Trigger (deploy tokens)
Sometimes you want a CI pipeline to redeploy a project the moment it
finishes building a new image — without giving it a full kimbap login or
an API key that inherits a user's role. A deploy token is scoped to
exactly one project and can do exactly one thing: redeploy that project,
optionally patching a handful of its .env values first.
Creating a token
Admin UI → Integrations → Trigger → New token → pick the project it
should belong to. The raw token (kbpdeploy_...) is shown once — copy it
into your CI's secret store now, since kimbap never displays it again.
Triggering a deploy
curl -X POST 'https://<your-domain>/api/deploy/<slug>' \
-H 'Authorization: Bearer kbpdeploy_...'
That alone is equivalent to clicking Deploy on the project's Overview
page: it pulls fresh images for any mutable tags and runs
docker compose up -d --remove-orphans, then records an audit log entry.
Updating .env first
Pass an env object in a JSON body to patch specific values immediately
before deploying — the common case being a CI job that just minted a new
image tag:
curl -X POST 'https://<your-domain>/api/deploy/<slug>' \
-H 'Authorization: Bearer kbpdeploy_...' \
-H 'Content-Type: application/json' \
-d '{"env": {"IMAGE_TAG": "abc1234", "OTHER_VAR": "value"}}'
env is a merge, not a replace: each key you send has its line updated
in place if it already exists in .env, or gets appended if it doesn't —
every other line (including keys you didn't mention, and anything a human
set via the Environment page) is left exactly as it was. Omit the body (or
send {}) to redeploy with .env untouched entirely.
Only .env is settable this way — a deploy token can't rewrite
docker-compose.yml. Changing the compose file itself still requires a
session or a role-inheriting API key.
What a deploy token can't do
- Read or write anything about any other project.
- Stop, restart, or delete the project it belongs to.
- Touch domains, registries, users, or any host-level action.
It really is just "redeploy this one project," which is the point — handing a CI pipeline a full admin API key to do that would be handing it far more power than the job needs.
Revoking a token
Admin UI → Integrations → Trigger → the trash icon next to the token in the list (every project's tokens show there together). Takes effect immediately; nothing else about the project is affected.