deployphp/deployer
60.2
Adequate · 26 September 2026
15.8k
lines of production code
PHP
primary language
4
measurements over time
What this system is
This system is a modernized PHP-based deployment automation tool that manages server provisioning, code distribution, and application configuration. It orchestrates parallel task execution across remote hosts using a master-worker architecture, supporting declarative configuration via YAML and MAML. The system includes built-in recipes for popular frameworks and infrastructure integrations, enabling comprehensive lifecycle management from environment setup to rollback.
How it got here
2013–2014 — Architecture modernization and PHP 8.3 upgrade
10 changes.
The project underwent a comprehensive overhaul, migrating to PHP 8.3 and Symfony 7.4/8.0 while replacing legacy core classes with a new YAML-based configuration system and isolated task execution engine. This period also saw the introduction of modern development tooling, including Docker support and static analysis, alongside new deployment recipes for CakePHP and CodeIgniter.
2016–2020 — Architecture modernization and feature expansion
12 changes.
This period focused on a comprehensive architectural overhaul, introducing a Master-Server-Worker execution model and a dedicated Host abstraction to enable parallel processing and advanced SSH management. The codebase was significantly expanded with new utility classes for HTTP and Rsync, structured logging, and a robust exception handling system. Additionally, the project grew its ecosystem through numerous contrib recipes for third-party integrations and automated documentation generation tools.
2021–2024 — SSH refactoring and test expansion
12 changes.
This period focused on refactoring the SSH execution module to improve security and timeout handling, alongside introducing a new ProcessRunner class for command execution. Significant effort was also dedicated to expanding test coverage across core components, including configuration, host management, and task execution, while adding a new provision recipe for setting up remote deployment environments.
2026 — Import feature and test expansion
5 changes.
This period introduced support for importing MAML and YAML deployment recipes, enabling modular configuration management. It also significantly expanded test coverage by adding unit tests for the new Import, Logger, and Utility components, while consolidating legacy tests into a new spec suite.
Features
Add Pimple as a dependency injection component
The application now includes the Pimple library as an internal component under \src/Component/Pimple\, providing a lightweight dependency injection container. This adds the \Container\ class implementing \ArrayAccess\ for managing services and parameters, along with specific exception classes (\FrozenServiceException\, \UnknownIdentifierException\, etc.) to handle container state errors, enabling more structured service management within the codebase.
src/Component · high confidence
Automated API and recipe documentation generation
Added a new \src/Documentation\ component containing \ApiGen\, \DocGen\, \DocConfig\, \DocRecipe\, and \DocTask\ classes that automatically parse PHP source code to generate Markdown documentation. This tool extracts function signatures, parameter types, and comments for the API reference, and parses recipe files to document configuration settings, tasks, and their interdependencies, enabling the automatic generation of up-to-date deployment guides and API docs.
src/Documentation · high confidence
Introduce new Collection class for managing named items
A new \Collection\ class has been added to the \src/Collection\ directory to provide a typed, iterable container for storing and retrieving named items. This class implements \Countable\ and \IteratorAggregate\, allowing users to add, retrieve, check for existence, remove, and filter items using standard PHP iteration and array-access patterns, while enforcing strict typing via \declare(strict\_types=1)\ and modern PHP type hints.
src/Collection · high confidence
Introduction of ProcessRunner class for command execution
A new ProcessRunner class has been added to handle the execution of remote commands. It manages environment variables, dotenv sourcing, and secret replacement before running the command via Symfony Process. The class integrates with the Logger to output command details and process buffers, and it handles timeouts and failures by throwing specific Deployer exceptions.
src/ProcessRunner · high confidence
New HTTP client and refactored Rsync utility
This change introduces a new \Httpie\ utility class in \src/Utility\ that provides a fluent API for making HTTP requests (GET, POST, PUT, PATCH, DELETE) with support for headers, authentication, and JSON/form bodies, returning structured \HttpResponse\ objects. It also replaces the previous \Rsync\ implementation with a new class that uses Symfony Process, adds configurable rsync flags and options, supports a progress bar for file transfers, and includes an optional stats display feature.
src/Utility · high confidence
New Host abstraction with SSH multiplexing, ranges, and localhost support
The deployment system now uses a dedicated Host class to manage server configurations, introducing several new capabilities for users. You can now define host ranges using bracket notation (e.g., \[1-3\]) which are automatically expanded into individual hosts. SSH connections can be optimized by enabling multiplexing to reuse existing connections. The system also supports running tasks on localhost without defining a separate host entry. Additionally, users can customize the remote shell and its path, and configure specific SSH options like port, identity file, and config file directly on the host.
