Open CLI Deployment (OCD) builds immutable OCI images from Git and reconciles
them onto Hetzner Cloud servers. You operate it through the ocd CLI while a small,
self-hosted panel keeps desired state, credentials, deployment history, and
recovery operations in one place.
git push / ocd deploy
│
▼
┌─────────────────┐ build ┌──────────────┐ pull by digest ┌──────────────────┐
│ OCD panel │ ─────────▶ │ OCI registry │ ─────────────────▶ │ Hetzner servers │
│ desired state, │ BuildKit └──────────────┘ │ Docker + Traefik │
│ secrets, history│ ──────────── reconcile over SSH ─────────────▶ │ private network │
└─────────────────┘ └──────────────────┘
The panel stores what should run; its engine builds images, provisions infrastructure, and reconciles containers onto the servers you place them on.
- Your Hetzner account: OCD provisions and manages servers, the private network, firewall, volumes, and object storage in your Hetzner Cloud project.
- Immutable releases: deployments and re-releases use digest-qualified images.
- Git-based configuration: keep single-app or multi-app manifests beside the code they deploy.
- Operational controls: inspect logs, open a shell, copy files, pause, move, and recover failed operations from the CLI. The panel is for reading and configuration; operations run through the CLI.
- Portable integrations: use HTTPS Git hosts and OCI registries rather than a closed hosting ecosystem.
To run a panel you need a Hetzner Cloud account and API token. OCD runs on Hetzner Cloud only. Hetzner Object Storage (access key and secret key) is needed for buckets, app storage bindings, and panel backups.
The CLI supports macOS and Linux on x64 and arm64. App builds require an OCD BuildKit worker or a prebuilt image in an OCI registry.
Install the latest CLI release and start the guided bootstrap:
curl -fsSL https://github.com/0-AI-UG/open-cli-deployment/releases/latest/download/install.sh | sh
ocd bootstrapThe wizard provisions a managed Hetzner server for the panel. It verifies
access, deploys the panel, and guides you through browser setup. Omit --domain to use a generated nip.io address:
HETZNER_API_TOKEN=... ocd bootstrap \
--domain=panel.example.comOnce the panel is ready, log in and check that all deployment prerequisites are configured:
ocd login https://panel.example.com
ocd registry login registry.example.com/team --username=registry-user
ocd source login git.example.com --username=git-user # private Git only
ocd doctorApplications are described by a .ocd-deploy.json manifest. A minimal app
built from Git looks like this:
{
"$schema": 1,
"name": "Example API",
"build": {
"repository": "https://github.com/example/example-api.git",
"branch": "main",
"dockerfile": "Dockerfile",
"image_repository": "ghcr.io/example/example-api"
},
"container_port": 3000,
"health_check": { "path": "/healthz" },
"environment": "production",
"env": {
"NODE_ENV": "production",
"DATABASE_URL": { "from": "environment.DATABASE_URL" }
}
}Validate and deploy it:
ocd manifest validate .ocd-deploy.json
ocd deploy .ocd-deploy.json
ocd logs example-api --tail=200Use ocd envs set or ocd envs generate to create referenced values before
deploying. Stack manifests can connect multiple apps and infer startup order
from references such as apps.database.outputs.URL.
Start with the documentation index for concepts, manifests, infrastructure, networking, storage, releases, and recovery. The CLI also ships the complete deployment guide as an installable skill for supported coding agents:
ocd skill list
ocd skill install --agent <agent>OCD is built with Bun, TypeScript, React, and Docker.
git clone https://github.com/0-AI-UG/open-cli-deployment.git
cd open-cli-deployment
bun install --frozen-lockfile
bun run typecheck
bun run test
bun run buildSee CONTRIBUTING.md for the development workflow and pull request checklist. Please report security issues according to SECURITY.md, not in a public issue.
OCD is used in production by its maintainers, but it is pre-1.0: manifests and CLI flags can still change between minor releases. Check the release notes before upgrading.
Open CLI Deployment is available under the MIT License.
