Cookies ahead

Our support chat tool "Intercom" would like to collect some more data on you. See the related link for more details.

Docs

Deployment permission

Published

Reviewedbyfl

🔐

Decide who deploys.

Deployments start in three ways, with git push, with the Deploy now button in the dashboard, or with a deploy hook. Each one checks access differently. This matters most when several people share a GitHub repo.

About deployment permission

Access to a repo on GitHub and access to the app on fortrabbit are separate. A person can push to the repo without any fortrabbit account. The deployment permission setting decides whether that push deploys.

Git push

With push to deploy enabled, every push to the connected branch is checked against the deployment permission of the environment:

SettingWho can deploy with git push
Everyone with access to the repoAnyone who can push to the branch on GitHub. No fortrabbit account required. This is the default.
Connected developers onlyPeople whose GitHub account is connected to a fortrabbit developer account that has a developer connection to the app.

The check uses the GitHub account that sent the push, not the commit author. A push that fails the check is skipped without notice: no deployment shows up in the dashboard and no comment goes to GitHub. With the deployment trigger set to manual, pushes never deploy, whatever this setting says.

A public repo does not open deployment to everyone. Pushing still requires write access on GitHub.

Deploy now

The Deploy now button in the dashboard deploys the latest commit of the connected branch. It ignores the deployment permission setting. Two things are required:

  • Access to the app on fortrabbit, directly or through a team.
  • A GitHub account connected to the fortrabbit account, with the fortrabbit GitHub App installed for the owner of the repo, the personal account or the organization.

fortrabbit reads the latest commit with that person's own GitHub connection. A developer invited to the app without access to the repo on GitHub can't deploy.

Deploy hook

A deploy hook URL deploys for anyone who holds it. It ignores both the deployment permission and the deployment trigger setting. The deployment is not tied to a person.

For a group of developers, mirror the GitHub organization on fortrabbit:

  1. Create a team on fortrabbit for the people who work on the apps.
  2. Install the fortrabbit GitHub App on the GitHub organization that owns the repos.
  3. Have every developer connect their own GitHub account to fortrabbit.
  4. Set the deployment permission to connected developers only, at least for production environments.

Keep the default for an environment where every push should go live, for example staging fed by automation.

A personal repo is the simpler case. When nobody else has write access, both settings behave the same.

Written by a human. Review, grammar checks and typo fixes by AI.

AI use & editorial processEdit on GitHub ↗