Fly.io is a planned Capy deploy target in 0.9.7. Use Fly’s normal deployment tooling and Capy’s token-and-instructions path.
Build an image with capy run as its entrypoint. The Dockerfile in Docker works unchanged for a Fly Machine.
Create a deploy-token pair from the Capy branch that should run on this Fly app, then set the two values with Fly’s secret command:
Deploy the code through your normal Fly workflow:
At Machine startup, capy run decrypts the map and starts the application. The Machine needs outbound connectivity to the Capy service at startup. The emitted pair uses SECRETS_BLOB / PROJECT_KEY, so remove a same-named plaintext variable from Fly when the decrypted value is meant to be authoritative.
Environment changes
Use a separate Fly app or Fly environment configuration for each Capy branch. When a value changes, mint a fresh pair from that branch, update both Fly secrets, and deploy or restart the Machines. Revoke an unused pair with capy deploy revoke <deploy-id>. Last modified on October 2, 2026