deploymate

Start

Connect GitHub

Connect GitHub once and DeployMate can clone your repositories and deploy on every push, with no deploy keys, no webhook URLs to paste and no access tokens to create or renew. You pick repositories from a list.

It works by creating a small private GitHub app on your own GitHub account. The app belongs to you, only sees the repositories you give it, and you can remove it at any time. The older manual setup (a deploy key plus a webhook per repository, covered here) keeps working next to it, and is still the way for GitLab and Gitea.

What you needA DeployMate you can sign in to, and an address for it that GitHub can reach from the internet (a domain, or your tunnel's hostname), because GitHub sends push notifications to https://your-address/hooks/github-app. Open the dashboard at that public address when you connect.

1. Connect

  1. In the dashboard, click the GitHub icon in the top bar, then Connect GitHub. Choose your personal account, or an organisation (type its name).
  2. GitHub opens a page titled Register new GitHub App, already filled in. The name is DeployMate plus your address; you can change it. Press Create GitHub App.
  3. You land back on DeployMate's GitHub page, which now says Connected and shows the app and its webhook address.

2. Install it on your repositories

  1. Press Install on GitHub.
  2. Choose Only select repositories and tick the ones you want to deploy (or All repositories if you prefer). You can change this later on GitHub.
  3. Back on DeployMate's GitHub page, Where it is installed lists your account.

3. Connect a repository to an app

  1. Open the app, then Settings → Source & build → Git.
  2. Under From GitHub, pick the repository. Leave Branch empty to use the repository's default branch.
  3. Press Connect repository, then Review & deploy.

There is nothing to copy: the app shows Through your GitHub app instead of a key and a webhook.

4. Push

From now on, every push to the app's branch deploys by itself. It appears in the app's history, triggered by webhook, with the usual build log. If several apps are built from one repository, a push only deploys the apps whose build folder it changed; the others show Push skipped in their activity.

Prebuilt apps (a GitHub Actions workflow builds the JAR) work the same way and need no token either: switch the app to Prebuilt under the same panel. DeployMate reads the workflow's runs and downloads the artifact through the app, and can start the workflow with Run workflow now.

What the app can and can't do

Read your codePermission Contents: read, only for the repositories you installed it on. DeployMate clones with a short-lived token (about an hour) that GitHub issues on demand, which is never written to disk.
Read CI runs, download artifacts, start a workflowPermission Actions: read and write. Used by prebuilt apps only.
Hear about pushes and finished runsSubscribed to the push and workflow run events, sent to your DeployMate's webhook address and checked against a secret before anything runs.
Change your codeNo. It has no write access to contents, issues, pull requests or settings.
See other accounts or repositoriesNo. Only what you installed it on.

The app's private key is stored encrypted on your server and is never shown on any page. Disconnect on the GitHub page deletes it; to remove the app from GitHub as well, delete it under Settings → Developer settings → GitHub Apps. Apps already connected keep their code but stop deploying on push.

Behind a login or a tunnel

GitHub has to reach /hooks/github-app without signing in. If the dashboard is behind Cloudflare Access, the hooks/* bypass from Deploy on every push already covers it. Everything else stays locked.

If you connected from an address GitHub can't reach (for example http://127.0.0.1:8080 through an SSH tunnel), the GitHub page warns you and the app is created with its webhook switched off: cloning and the repository list work, but pushes won't deploy. To fix it, open Settings → Developer settings → GitHub Apps → your app on GitHub, tick Active, and set the webhook URL to https://your-address/hooks/github-app (leave the secret as it is).

If something doesn't work

The setup page says GitHub didn't accept itThe one-time code from GitHub was used or is older than an hour. Press Connect GitHub again.
The repository list is emptyThe app isn't installed on any repository yet: press Install on GitHub and select some. A repository you add on GitHub shows up within a minute.
A deploy fails with “no longer lets DeployMate's app reach this repository”The app was removed from that repository (or deleted on GitHub). Install it again, or connect the app to a different repository.
A push doesn't deployOn GitHub open Settings → Developer settings → GitHub Apps → your app → Advanced. Recent Deliveries shows what DeployMate answered: queued worked; ignored: not the deploy branch means you pushed another branch; ignored: no app uses this repository means no app is connected to it; ignored: no changes in the build folder means the push didn't touch the app's folder; bad signature means DeployMate and GitHub disagree about the secret, so disconnect and connect again. A login page, 302 or 403 means something in front of the dashboard is blocking GitHub.
The webhook says it is switched offSee Behind a login or a tunnel above.