src/Host · high confidence
New YAML recipe schema and configuration system
Deployer now supports a new configuration format validated by src/schema.json, allowing users to define imports, hosts, and tasks (including run, runLocally, upload, and download) directly in YAML. This is backed by a new Configuration class that handles hierarchical config merging, environment variable parsing with filters (like quote), and worker synchronization, while the updated Deployer singleton and functions.php provide the corresponding runtime support for these new declarative recipes.
src · high confidence
New blackjack easter egg command and improved init/config commands
The CLI now includes a hidden 'blackjack' command for users to play a card game in the terminal, accessible via the new BlackjackCommand. The 'init' command has been enhanced to support both PHP and MAML recipe languages, includes better template selection, and prevents accidental overwrites of existing files. Additionally, the 'config' command now supports multiple output formats (JSON, YAML, and MAML) for inspecting host configurations, and the 'ssh' command has been updated to handle Windows paths correctly.
src/Command · high confidence
New build, entry-point, and documentation generation scripts
The repository now includes three new executable scripts in the bin directory. bin/build generates a compressed Phar archive (deployer.phar) from the source code, allowing users to create a standalone distribution. bin/dep serves as the new CLI entry point, enforcing a minimum PHP 8.2 requirement, locating the deploy configuration file (deploy.php, deploy.maml, deploy.yaml, or deploy.yml), and initializing the Deployer application. bin/docgen provides a tool to regenerate API reference documentation, recipe documentation, and the JSON schema for deploy configurations.
bin · high confidence
New contrib recipes for Bugsnag, Cachetool, Chatwork, CIMonitor, Cloudflare, cPanel, crontab, DirectAdmin, Discord, Grafana, Hangouts, Hipchat, ISPmanager, and Mattermost
This release adds a large set of new contrib recipes that extend Deployer with deployment integrations and server management tasks. The new files introduce recipes for notifying Bugsnag of deployments, clearing PHP caches via Cachetool (including OPcache, APCu, and stat:clear), sending notifications to Chatwork, CIMonitor, Discord, Grafana, Google Hangouts Chat, Hipchat, and Mattermost, purging Cloudflare caches, managing cPanel and DirectAdmin domains and databases, syncing and removing crontab jobs, and configuring ISPManager Lite. Each recipe provides specific tasks (e.g., bugsnag:notify, cachetool:clear:opcache, crontab:sync, directadmin:createdb) and configuration options to integrate these services into the deployment workflow.
contrib · high confidence
New deployment recipes for CakePHP, CodeIgniter, and CodeIgniter 4
Added deployment recipes for CakePHP 4, CodeIgniter, and CodeIgniter 4. The CakePHP recipe configures shared directories (logs, tmp) and files (config/.env, config/app.php), and includes tasks to symlink plugin assets and run database migrations. The CodeIgniter recipe sets up shared and writable directories for application cache and logs. The CodeIgniter 4 recipe provides a comprehensive set of tasks for the Spark CLI, including version-aware command execution, environment checks, database migrations, cache management, and optimization, with specific shared and writable directory configurations for the writable folder structure.
recipe · high confidence
New exception classes for configuration, schema, timeouts, and graceful shutdowns
The src/Exception directory now includes several new exception types to improve error handling and debugging. ConfigurationException and SchemaException provide specific error types for invalid configuration and schema validation issues. TimeoutException is introduced to handle command execution timeouts, including the command name and timeout duration in its message. GracefulShutdownException allows tasks to fail without triggering the 'fail' callback, enabling more controlled shutdown behavior. RunException now includes detailed context such as the host, command, exit code, and output/error streams. WillAskUser exception supports interactive prompts with a static flag to control user interaction. The base Exception class has been enhanced to track task source location, filename, and line number for better error reporting.
src/Exception · high confidence
New provision recipe for PHP, Node.js, databases, and Caddy web server
The provision recipe now includes dedicated components to set up a complete deployment environment on remote servers. It provisions PHP (with configurable versions and FPM configuration), Node.js (using fnm for LTS support), and databases (MySQL, MariaDB, or PostgreSQL) with automated user and database creation. The web server is configured via Caddy, including a custom 404 error page and specific handling for PHP-FPM sockets. Additionally, it manages the creation of a dedicated 'deployer' user with appropriate SSH and file permissions.
recipe/provision · high confidence
New structured logging system with file output and CI integration
The application now includes a dedicated Logger component that writes logs to both the console and a specified file. This new system provides structured task timing (including human-readable duration), integrates with GitHub and GitLab CI for collapsible task sections, and handles exceptions with detailed context. It replaces the previous ad-hoc logging approach with a consistent interface for file and console output.
