# Websites deploy / provision agent (runs on websites VM: /opt/websites-agent) # # Endpoints (X-Deploy-Token): # POST /deploy { slug, wait?: true } — git pull + build + pm2 restart # wait=true (API default): sync, returns success/failed # wait=false: fire-and-forget 202 accepted # GET /deploy-status?slug=… — last deploy status JSON for slug # POST /provision { slug, host, gitRepoUrl } — clone + nginx + ecosystem + allowlist (no certbot) # POST /ssl { host, slug? } — certbot for apex + www (nginx must exist) # GET /health # # Env (.env): PORT, DEPLOY_TOKEN, ALLOWED_SLUGS # # Note: provision.sh intentionally skips certbot. SSL is issued via POST /ssl so # Edit/Add Domain does not hang when www DNS is wrong. # deploy.sh checks out origin/HEAD (falls back to main, then master).