Skip to main content
If you have code in a GitHub repository, you might want to connect it to an Upsun project. This means you can keep your GitHub workflows and treat the GitHub repository as the source of truth for your code. Your Upsun project becomes a mirror of your GitHub repository. This means you shouldn’t push code directly to Upsun. Any changes you push directly get overwritten by the integration when changes happen in the GitHub repository. When you set up an integration with GitHub, it automates the following processes for you:
  • Creating a new environment when a branch is created or a pull request is opened.
  • Rebuilding the environment when new code is pushed to GitHub.
  • Deleting the environment when a pull request is merged.

Before you begin

To manage source integrations, you need to be a project admin. You also need a GitHub repository with working code.

1. Generate a token

To integrate your Upsun project with an existing GitHub repository, you need to generate a new token. You can generate a classic personal access token, or a fine-grained personal access token for even greater control over the permissions you grant. For the integration to work, your GitHub user needs to have permission to push code to the repository. When you set up or update an integration, it also needs permission to manage its webhooks. This means your user needs to be a repository admin to create the integration. You can remove this permission after setup. Make sure you give your token a description. If you’re generating a classic personal access token, ensure the token has the appropriate scopes based on what you want to do: If you’re generating a fine-grained personal access token, ensure the token has the right repository permissions for the integration to work: After you’ve set the needed scopes or permissions, generate and copy your token.

2. Enable the integration

To enable the integration, use either the CLI or the Console.
Run the following command:
  • PROJECT_ID is the ID of your Upsun project.
  • OWNER/REPOSITORY is the name of your repository in GitHub.
  • GITHUB_ACCESS_TOKEN is the token you generated.
  • GITHUB_URL is the base URL for your GitHub server if you self-host. If you use the public https://github.com, omit the --base-url flag when running the command.
For example, if your repository is located at https://github.com/platformsh/platformsh-docs, the command is similar to the following:
In both the CLI and Console, you can choose from the following options: To keep your repository clean and avoid performance issues, make sure you enable both the fetch-branches and prune-branches options.

3. Validate the integration

Verify that your integration is functioning properly using the CLI:

Add the webhook manually

If the integration was added with the correct permissions, the necessary webhook is added automatically. If you see a message that the webhook wasn’t added, add one manually. To configure a webhook on a GitHub repository, you need to have Admin user permissions.
  1. Get the webhook URL by running this command: upsun integration:get --property hook_url.
  2. Copy the returned URL.
  3. In your GitHub repository, click Settings > Webhooks > Add webhook.
  4. In the Payload URL field, paste the URL you copied.
  5. For the content type, select application/json.
  6. Select Send me everything.
  7. Click Add webhook.
You can now start pushing code, creating new branches, and opening pull requests directly in your GitHub repository. Your Upsun environments are automatically created and updated.

Environment parent and status

When a branch is created in GitHub, an environment is created in Upsun with the default branch as its parent. It starts as an inactive environment with no data or services. When a pull request is opened in GitHub, an environment is created in Upsun with the pull request’s target branch as its parent. It starts as an active environment with a copy of its parent’s data.

Source of truth

When you add an integration, your GitHub repository is considered to be the source of truth for the project. Your Upsun project is only a mirror of that repository and you can only push commits to GitHub. To clone your code, follow these steps:
Run the following command:
When you do this, you’re cloning from your integrated GitHub repository, if you have the appropriate access to do so.

Sync, fetch, and prune

An integration from your source repository to Upsun establishes that:
  • your source repository is the source of truth, where Git operations occur
  • Upsun is a mirror of that repository, provisioning infrastructure according to configuration, and orchestrating environments according to the branch structure of the your source repository repository
Actions that take place on Upsun don’t affect commits on your source repository. Because of this, the your source repository integration enables both fetch-branches (track branches on your source repository) and prune-branches (delete branches that don’t exist on your source repository) by default. You can change these settings but it is recommended to keep them. When enabled by default, you are limited by design as to what actions can be performed within the context of an Upsun project with a your source repository integration:

Pull request URLs

When a pull request is deployed, the integration reports the primary URL for the deployed environment. So you get a link to the deployed environment right in the pull request. If you have multiple routes, ensure the correct one is reported by specifying the primary route.
Last modified on June 25, 2026