This workflow automates deployments using Deployer, executing the deployment recipe defined in
the consuming repository's deployment/ directory.
To achieve that, the reusable workflow:
- Checks out the repository
- Sets up PHP and installs Composer dependencies (production only)
- Optionally establishes a VPN tunnel to reach private networks
- Detects and builds npm workspaces if present
- Installs Deployer from the
deployment/directory - Configures SSH access to the target host
- Runs the Deployer
deploycommand for the specified environment
The consuming repository is expected to have a deployment/ directory with its own composer.json that includes
Deployer as a dependency. The deploy.php recipe inside that directory should read connection parameters from
environment variables to avoid storing sensitive data in the repository.
The following is a basic configuration for the host in the deploy.php file:
$hostname = getenv('DEPLOY_HOSTNAME');
$port = getenv('DEPLOY_PORT');
$user = getenv('DEPLOY_USER');
host('staging')
->setHostname($hostname)
->setRemoteUser($user)
->setPort((int) $port)
->setDeployPath('~/deployments')
->setSshArguments([
'-o UserKnownHostsFile=/dev/null'
'-o StrictHostKeyChecking=no',
]);name: Deploy
on:
workflow_dispatch:
inputs:
ENVIRONMENT:
description: 'Target environment'
required: true
type: choice
options:
- staging
- production
jobs:
deploy:
uses: inpsyde/reusable-workflows/.github/workflows/deploy-deployer.yml@main
secrets:
DEPLOY_HOSTNAME: ${{ secrets.DEPLOY_HOSTNAME }}
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
GITHUB_USER_SSH_KEY: ${{ secrets.DEPLOYBOT_SSH_PRIVATE_KEY }}
COMPOSER_AUTH_JSON: ${{ secrets.PACKAGIST_AUTH_JSON }}
with:
ENVIRONMENT: ${{ inputs.ENVIRONMENT }}| Name | Default | Description |
|---|---|---|
ENVIRONMENT |
Name of the target environment to load Deployer settings | |
VERBOSITY |
'v' |
Deployer command verbosity |
PHP_VERSION |
'8.2' |
PHP version with which the scripts are executed |
PHP_EXTENSIONS |
'' |
PHP extensions supported by shivammathur/setup-php to be installed or disabled |
PHP_TOOLS |
'' |
PHP tools supported by shivammathur/setup-php to be installed |
NODE_VERSION |
'22' |
Node.js version to use when npm workspaces are detected |
NPM_REGISTRY_DOMAIN |
'https://npm.pkg.github.com/' |
Domain of the private npm registry |
OVPN_GATEWAY_IP |
'' |
The IP address of the OpenVPN gateway |
| Name | Required | Description |
|---|---|---|
DEPLOY_HOSTNAME |
Yes | Hostname or IP address of the target server |
DEPLOY_PORT |
Yes | SSH port on the target server |
DEPLOY_USER |
Yes | SSH user on the target server |
GITHUB_USER_SSH_KEY |
Yes | Private SSH key used for repository checkout and remote server access |
COMPOSER_AUTH_JSON |
Yes | Authentication for privately hosted packages and repositories as a JSON formatted object |
WIREGUARD_CONFIGURATION |
No | The full content of the WireGuard configuration file for VPN tunnel setup. Deprecated: the support for WireGuard will be removed in the future in favour of OpenVPN |
NPM_REGISTRY_TOKEN |
No | Authentication for the private npm registry |
OVPN_CONFIG |
No | The full content of the OpenVPN configuration file |
OVPN_USERNAME |
No | The username to authenticate with the OpenVPN server |
OVPN_PASSWORD |
No | The password to authenticate with the OpenVPN server |
Example with configuration parameters:
name: Deploy
on:
workflow_dispatch:
inputs:
ENVIRONMENT:
description: 'Target environment'
required: true
type: choice
options:
- staging
- production
jobs:
deploy:
uses: inpsyde/reusable-workflows/.github/workflows/deploy-deployer.yml@main
secrets:
DEPLOY_HOSTNAME: ${{ secrets.DEPLOY_HOSTNAME }}
DEPLOY_PORT: ${{ secrets.DEPLOY_PORT }}
DEPLOY_USER: ${{ secrets.DEPLOY_USER }}
GITHUB_USER_SSH_KEY: ${{ secrets.DEPLOYBOT_SSH_PRIVATE_KEY }}
COMPOSER_AUTH_JSON: ${{ secrets.PACKAGIST_AUTH_JSON }}
OVPN_CONFIG: ${{ secrets.OVPN_CONFIG }}
OVPN_USERNAME: ${{ secrets.OVPN_USERNAME }}
OVPN_PASSWORD: ${{ secrets.OVPN_PASSWORD }}
NPM_REGISTRY_TOKEN: ${{ secrets.NPM_REGISTRY_TOKEN }}
with:
ENVIRONMENT: ${{ inputs.ENVIRONMENT }}
PHP_VERSION: '8.3'
NODE_VERSION: '22'
VERBOSITY: 'vvv'
OVPN_GATEWAY_IP: ${{ vars.OVPN_GATEWAY_IP }}