-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathteploy.example.yml
More file actions
94 lines (87 loc) · 4.42 KB
/
Copy pathteploy.example.yml
File metadata and controls
94 lines (87 loc) · 4.42 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# Minimal self-hosted Ship — the stranger's teploy.yml.
#
# The repository's own teploy.yml is the MAINTAINER's production config
# (gateway, sandbox host, host-bind mounts, Observe). Starting from it by hand
# means discovering ~13 required edits the hard way — the fresh-machine pass of
# 2026-09-23 measured exactly that, with a worker that crash-loops on the first
# one (`sandbox URL set but no token`). Copy THIS file to teploy.yml and change
# the lines marked CHANGE; everything else is a working minimal shape.
#
# `teploy validate` checks it parses. The 2026-09-24 rerun deployed this file
# as written (plus the CHANGE lines) and got a verified pull request from it.
#
# `./install.sh --host <ip> --user root <name>` does all of this for you —
# this file is for the by-hand path (QUICKSTART steps 2-4).
#
# Secrets are never in this file. Set them with `teploy secret set`
# (QUICKSTART step 3): SHIP_WEB_TOKEN, SHIP_SESSION_SECRET,
# SHIP_WEBHOOK_SECRET, SHIP_GIT_TOKEN, and the model key (ANTHROPIC_API_KEY, or
# AI_GATEWAY_KEY for an Anthropic-compatible endpoint — see env below).
app: ship
# CHANGE: the box you registered in step 1 (a servers.yml name or a raw IP).
server: mybox
# CHANGE: your ssh user.
user: root
# One published web process, no domain, no Caddy — the private/tailnet shape.
# Firewall the port (QUICKSTART step 4).
ingress: host
port: 7460
# AMD64 only today — see docs/DEPLOY.md "Supported platforms and forges".
platform: linux/amd64
# teploy's processes are one command string each (not maps). The image's
# entrypoint is `node dist/cli.js`, so these are teploy-ship subcommands.
processes:
web: web --store nucleus --port 7460
worker: worker --store nucleus --interval 5
memory: 1g
# The store. Reachable only on the app's docker network (alias ship-nucleus);
# NUCLEUS_ALLOW_NO_AUTH is safe for that reason and no other — do not publish
# its port. Pinned: bump deliberately (teploy.yml explains why).
accessories:
nucleus:
image: ghcr.io/neutron-build/nucleus:v1.1.1
port: 5432
memory: 1500m
env:
NUCLEUS_ALLOW_NO_AUTH: "1"
NUCLEUS_MAX_MEMORY_MB: "1024"
volumes:
nucleus-data: /data
env:
NUCLEUS_URL: postgres://nucleus@ship-nucleus:5432/nucleus
# CHANGE: the forge origin (or owner prefix) your SHIP_GIT_TOKEN may be sent
# to. Without it every repository URL is refused, deliberately. Adding a
# repo on the dashboard's Projects page allows it too.
SHIP_REPO_ALLOWLIST: https://github.com/your-org
# Run the repo's suite after the agent stops and put the result on the PR.
# The command is detected from the repo (package.json test script, Makefile
# test:, go.mod, Cargo.toml, pytest config). Without a sandbox daemon the
# suite runs inside the worker container, which carries node, npm and
# git only — a Go or Python suite reports "not run" until you add the
# sandbox daemon and its images (docs/DEPLOY.md, sandbox).
SHIP_TESTS: "1"
# Model, with an Anthropic key (secret ANTHROPIC_API_KEY): nothing more.
SHIP_MODEL: anthropic/claude-sonnet-5
# Model, with an Anthropic-COMPATIBLE endpoint instead (z.ai's route,
# verified 2026-09-23/24): replace SHIP_MODEL above with these four and set
# the secret AI_GATEWAY_KEY=<the endpoint's key>. The model id is
# UNPREFIXED — the endpoint receives it verbatim — and the wire prefix
# tells Ship to speak Anthropic's wire to it. ANTHROPIC_BASE_URL is NOT
# read by Ship; setting it sends your key to api.anthropic.com.
# AI_GATEWAY_URL: https://api.z.ai/api/anthropic
# SHIP_MODEL: glm-5.3
# SHIP_ANTHROPIC_WIRE_PREFIXES: glm
# No SHIP_SANDBOX_* here: without a sandbox daemon the worker runs tasks you
# launch yourself in its own container and REFUSES tasks from webhooks,
# Slack or issues. docs/DEPLOY.md §sandbox is the next step up.
#
# Previews (optional, docs/DEPLOY.md SHIP_PREVIEW_*): a clone of the app
# being fixed at SHIP_PREVIEW_DIR, plus — for tailnet-only previews, the
# default shape for a tailnet dashboard — the deploy target's tailnet IP:
# SHIP_PREVIEW_DIR: /srv/app-clone
# SHIP_PREVIEW_TAILNET_IP: 100.x.y.z # previews at http://preview-*.100.x.y.z.sslip.io,
# # HTTP, reachable only from 100.64.0.0/10;
# # env here reaches web too, so the run page may frame them
# SHIP_PREVIEW_MAIN_URL: https://app.example.com # main, for the visual diff
volumes:
ship-data: /data