Skip to main content

In CI

In CI nothing is stored: instead of login, set HIVEPAAS_URL to the installation's address and HIVEPAAS_API_KEY to <key id>:<secret>, from the CI's secrets. Give the key only what the pipeline does: see CI/CD.

.github/workflows/deploy.yml
name: Deploy

on:
push:
branches: [main]

jobs:
deploy:
runs-on: ubuntu-24.04
steps:
- name: Install the HivePaaS CLI
run: |
v=1.0.0-beta1
base=https://github.com/hivepaas/hivepaas-cli/releases/download/v$v
curl -fsSLO "$base/hivepaas_${v}_linux_amd64.tar.gz"
curl -fsSLO "$base/checksums.txt"
sha256sum -c --ignore-missing checksums.txt
tar xzf "hivepaas_${v}_linux_amd64.tar.gz" hivepaas
sudo mv hivepaas /usr/local/bin/

- name: Deploy, and wait for it
env:
HIVEPAAS_URL: https://hivepaas.example.com
HIVEPAAS_API_KEY: ${{ secrets.HIVEPAAS_API_KEY }}
run: hivepaas deploy -p shop -e production -a api --image ghcr.io/acme/shop-api:${{ github.sha }}

Pin the CLI's version in CI, as above, and move it when you update the installation.

deploy fails the job when the deployment fails, and waits up to 30 minutes; --timeout changes that. job run waits for a scheduled job's run the same way. A command that would ask at a terminal needs --yes here: see Scripting.