src/Logger · high confidence
New support utilities and object proxying
The src/Support area now includes an ObjectProxy class that allows method calls to be forwarded to multiple Host objects simultaneously, a Reporter class that asynchronously sends deployment statistics to deployer.org, and a comprehensive helpers.php file providing utility functions for array manipulation, environment variable stringification, secret replacement, and host colorization.
src/Support · high confidence
Support for importing MAML and YAML deployment recipes
Users can now import external deployment configurations using \.maml\ and \.yaml\ files via the new \Import\ class. The system automatically detects the file format and delegates to \MamlRecipe\ or \YamlRecipe\ respectively. MAML recipes are validated against a strict schema supporting task definitions, host configurations, and steps like \run\, \runLocally\, \cd\, \upload\, and \download\, while YAML recipes are parsed to define hosts, config, tasks, and lifecycle hooks (\before\, \after\, \fail\). This allows users to modularize their deployment logic into reusable recipe files.
src/Import · high confidence
Removals
Removal of legacy Deployer core classes and global functions
The \Task\, \Tool\, \Tool\\Context\, \Tool\\Remote\, and \Tool\\Remote\\Rsa\ classes, along with the global helper functions in \functions.php\ (such as \task\, \start\, \connect\, \upload\, and \run\), have been removed from the \src/Deployer\ directory. This deletion eliminates the previous implementation of the deployment tool's core architecture, including its Symfony Console integration, remote SFTP connection handling, and task execution logic.
src/Deployer · high confidence
Architecture
Refactored deploy recipes into modular, standalone task files
The monolithic deploy recipe has been split into distinct, modular files (check\_remote, cleanup, clear\_paths, copy\_dirs, env, info, lock, push, release, rollback, setup, shared, symlink, update\_code, vendors, writable). This change reorganizes the deployment logic into individual components, improving maintainability and allowing users to selectively include or override specific deployment steps. Each file now contains its own task definition and configuration, making the deployment process more transparent and easier to customize.
recipe/deploy · high confidence
Behavioural changes
Host selector now supports multiple values in labels
The new Selector component allows filtering hosts using expressions where label values can be specified as a list (e.g., \env=staging\|production\). This enables users to select hosts matching any of several label values in a single expression, rather than requiring separate selectors for each value.
src/Selector · high confidence
Refactored SSH execution with improved timeout handling and secure parameter management
The SSH module has been refactored to improve reliability and security. A new \RunParams\ class now manages execution settings, introducing a \killOnTimeout\ flag (replacing the previous \noCleanup\ concept) to explicitly control whether child processes are terminated when a command exceeds its timeout. Sensitive data, such as secrets, is now marked with the \SensitiveParameter\ attribute to prevent accidental logging. Additionally, a new \IOArguments\ helper standardizes the collection of console input/output options for SSH commands, and the \SshClient\ implementation has been updated to use these new parameters and a dedicated logger for command execution.
src/Ssh · high confidence
Refactored executor architecture with new Master/Server/Worker components
The deployment execution engine has been restructured to use a new Master-Server-Worker model. The new Master component orchestrates task execution across hosts, supporting parallel processing with configurable limits and specific modes like 'once' or 'once per node'. It communicates with Worker processes via a new HTTP-based Server implementation that handles request routing, authentication via bearer tokens, and client connection management. This change introduces a Planner for visualizing task assignments and a Response class for structured communication, fundamentally changing how deployment tasks are dispatched and monitored compared to the previous implementation.
src/Executor · high confidence
Refactored task execution engine with new Context and GroupTask abstractions
The task execution model has been restructured to improve isolation and support complex task compositions. A new Context class now manages the execution state (such as the current Host) via a stack-based push/pop mechanism, ensuring that task-specific data is properly isolated and automatically restored after each task runs. The introduction of the GroupTask class allows multiple tasks to be bundled and executed sequentially as a single unit, with the ScriptManager handling the expansion of these groups and their associated before/after hooks. Additionally, the ScriptManager now enforces circular dependency detection to prevent infinite loops during task resolution.
src/Task · high confidence
Repository structure modernization and testing infrastructure overhaul
The project has significantly reorganized its repository structure and testing infrastructure. The legacy \test/\ directory has been removed and replaced with a split into \tests/src/\ and \tests/spec/\ suites, configured via a new \phpunit.xml\ that targets PHPUnit 12 schema and includes source coverage for \src/\ and \recipe/\. A new \.php-cs-fixer.dist.php\ enforces the \@PER-CS\ coding standard with specific rules for PHP 7.4 compatibility. The repository now includes a \Dockerfile\ based on PHP 8.5-alpine, a \.dockerignore\ file, and a \phpstan.neon\ configuration raising static analysis to level 6. Additionally, the legacy \deploy.php\ example script has been removed, and \.gitignore\ and \.gitattributes\ have been updated to exclude build artifacts, caches, and non-essential files from archives.
