One-Click Install
A project usually comes from a Git repository. It does not have to. Pick an application from the catalog and Depfloy downloads it, creates its database, configures it and publishes it — there is nothing to connect and nothing to build.
Starting an install #
In the Console, open Create Project and click One-click install instead in the top-right. You can also go straight to /projects/install.
You need at least one app server. You do not need a source control provider connected — a one-click install never touches one.
Choosing an application #
The catalog is the first thing on the page. Two applications are available today:
- WordPress — the publishing platform. Optionally with WooCommerce installed and activated during setup.
- phpMyAdmin — a browser interface to the MySQL or MariaDB server on that machine. It creates no database of its own.
Each card says how many of your servers can host it. What an application needs has to already be on the server: WordPress runs on MySQL or MariaDB and will not install against PostgreSQL. If none of your servers qualifies, the card says what is missing rather than leaving you to guess.
Pick the application first, then the server. The server list shows all of your app servers, and the ones that cannot host your choice are greyed out with the reason next to them — so a machine that is nearly right is visible rather than missing.
What you fill in #
Every install asks for a project name. The domain is optional: leave it empty to use the reserved depfloy.app preview URL, or enter a production domain that already points at the server. The rest depends on the application.
If you enter a production domain, point it at the server before installation. WordPress records the selected primary address during setup, and a production-domain certificate can only be issued once DNS resolves to the machine. The platform preview URL remains available separately.
WordPress #
- Site title — shown in the browser tab and the admin bar. Changeable later from Settings.
- Administrator username — avoid
admin; it is the username every credential-stuffing bot tries first. - Administrator email — where WordPress sends password resets and update notices.
- Administrator password — leave it empty and one is generated for you.
- Language — the language WordPress is installed in. More can be added later from Settings.
- Preset — WordPress only, or WordPress with WooCommerce installed and activated during setup. Nothing else differs.
- Block xmlrpc.php — on by default. It closes a legacy endpoint mostly used for brute-force attacks. Turn it off if you use the WordPress mobile apps or Jetpack.
phpMyAdmin #
phpMyAdmin puts a login form in front of every database on the server, so it will not install without a way to keep it off the open internet. Choose one:
- Only the IP addresses I list — one per line, IPv4, IPv6 and CIDR ranges accepted.
- Anyone with an extra username and password — the browser asks for these before phpMyAdmin loads. This is not a database user.
Both are written into the project’s nginx configuration and can be edited later on the Nginx Configuration tab.
Watching it install #
The install runs on the server and you can leave the page — it keeps going. The project shows every step before it starts and moves through them as they happen: preparing the directory, creating the database, downloading the application, writing its configuration, running its installer, setting permissions, publishing the site, scheduling its background work, and requesting a certificate.
Each step reports what it produced — the version that was installed, the database that was created — and how long it took.
If a step fails it says why and stops there; the steps after it stay untouched. Nothing is removed. Fix what the failing step reports and click Run it again: every step is safe to repeat, and a retry reuses the same database rather than creating a second one.
The certificate step is allowed to be skipped. If DNS does not point at the server yet, the install finishes and the site serves over http; turn SSL on later from the Domains tab. When a certificate is issued during the install, Depfloy moves the site’s address to https for you.
What a WordPress install gives you #
- Its own MySQL database and user, with rights to that database and nothing else on the server.
- WP-CLI, installed on the server and left there. Use it over SSH or through project commands.
- A real scheduled task running WordPress’s due jobs every five minutes, in place of WP-Cron. WordPress otherwise fires scheduled work from visitor requests, which means a quiet site never runs it and a busy one runs it on someone’s page load. You can see and edit it on the Schedulers tab.
- nginx rules that refuse
wp-config.php, refuse the installer scripts, and refuse to run PHP fromwp-content/uploads— an uploaded file is served as a file, never as code.
After it is installed #
A catalog application has no repository, so it has no deployments. A successful installation completes the setup guide’s final stage. The project’s summary shows the application, the installed version, and a link to its admin area.
Update replaces the Deploy action. For WordPress it updates core, applies any database changes that come with it, then updates plugins and themes. phpMyAdmin has no in-place update; installing a newer version is a new install.
Asking for a deployment on a catalog project is refused rather than half-run.
The credentials the installer set — the administrator login and the database password — are readable from the project. Reading them needs the project:update permission, and the administrator password shown is the one set at installation; if you have changed it in WordPress since, WordPress is right and this is not.
Removing it #
Deleting the project removes the application and drops the database that was created for it. A database you made yourself on the server’s Database section is separate and is not touched.
Doing it from the API #
# What can be installed on a given server, and what cannot, with reasons
curl -H "Authorization: Bearer $TOKEN" \
https://app.depfloy.com/api/v1/servers/12/apps
# Install
curl -X POST -H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Company Blog",
"domain": "blog.example.com",
"server_id": 12,
"app_slug": "wordpress",
"inputs": {
"site_title": "Company Blog",
"admin_user": "editor",
"admin_email": "[email protected]"
}
}' \
https://app.depfloy.com/api/v1/projects/installFollow it with GET /api/v1/projects/{id}/install-steps until installation_status is 1. POST /api/v1/projects/{id}/install/retry restarts a failed install, GET /api/v1/projects/{id}/app returns the application’s details and credentials, and POST /api/v1/projects/{id}/app/update runs the update.
Installing needs project:create. Reading an application’s details or updating it needs project:update.
Limits worth knowing #
- WordPress needs MySQL or MariaDB. A PostgreSQL server is refused before anything is written.
- There is no rollback. A catalog application updates itself in place, so the way back to a previous state is a backup taken beforehand.
- PHP applications on one server share a PHP-FPM pool. Two WordPress sites on the same machine run as the same system user and can read each other’s files. Put sites belonging to different customers on different servers.