Skip to content
homeport

Docs · Deploy

Deploy from your own CI

On Growth and Business, you can build a Linux binary in GitHub Actions and deploy it with the homeport-sh/deploy action. It signs in with the run’s own GitHub OIDC token, so there is no API key or secret to store.

Set it up

  1. Create the app from a connected GitHub repository (Quickstart). A repository added by its public URL, or one on GitLab, cannot deploy from CI.
  2. In the app’s Settings → Builds, choose Deploy from my own CI instead. homeport stops building pushes to that environment’s branch. Let homeport build it switches back.
  3. Add a workflow that builds the binary and runs the action, on the branch the environment follows.

The workflow

.github/workflows/deploy.yml
name: Deploy
on:
  push:
    branches: [main]

permissions:
  id-token: write     # mint the OIDC token
  contents: read

jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v5
      - uses: oven-sh/setup-bun@v2
      - run: bun install --frozen-lockfile
      - run: bun build --compile --target=bun-linux-x64 ./src/index.ts --outfile server

      - uses: homeport-sh/deploy@v1
        with:
          artifact: ./server

For Go, build with CGO_ENABLED=0 GOOS=linux go build -o server . and pass the same artifact. The permissions: id-token: write line is required: without it the job has no token to sign in with.

Which app it deploys to

There is no app to name. The deploy lands on the environment that follows the branch the run is on: main to production, staging to staging. Only a repository that holds several apps on the same branch needs app:, set to the app’s name.

The token is checked against the repository and branch: a run from another repository, or from a branch no environment follows, is refused. Runs on GitHub-hosted runners are accepted.

Inputs

Action inputs
InputRequiredDefaultWhat it is
artifactYes—Path to the compiled Linux binary.
appNo—The app’s name, when the repository holds several apps.
timeoutNo600Seconds to wait for the deploy to go live.
api-urlNohttps://api.homeport.shLeave as it is.
audienceNohttps://api.homeport.shLeave as it is.

The action sets two outputs, deployment-id and status.

What you deploy

  • One Linux executable (ELF), for the architecture of the machine your app runs on. A macOS or Windows build is refused.
  • Up to 512 MB.
  • Its environment variables still come from homeport, set on the Variables tab. Your workflow never sees them.
  • It runs the same way as one homeport built: on $PORT, with its health check, and with the run, release and processes of the app.

For a static site, use homeport’s own builds or upload it: the action deploys binaries.

When it fails

Action errors
MessageFix
no OIDC token available — the job needs 'permissions: id-token: write'Add the permissions block.
no artifact at ./server — did the build step run?Check the path, and that the build step ran before.
./server is not a Linux (ELF) executable — check the build's GOOS/targetBuild for Linux.
this repository is not authorised to deploy … — check that an environment follows this branchRun on the branch an environment follows, from the repository the app was created from.
Deploying from your own CI needs GrowthThe team is on Free or Starter.
homeport builds this environment from its pushes; switch its build source to CIChoose Deploy from my own CI instead in the app’s Settings.
several apps of this repository follow this branch; set app: in the workflowAdd app:.
artifact does not match the box architectureBuild for the other architecture (x86-64 or arm64).