  • A dashboard that's dark by default, light if you prefer, and works on a phone.

For AI agents

Let an agent run the boring parts — on a leash you set.

DeployMate ships an MCP server, so Claude and other agents can look at your fleet, explain a failure, deploy and even set up new apps. What they may do is decided by the token you give them, and enforced by the server — not by the agent's good manners.

TokenThe agent can
readLook at everything: fleet, apps, deploys, logs, why a deploy failed.
deployAlso deploy, retry, redeploy, roll back, start, stop, restart.
provisionAlso create projects, apps, databases and domains, connect a repo, set variables.
  • Nothing can be deleted through it. Ever.
  • Secrets are write-only: it can set a variable, never read one back.
  • Every change is logged with the token's name, and writes are rate-limited.

Set it up in two minutes →

Install

A fresh server to a first deploy, in about five minutes.

The installer downloads the release for your CPU, verifies its checksum, and sets up Docker, the firewall, Traefik and a systemd service. Read it first if you like — it's short.

  1. Run the installer on the server

    As root, on a recent Ubuntu LTS.

    # your email is only used for Let's Encrypt
    curl -fsSL https://deploymate.link/install \
      | sudo [email protected] bash
  2. Create your login

    sudo -u deploymate DEPLOYMATE_DATA_DIR=/var/lib/deploymate /usr/local/bin/deploymate setup-admin
  3. Point a domain at the server, open the dashboard

    Add an A record, attach the domain to an app, and you're serving HTTPS. Connect a repo, add the deploy key, press Deploy.

    The full quickstart →

What it needs

Server
Any machine you control: a VPS, a mini PC, a spare laptop. A recent Ubuntu LTS, amd64 or arm64, and root access.
Network
Ports 80 and 443 open to the internet, and a domain pointing at the server for HTTPS.
Your computer
Nothing to install. The agent bridge (deploymate mcp) is a single file for macOS or Linux.

Prefer to build it yourself? make build — it's Go and nothing else. From source →

Can't open ports on your connection? An optional tunnel setup works without them.

Straight talk

Who it's for, and what it isn't yet.

DeployMate is deliberately small. Knowing the edges now saves you a bad week later.

A good fit

today

  • You have one server and want to stop paying per-seat, per-GB platform prices.
  • You deploy web apps and APIs: a handful to a few dozen.
  • You want Postgres, MySQL or Redis next to the app without managing them by hand.
  • You like the idea of an agent doing the routine ops, with limits.

Not yet

on purpose, or not built

  • One server, one owner. No clustering, no teams or roles yet.
  • Backups cover PostgreSQL, not MySQL or Redis.
  • Prebuilt mode is GitHub + Java (Gradle or Maven) for now.
  • No built-in metrics export yet, and no per-branch preview deploys.