(repo-wide) · high confidence
Test coverage
Added test fixtures for repository and upload scenarios; Added test suite for Collection and Selector components; Added unit and integration tests for HTTP and Rsync utilities; Added unit and integration tests for SSH components; Added unit and integration tests for command and process runner components; Added unit tests for Configuration parsing and escaping; Added unit tests for Deployer, Functions, and Quote utilities; Added unit tests for Host, Configuration, and Range components; Added unit tests for Import functionality and MAML recipes; Added unit tests for Task execution, context, and script management; Added unit tests for support helpers and object proxy; Added unit tests for the Logger component; Migrate legacy tests to the \spec\ suite; Removal of test bootstrap file; Removed legacy Deployer test files.
Dependencies
Major dependency upgrade and PHP 8.3 requirement
The project now requires PHP 8.3 and has upgraded its core dependencies to Symfony 7.4/8.0 (console, process, yaml), replacing the legacy phpseclib with maml/maml ^3.2. Development tooling has also been significantly updated, moving to PHPUnit 12.5, phpstan 2.1, and php-cs-fixer 3.68. Additionally, the package namespace changed from elfet/deployer to deployer/deployer, and autoloading switched from PSR-0 to PSR-4.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 46 → 60 (+14.1)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.
Lenses
- Code Health 94 → 87 (-7.0)
- Architecture 96 → 98 (+2.8)
- Maturity 34 → 44 (+9.9)
- Readiness 27 → 61 (+33.9)
- Security 89 → 86 (-2.8)
Resolved (14)
- Coverage not measured — test suite did not build
- Dimension evaluation failed
- DocGen.gen (cognitive 63) (DocGen)
- DocGen.gen (cyclomatic 23) (DocGen)
- Duplicated block (14 lines × 2) (src/Import/YamlRecipe.php)
- Duplicated block (5 lines × 2) (src/Import/MamlRecipe.php)
- Low IaC: DS-0026 (Dockerfile)
- Master.run (cognitive 77) (Master)
- Master.run (cyclomatic 26) (Master)
- No artifact signing
- No exposed public API
- No tests found
- Test reliability not included
- The Tasks document mentions task() and desc() but does not explain how to fetch an existing task or chain config on it as shown in the example. (docs/tasks.md)
New (71)
- ApiGen.parse (cognitive 31) (src/Documentation/ApiGen.php)
- BlackjackCommand.execute (cognitive 34) (src/Command/BlackjackCommand.php)
- BlackjackCommand.execute (cyclomatic 30) (src/Command/BlackjackCommand.php)
- Boundary-crossing change coupling: ProcessRunner.php ↔ SshClient.php (src/ProcessRunner/ProcessRunner.php)
- Boundary-crossing change coupling: WorkerCommand.php ↔ Master.php (src/Command/WorkerCommand.php)
- Boundary-crossing change coupling: rsync.php ↔ SshClient.php (contrib/rsync.php)
- Dependency hygiene PARTLY measured — Composer dependencies read, no committed lock to grade for currency
- Deployer.run (cognitive 18) (src/Deployer.php)
- DocGen.gen (cognitive 137) (src/Documentation/DocGen.php)
- DocGen.gen (cyclomatic 49) (src/Documentation/DocGen.php)
- DocRecipe.parse (cognitive 67) (src/Documentation/DocRecipe.php)
- DocRecipe.parse (cyclomatic 25) (src/Documentation/DocRecipe.php)
- Documentation: no installation or build instructions (README.md)
- Documentation: no installation or build instructions (docs/ci-cd.md)
- Documentation: no usage examples (docs/basics.md)
- Duplicated block (10 lines × 2) (src/Import/MamlRecipe.php)
- Duplicated block (10 lines × 2) (src/functions.php)
- Duplicated block (15 lines × 2) (src/functions.php)
- Duplicated block (16 lines × 2) (src/Import/YamlRecipe.php)
- Further sole-owners (lower concentration)
- …and 51 more
Changes since last survey
- 1 commits — 1 feature/other, 0 fixes
By area
- (root) — 1 commit
Notable commits
- change: Remove Crow Watch promotional content
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
deployphp/deployer was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 26 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit c08d1367d8f1688e5ee66ba5c3821a12743125f4 — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-a15879f6f801.