Self-Hosting Activepieces: How to Automate Source Code Sync from Private Repositories to Production VPS on Every Commit
Introduction: The Case for Self-Hosted Deployment Automation
In the modern software development lifecycle, continuous integration and continuous deployment (CI/CD) have transitioned from luxury workflows to absolute necessities. However, for small-to-medium enterprises (SMEs), indie developers, and privacy-conscious organizations, relying on third-party cloud SaaS platforms for code deployment can introduce significant bottlenecks. Monthly subscription costs scale rapidly, build-minute limitations disrupt momentum, and hosting proprietary source code on external infrastructure raises valid security and compliance questions.
This is where Activepieces enters the frame as a disruptive force. Activepieces is an open-source, ultra-intuitive workflow automation platform designed to be a self-hosted alternative to Zapier or Make. By hosting Activepieces on your own Virtual Private Server (VPS), you retain 100% control over your data, enjoy unlimited executions, and can orchestrate complex workflows without premium tier restrictions. In this comprehensive guide, we will explore how to self-host Activepieces and configure an automated pipeline that instantly synchronizes your private source code repositories to a production VPS the moment a new commit is pushed.
---Why Choose Activepieces Over Traditional CI/CD Tools?
While legacy tools like Jenkins, GitHub Actions, or GitLab CI/CD are powerful, they often come with steep learning curves, heavy resource consumption, or vendor lock-in. Activepieces bridges the gap by offering several distinct advantages for VPS management:
- Resource Efficiency: Unlike heavy enterprise CI/CD runners, a self-hosted Activepieces instance operates efficiently on lightweight VPS configurations, leaving precious system resources for your actual production applications.
- Visual Workflow Builder: The intuitive drag-and-drop interface allows you to visualize the entire deployment pipeline, making troubleshooting and modifications straightforward for both developers and system administrators.
- Extensible Ecosystem: Activepieces supports a vast library of pre-built pieces (integrations) for Git platforms (GitHub, GitLab, Gitea) and system utilities (SSH, Webhooks), allowing you to expand your deployment pipeline with notifications (Slack, Discord) or database backups effortlessly.
Prerequisites and System Architecture
Before diving into the implementation phase, ensure you have the following components ready:
- A VPS running Ubuntu 22.04 LTS (or any modern Linux distribution) with a public IP address.
- Docker and Docker Compose installed on the server.
- A private repository hosted on a Git provider (e.g., GitHub, GitLab, or a self-hosted Gitea instance).
- SSH access to your production environment with proper user permissions.
Security Note: Always adhere to the principle of least privilege. For deployment tasks, create a dedicated SSH user on your production VPS with access restricted exclusively to the target application directory. Avoid using the root account for automated syncs.---
Step 1: Deploying Activepieces on Your VPS via Docker Compose
To begin, we will deploy Activepieces in a self-hosted environment using Docker Compose. This ensures an isolated, reproducible, and easily maintainable setup.
Connect to your VPS via SSH and create a dedicated directory for your automation stack:
mkdir -p ~/activepieces && cd ~/activepiecesCreate a docker-compose.yml file using your preferred text editor and insert the following configuration:
version: '3.8'
services:
postgres:
image: 'postgres:15-alpine'
environment:
POSTGRES_DB: activepieces
POSTGRES_USER: ap_user
POSTGRES_PASSWORD: your_secure_password_here
volumes:
- postgres_data:/var/lib/postgresql/data
restart: always
redis:
image: 'redis:7-alpine'
restart: always
activepieces:
image: 'activepieces/activepieces:latest'
environment:
AP_DATABASE_TYPE: POSTGRES
AP_POSTGRES_DATABASE: activepieces
AP_POSTGRES_USER: ap_user
AP_POSTGRES_PASSWORD: your_secure_password_here
AP_POSTGRES_HOST: postgres
AP_POSTGRES_PORT: 5432
AP_REDIS_URL: redis://redis:6379
AP_FRONTEND_URL: "http://your-vps-ip:8080"
AP_ENCRYPTION_KEY: "generate_a_random_32_char_string"
AP_JWT_SECRET: "generate_another_random_string"
ports:
- '8080:80'
depends_on:
- postgres
- redis
restart: always
volumes:
postgres_data:Replace the placeholder passwords and set the AP_FRONTEND_URL to your server's public IP or domain name. Launch the stack by executing:
docker compose up -dOnce initialized, navigate to http://your-vps-ip:8080 in your web browser to create your administrator account and access the dashboard.
