Operations

Deploy a Rails App With SSM and Docker

A git-based continuous deployment flow to a shared Docker host, orchestrated by AWS SSM (no SSH). Push to main, CI goes green, and a deploy job runs git reset + docker compose up --build on the instance. Covers compose, secrets, least-privilege IAM, boot migrations and verification.

Premium

What this flow is

This playbook describes a git-based continuous deployment (CD) to a
shared Docker host, orchestrated entirely by AWS Systems Manager (SSM)
— no SSH keys, no bastion, no interactive shell.

The mental model is simple:

push to main
  -> CI (audit + lint + tests) goes green
    -> deploy job authenticates to AWS
      -> aws ssm send-command (AWS-RunShellScript) on the instance
        -> on the host: git fetch/reset --hard + docker compose up -d --build
          -> healthcheck (curl /up)

Why SSM instead of SSH

When to use this

When NOT to use this

The steps below build the flow from the ground up: the deploy compose file,
secrets on the host, the CD job that fires the SSM command, migrations on
boot, verification (with a timing gotcha), and rollback.

Steps

Subscriber-only content. View plans