Docs · Deploy
Deploy from your own CI
On Growth and Business, you can build a Linux binary in GitHub Actions and deploy it with the homeport-sh/deploy action. It signs in with the run’s own GitHub OIDC token, so there is no API key or secret to store.
Set it up
- Create the app from a connected GitHub repository (Quickstart). A repository added by its public URL, or one on GitLab, cannot deploy from CI.
- In the app’s Settings → Builds, choose Deploy from my own CI instead. homeport stops building pushes to that environment’s branch. Let homeport build it switches back.
- Add a workflow that builds the binary and runs the action, on the branch the environment follows.
The workflow
name: Deploy
on:
push:
branches: [main]
permissions:
id-token: write # mint the OIDC token
contents: read
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v5
- uses: oven-sh/setup-bun@v2
- run: bun install --frozen-lockfile
- run: bun build --compile --target=bun-linux-x64 ./src/index.ts --outfile server
- uses: homeport-sh/deploy@v1
with:
artifact: ./serverFor Go, build with CGO_ENABLED=0 GOOS=linux go build -o server . and pass the same artifact. The permissions: id-token: write line is required: without it the job has no token to sign in with.
Which app it deploys to
There is no app to name. The deploy lands on the environment that follows the branch the run is on: main to production, staging to staging. Only a repository that holds several apps on the same branch needs app:, set to the app’s name.
The token is checked against the repository and branch: a run from another repository, or from a branch no environment follows, is refused. Runs on GitHub-hosted runners are accepted.
Inputs
| Input | Required | Default | What it is |
|---|---|---|---|
artifact | Yes | — | Path to the compiled Linux binary. |
app | No | — | The app’s name, when the repository holds several apps. |
timeout | No | 600 | Seconds to wait for the deploy to go live. |
api-url | No | https://api.homeport.sh | Leave as it is. |
audience | No | https://api.homeport.sh | Leave as it is. |
The action sets two outputs, deployment-id and status.
What you deploy
- One Linux executable (ELF), for the architecture of the machine your app runs on. A macOS or Windows build is refused.
- Up to 512 MB.
- Its environment variables still come from homeport, set on the Variables tab. Your workflow never sees them.
- It runs the same way as one homeport built: on
$PORT, with its health check, and with the run, release and processes of the app.
For a static site, use homeport’s own builds or upload it: the action deploys binaries.
When it fails
| Message | Fix |
|---|---|
no OIDC token available — the job needs 'permissions: id-token: write' | Add the permissions block. |
no artifact at ./server — did the build step run? | Check the path, and that the build step ran before. |
./server is not a Linux (ELF) executable — check the build's GOOS/target | Build for Linux. |
this repository is not authorised to deploy … — check that an environment follows this branch | Run on the branch an environment follows, from the repository the app was created from. |
Deploying from your own CI needs Growth | The team is on Free or Starter. |
homeport builds this environment from its pushes; switch its build source to CI | Choose Deploy from my own CI instead in the app’s Settings. |
several apps of this repository follow this branch; set app: in the workflow | Add app:. |
artifact does not match the box architecture | Build for the other architecture (x86-64 or arm64). |