Skip to content

Configuration

One TOML file plus a secrets file:

Install Config Secrets
without root ~/.config/nimdeploy/config.toml ~/.config/nimdeploy/secrets.env
service account ~deploy/.config/nimdeploy/config.toml ~deploy/.config/nimdeploy/secrets.env
as root /etc/nimdeploy/config.toml /etc/nimdeploy/secrets.env

The config only holds the names of environment variables (*_env); the values live in secrets.env (NAME=value, mode 600), which systemd loads as the service's environment. The config can therefore be shared or committed; the secrets file never.

nimdeploy -check                 # validate config and secrets, exit 0/1
systemctl reload nimdeploy       # apply config.toml; running deploys continue
systemctl restart nimdeploy      # after changing secrets.env, listen or logging.directory

A complete annotated example is in config.example.toml.

[server]

Key Default
listen 127.0.0.1:9000 host:port or unix:/path/to.sock
socket_mode 0666 permissions of the unix socket
base_path – only if the proxy forwards /prefix/hooks/... without stripping /prefix
trusted_proxies ["127.0.0.0/8", "::1"] proxies whose X-Forwarded-For / X-Real-IP are believed; "cloudflare" adds Cloudflare's ranges
client_ip_header – e.g. CF-Connecting-IP, read only from trusted proxies
max_body_bytes 26214400 (25 MB) larger requests are rejected
shutdown_timeout 5m on stop, wait this long for running deploys
api_token_env – env var with the Bearer token for /status, /history, /deploy and the CLI. Without it /status is open and manual deploys are disabled

[logging]

Key Default
directory /var/log/nimdeploy one subdirectory per deploy (user install: ~/.local/state/nimdeploy)
retain 30 log files kept per deploy; 0 keeps all

[notify]

Key Default
format – slack, discord, telegram or json
on failure failure (failures and recoveries), always, never
url_env – env var with the webhook URL (all formats except Telegram)
telegram_token_env, telegram_chat_id – Telegram bot token variable and chat ID
log_lines 20 last log lines included in failure messages

See Notifications.

[github]

Key Default
token_env – env var with a GitHub token, for commit statuses and wait_for_ci
commit_status true false: use the token only for wait_for_ci
api_url https://api.github.com GitHub Enterprise Server API URL

[deploy.<name>]

One table per deploy. The name is used in the CLI, the log directory and DEPLOY_NAME.

Key Default
path required URL path the git host posts to, e.g. /hooks/shop
provider github github, gitea, forgejo, gitlab, bitbucket (details)
repository required repository the pushes must come from, as the provider names it; any other is ignored
branch main pushes to other branches are ignored
secret_env required env var holding this deploy's webhook secret; startup fails if it is empty
command required run directly, no shell
args – arguments; for an inline script use command = "/bin/bash", args = ["-c", "..."]
working_directory service's cwd
env – extra KEY=VALUE entries, e.g. PATH=...
timeout 30m then the whole process group gets SIGTERM, and SIGKILL 10 s later
lock true one run at a time; false allows parallel runs
queue true with lock, a push during a run waits for it; later pushes replace the queued one. false: answer 409
log_output true false keeps only the header and footer lines in the log
wait_for_ci – GitHub Actions workflow names that must pass first (details)
ci_timeout 30m

Example

[server]
listen = "127.0.0.1:9000"
api_token_env = "NIMDEPLOY_API_TOKEN"

[logging]
directory = "/var/log/nimdeploy"
retain = 30

[notify]
format = "slack"
url_env = "NOTIFY_WEBHOOK_URL"

[deploy.agency-frontend]
path = "/hooks/agency-frontend"
repository = "acme/agency-frontend"
branch = "main"
secret_env = "AGENCY_FRONTEND_WEBHOOK_SECRET"
working_directory = "/var/www/frontend/agency"
command = "/home/deploy/bin/deploy-agency-frontend.sh"

[deploy.agency-backend]
path = "/hooks/agency-backend"
repository = "acme/agency-backend"
branch = "main"
secret_env = "AGENCY_BACKEND_WEBHOOK_SECRET"
working_directory = "/var/www/backend/agency"
command = "/home/deploy/bin/deploy-agency-backend.sh"
timeout = "20m"
secrets.env (600)
NIMDEPLOY_API_TOKEN=3f9c...
AGENCY_FRONTEND_WEBHOOK_SECRET=8a21...
AGENCY_BACKEND_WEBHOOK_SECRET=d07e...
NOTIFY_WEBHOOK_URL=https://hooks.slack.com/services/...

Generate secrets with openssl rand -hex 32. The same values go into each repository's webhook settings.