Websites deploy / provision agent (runs on websites VM: /opt/websites-agent)
Endpoints (X-Deploy-Token):
POST /deploy { slug, wait?: true } — git pull + build + pm2 restart
wait=true (API default): sync, returns success/failed
wait=false: fire-and-forget 202 accepted
GET /deploy-status?slug=… — last deploy status JSON for slug
POST /provision { slug, host, gitRepoUrl } — clone + nginx + ecosystem + allowlist (no certbot)
POST /ssl { host, slug? } — certbot for apex + www (nginx must exist)
GET /health
Env (.env): PORT, DEPLOY_TOKEN, ALLOWED_SLUGS
Note: provision.sh intentionally skips certbot. SSL is issued via POST /ssl so
Edit/Add Domain does not hang when www DNS is wrong.
deploy.sh checks out origin/HEAD (falls back to main, then master).