--- schema_version: 1 id: home-server.deployment type: reference scope: [jupiter, portainer, github, stack-deployment, secrets] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "Portainer GitHub/main/PAT configuration, environment management and manual pull/redeploy workflow, 2026-10-06" - kind: owner-report reference: "No independent credential recovery; operational rules not established, 2026-10-06" related: [home-server.reference, home-server.host, home-server.portainer, home-server.authentication, home-server.backups, home-server.operations] update_triggers: [deployment-workflow-change, repository-change, credential-rotation, rollback-policy-change] unknowns: - github-pat-scopes-and-expiration - post-deployment-health-criteria --- # Deployment | Setting | Source / workflow | | --- | --- | | Stack definitions | | | Git ref | `main` | | Repository authentication | GitHub PAT configured in Portainer | | Environment values/secrets | Portainer stack environment settings | | Deployment | Manually pull/redeploy each affected stack in Portainer | | Portainer itself | [Host shell script](portainer.md), not a managed Compose stack | ```text Compose change -> push main -> manual Portainer pull/redeploy -> running stack ``` A Git commit is not deployment proof. Installed host Compose version is not proof of Portainer's Compose implementation. Recovering deployment requires Portainer state or independently retrievable repository credentials and stack environment values. [Portainer backups](backups.md) exist; credential/state restoration is untested. Do not put secret values in this site or Git. No independent recovery arrangement exists for the PAT or stack secrets. Rollback, health-check gates, approval rules and UI-versus-Git drift policy are not established; do not assume permission to deploy, stop or delete services. Host apt packages, fstab, RAID assembly, systemd units and Mercury nginx are outside the Compose deployment workflow.