--- schema_version: 1 id: home-server.deployment type: reference scope: [jupiter, portainer, github, stack-deployment, secrets] sensitivity: private-infrastructure last_reviewed: "2026-10-06" sources: - kind: owner-report reference: "Portainer GitHub/main/PAT configuration, environment management and manual pull/redeploy workflow, 2026-10-06" related: [home-server.reference, home-server.host, home-server.portainer, home-server.authentication, home-server.backups] update_triggers: [deployment-workflow-change, repository-change, credential-rotation, rollback-policy-change] unknowns: - github-pat-scopes-expiration-and-independent-recovery - rollback-and-post-deployment-health-procedure - rules-for-portainer-ui-versus-repository-drift --- # Deployment | Setting | Source / workflow | | --- | --- | | Stack definitions | | | Git ref | `main` | | Repository authentication | GitHub PAT configured in Portainer | | Environment values/secrets | Portainer stack environment settings | | Deployment | Manually pull/redeploy each affected stack in Portainer | | Portainer itself | [Host shell script](portainer.md), not a managed Compose stack | ```text Compose change -> push main -> manual Portainer pull/redeploy -> running stack ``` A Git commit is not deployment proof. Installed host Compose version is not proof of Portainer's Compose implementation. Recovering deployment requires Portainer state or independently retrievable repository credentials and stack environment values. [Portainer backups](backups.md) exist; credential/state restoration is untested. Do not put secret values in this site or Git. Host apt packages, fstab, RAID assembly, systemd units and Mercury nginx are outside the Compose deployment workflow.