Keeping your applications up to date while maintaining high availability is important for modern web applications.

RunCloud Docker Stacks includes built-in automation tools that manage deployment manifests, enforce automated update rollbacks using the 60-second safety window, and enable continuous deployment using push-to-deploy webhooks.

Deployment History and Manifest Inspection

Every time you deploy a stack, edit an environment variable, or trigger an update, RunCloud generates a fully managed orchestration manifest and tracks the operation in your deployment history.

To review the history of your deployments:

  1. Navigate to Stacks in your RunCloud control panel and select your stack.
  2. In the left menu, click on Deployments.
  3. The deployments table displays:

    • Deployment ID: The unique tracking hash for the deployment event.

    • Type: The trigger mechanism (such as Manual deployment or Webhook trigger).

    • Status: Current operational result (such as Running or Failed).

    • Duration: The elapsed time required to execute the deployment sequence.

Deployment inspection

On this screen, click on “View Details” next to the deployment that you want to inspect. This will open the Deployment Details view, where you can inspect the full Docker Compose / Swarm configuration manifest generated by RunCloud.

Docker snapshot

Automated Rollbacks with the 60-Second Safety Window

Updating a container image introduces the risk that an upstream code change could cause a crash at startup. To eliminate downtime caused by faulty images, RunCloud configures a strict 60-Second Observation Window directly in the container orchestration manifest:

  1. When a new image is pulled and deployed, RunCloud initiates a 60-second health monitoring countdown.
  2. During this 60-second window, RunCloud monitors process exit codes, health check probes, and system readiness.
  3. If the newly pulled image crashes or fails its readiness health checks before the 60-second window elapses, Docker Swarm triggers an automatic rollback:

    • The failing container is terminated.

    • The previous working container image and configuration are restored immediately.

    • The stack returns to a stable, running state without administrative intervention.

Creating Push-to-Deploy Webhooks

If you maintain a continuous integration and continuous deployment (CI/CD) pipeline on GitHub, GitLab, or Docker Hub, you can configure RunCloud to redeploy your stack automatically whenever your automated build tests pass and a new image is pushed.

How Webhooks Work

A webhook provides a secure URL endpoint unique to your stack. When your registry provider or build pipeline sends an HTTP POST request to this endpoint, RunCloud verifies the payload and initiates a fresh deployment.

RunCloud supports two vital security and control mechanisms for webhooks:

  • Tag Filtering: Restricts deployments to specific image tags (for example, triggering only when an image is tagged latest or matches a wildcard pattern like v*), preventing experimental branch builds from deploying to production.
  • Cryptographic Signatures: Allows you to require an HMAC-SHA256 signature (X-Hub-Signature-256), ensuring that RunCloud only accepts deployment commands originating from your authenticated build server.

Step-by-Step Instructions: Setting Up a Webhook

Follow these steps to configure a push-to-deploy webhook for your stack:

  1. Navigate to Stacks and select your stack.
  2. Click on Webhooks in the left-hand navigation menu.
  3. Click Create Webhook to open the setup modal.
Create webhook
  1. Select your container registry or CI provider from the “Registry Provider” dropdown list (such as “GitHub Container Registry”, “Docker Hub”, or “GitLab”).
  2. In the “Name” field, enter an optional recognizable label (for example, Production GitHub Action).
  3. In the “Tag Filter” field, type the tag or wildcard pattern you want to monitor (for example, latest or v*). Webhook notifications referencing non-matching tags will be ignored.
  4. Select the “Require signature” checkbox to enforce strict payload verification.
Create webhook
  1. When signature verification is enabled, RunCloud will generate a secret passphrase. You will need to configure this secret in your CI/CD pipeline or in your registry webhook settings.
  2. After reviewing the settings, click Create Webhook to generate your unique endpoint.
  3. RunCloud will display the unique webhook URL. Click the copy icon next to the URL to copy it to your clipboard.
Creation secrets for RunCloud

Connecting the Webhook to Your CI/CD Pipeline

Once you have copied the webhook URL from RunCloud:

  1. Log in to your repository or container registry management console (such as GitHub, Docker Hub, or GitLab).
  2. Navigate to your repository settings and locate the “Webhooks” configuration panel.
  3. Paste your RunCloud webhook URL into the “Payload URL” field.
  4. Set the content type to application/json.
  5. If you enabled signature verification in RunCloud, enter your secret passphrase into the “Secret” field.
  6. Select the trigger event (such as “Package published” on GitHub or “Push” on Docker Hub).
  7. Save your webhook settings in the external provider.
Create webooks

Whenever your build pipeline pushes a new container image that matches your tag filter, RunCloud will receive the signal, verify the secret signature, pull the new image, and redeploy your stack with zero manual intervention.

If you have any other questions or need help, please feel free to get in touch with our 24/7 support team. We’re here to help!