Deploy a Private Repository
Deploy code from a private GitHub, GitLab or Bitbucket repository with a read-only key, and redeploy on every push.
A Custom app can build from a private repository on GitHub, GitLab or Bitbucket. FlyNode never asks for your account password or an access token. Instead it makes a read-only SSH key for this one app. You add the public half of the key to your repository, and the key can read that repository and nothing else.
Deploy
- Go to Deploy, choose Custom app, and pick Private repository.
- Enter the repository address, for example
git@github.com:you/repo.git. An https address works too; FlyNode converts it. - Press Create key. FlyNode shows the public key and its fingerprint.
- Add the key to your repository as a read-only key (steps below). Do not allow write access.
- Press Test connection. FlyNode tries to read the repository with the key and shows Connected with the branch it found. You cannot continue until this passes.
- Continue as for any custom app: branch, build commands, domain, plan, deploy.
Where to add the key
- GitHub: repository Settings, then Deploy keys, then Add deploy key. Leave Allow write access off.
- GitLab: Settings, then Repository, then Deploy keys, then Add new key. Leave Grant write permissions off.
- Bitbucket: Repository settings, then Access keys, then Add key.
The key page in the wizard has a link straight to the right settings page for your repository.
Deploy on every push
Open the app and look at Auto deploy on push. It shows an address and a secret to add as a webhook on your host, with the right steps for GitHub, GitLab or Bitbucket. After that, every push to your app's branch rebuilds and deploys it. The card also shows when the last push arrived and what FlyNode did with it.
Good to know
- One key per app. Each app gets its own key, so removing one app never affects another. A key that is not used within 24 hours is deleted.
- Deleting the app deletes its key. You can also remove the key from the repository settings yourself at any time; new builds will then fail until you add a new one.
- Only GitHub, GitLab and Bitbucket (the cloud versions) are supported. Self-hosted Git servers are not.
- The private half of the key is stored only by the build system and is never shown again, not even to you.
Public repositories keep working exactly as before. See Deploy a GitHub Repository.
Still stuck?
Open a support ticket from your dashboard and include the container name.