Kordin Neo
Organization Acme Labs
Search or jump to ⌘K
$21.05
A bell with a count and a short list of what needs attention is not in this build yet. Documentation Get help Signed in as Sam Okonkwo Your settings
Not connected is where a new org lands. Disconnecting matters most of the rest; three after it are the ways connecting fails.

Connections

Where your code comes from, for the whole org
Install the GitHub App, once for the org
Connecting is a decision about the whole org rather than about one service: you pick which repositories we can see, and you pick them on GitHub's side. It happens once per org, not once per deploy, which is why it lives here and not in the middle of a deploy.

Nothing is charged by connecting and nothing is built. Afterwards the repositories you granted are listed on this screen, and nothing else is visible to us.
If you cannot install the integration
tokenSome orgs do not let a developer install one, and some self-managed servers cannot be reached by it. A personal access token works instead — paste it once and we store it write-only, the same way a registry credential is stored.
What it costs youA token carries whatever access the person who made it has, so we cannot narrow it to three repositories the way a granted install does. It also stops working when that person leaves. Prefer the install where you can have it.

Connections

Where your code comes from, for the whole org
GitHub
A GitHub App installed on Acme Labs, not a token pasted into a service
We see the three repositories you granted and nothing else.
3 repositories · 2 services built from it
Connected Disconnect
GitLab
Not available yet
Listed rather than hidden, so the answer is on the screen instead of something you conclude from an absence. A built image is the way in from here today.
proposed
Bitbucket
Not available yet
Same as GitLab. A built image is the way in from here today.
proposed
Registries
Credentials live with the service that needs them
A private registry credential is stored per service, beside the thing that pulls from it, rather than once here for everything.
Deploy an image
Model sources
For gated or private models, held for the whole org
Stored write-only, under a purpose of its own that neither a build nor a running service can read. It never appears in a URL, in a service specification, in an operation or in a log line — not redacted there, absent from there.
1 credential · used by 1 model
Stored

Disconnect GitHub?

Two services were built from it
Nothing stops running. api and web keep serving exactly what is live now, and they keep being charged the same. This is not a way to turn anything off.
Keeps working
the live deployments · their URLs · rollback to anything already built · logs · variables
Stops
deploying on every push · building anything new from this source
To undo it
connect again and re-grant the same repositories — the services reattach by name
Disconnect GitHub
Every service built from this source stops deploying on push. They stay live. Type Acme Labs to confirm you have read what that means.
Cancel

No repositories shared yet

You are connected to GitHub as Acme Labs, but no repository has been shared with us. This is on GitHub's side — we only ever see what you pick there, which is why it is a separate step.

Someone with admin on the Acme Labs organization may need to approve it. Until then there is nothing for us to build.

Deploy an image instead
no-repositories · installation Acme Labs · nothing to retry here

Connections

Where your code comes from, for the whole org
GitHub would not let us in.

The install was refused on GitHub's side. That usually means the Acme Labs organization requires an owner to approve applications, and whoever clicked through was not one.

Nothing was created here and nothing was charged. We hold no access to Acme Labs at all — not a partial grant, not a pending one — so starting again costs nothing and loses nothing.

Someone with admin rights on your GitHub org has to approve this install before we can see anything. Ask them, then come back and try again.

Reference 510ed25f197aGet help ›
Show the code SOURCE_INSTALL_APPROVAL_REQUIRED proposed code

You did not finish connecting

The GitHub window was closed before the install was confirmed, so nothing was granted. This is not an error — backing out of that screen is a perfectly reasonable thing to have done.

Nothing was created and nothing was charged. If you were checking what we would be able to see, the answer is: only the repositories you pick, and only while you keep them picked.

cancelled · no installation created · nothing to retry

What the install asks for

Connecting is a GitHub App installed on your organization, scoped to the repositories you pick. It is worth showing what that grants, because the honest answer is short.

The five permissions
metadata: read The names and default branches of the repositories you granted. Nothing about the ones you did not.
contents: read The code, at the commit being built. We never write to your repository.
checks: write So a build result appears next to your commit. This is the only write anywhere in the list.
pull_requests: read Which pull request a commit belongs to, for preview deployments. Not their contents or comments.
webhooks So we are told when you push, when a pull request opens or closes, and when the install itself changes. This is how deploying on every push knows there was a push.
Not asked for: issues, administration, workflows, or write access to your code. If a later feature needs one of those, it asks then and names itself.

If your organization will not allow the install, the way in is a built image rather than a token. A personal access token is not a supported connection here — its ownership, scope, rotation and offboarding are all weaker than an installation, and it leaves the connection depending on one person, who may leave.

installation-scoped · five permissions · one of them a write