Step 2: Configuring the Git Webhook Trigger
Now that Activepieces is operational, we need to establish a mechanism that listens for changes in your private repository. We achieve this by utilizing a Webhook trigger.
1. Setting up the Trigger in Activepieces
In your Activepieces dashboard, click on "New Flow". Rename the flow to something descriptive, such as "Production Code Sync Pipeline". For the trigger, select the Webhook piece. Activepieces will generate a unique, secure Webhook URL. Copy this URL to your clipboard.
2. Linking the Webhook to Your Private Repository
Navigate to your private repository settings on GitHub or GitLab. Go to the Webhooks section and click Add Webhook. Paste the Activepieces Webhook URL into the payload URL field. Set the content type to application/json, select the Just the push event option, and save the configuration. Your Git provider will now send a real-time HTTP POST payload to Activepieces whenever a developer executes a git push.
Step 3: Creating the Production Sync and Deployment Action
With Activepieces successfully capturing repository push events, the final phase involves executing the actual synchronization and code updates on your production VPS. While there are multiple methods to transfer files, leveraging an SSH connection to execute a Git pull or a secure rsync script is the most secure and atomic approach for production stability.
1. Add the SSH Piece to Your Flow
In the Activepieces visual builder, click the "+" icon directly below your Webhook trigger to append a new action. Search for and select the SSH piece. Choose the Execute Command action.
2. Configure Authentication and Credentials
To establish a secure handshake between Activepieces and your target environment, configure the SSH connection parameters:
- Host: The public IP address of your production VPS.
- Port: Your SSH port (default is 22, though changing this is recommended for production hardening).
- Username: The dedicated deployment user account on the server.
- Private Key: Paste the SSH private key corresponding to the public key added to your deployment user's
authorized_keysfile.
3. Constructing the Automated Deployment Script
In the Command field of the SSH action, write the shell commands required to fetch the latest code changes and restart your application environment. Here is a highly robust structure tailored for modern web applications:
cd /var/www/my-production-app && \
git fetch origin main && \
git reset --hard origin/main && \
npm install --production && \
pm run build && \
pm2 restart allNote: Adjust the commands based on your stack (e.g., substituting npm commands with Docker container restarts or PHP/Laravel artisan commands if applicable). Using git reset --hard ensures that any accidental local modifications on the production server are cleanly overwritten by the incoming source-of-truth commit.
Step 4: Testing, Monitoring, and Optimizing Your Workflow
Before activating the pipeline for daily operations, click the Test Flow button within Activepieces. Push a trivial change (such as an updated README file) to your private repository's main branch. Monitor the Activepieces execution logs in real time to ensure that the Webhook fires correctly, the payload passes successfully, and the SSH command executes with a 0 exit status code.
To guarantee long-term reliability and secure operations, implement these production optimizations:
- Branch Filtering: Modify your Activepieces flow to include a Branch Filter (Router) step. Ensure that code synchronizations are exclusively triggered when changes land on your
mainorproductionbranch, avoiding unwanted deployments from feature branches. - Reverse Proxy Hardening: Avoid exposing port
8080directly to the public web. Utilize a reverse proxy like Nginx or Caddy paired with Let's Encrypt to wrap your Activepieces dashboard and webhook endpoints in strict SSL/TLS encryption. - Automated Cleanups: Set up a cron job or an automated Activepieces scheduled maintenance flow to periodically clean up older deployment logs and Docker cache layers to prevent disk space exhaustion over time.
Conclusion
By shifting away from proprietary SaaS automation tools and choosing a self-hosted Activepieces architecture, you regain complete ownership over your automated CI/CD pipeline. Your source code remains confidential, execution limitations disappear, and your deployment workflow becomes deterministic, secure, and instantaneous. As your deployment needs evolve, you can seamlessly expand this pipeline to trigger database migrations, execute automated unit tests, or send immediate deployment status reports directly to your team's communication channels.
