Skip to main content

Deployment

Full-code apps can be deployed via the CLI or the UI editor. This page covers deployment options and configuration.

Deploy via CLI

Push your app to Windmill:

wmill sync push

The CLI reads raw_app.yaml, bundles your frontend code, uploads backend runnables and deploys the app. See CLI workflow for the full push flow.

Deploy via UI

From the in-browser editor, click the deploy button to save and publish your app.

Public apps

Make your app accessible without authentication by setting public: true in raw_app.yaml:

summary: "Public dashboard"
public: true

Public apps are accessible at their app URL without requiring a Windmill login. The execution policy is auto-generated at deployment time. See public apps for more details.

Custom paths

Admins can set a custom URL path for an app:

custom_path: "my-dashboard"

The app will then be accessible at https://<instance>/a/my-dashboard (on multi-workspace deployments such as the cloud, the workspace is part of the path: https://<instance>/a/<workspace>/my-dashboard).

Execution policy

The execution policy is auto-generated at deployment time. It controls how backend runnables are executed:

ModeDescription
publisherRequires login and read access on the app. Runnables execute as the app publisher (the user who deployed the app), so users don't need direct permissions on the underlying scripts. This is the default.
anonymousNo login required. Runnables still execute as the app publisher; unauthenticated callers appear as anonymous. This is the mode used by public apps.
viewerRequires login. Runnables execute with the permissions of the viewer themselves, for per-user access control.

The triggerables and triggerables_v2 fields map each runnable to its execution configuration and are populated automatically during push/deploy.

Versioning

Each deployment creates a new version of the app. The version counter increments on every update. Previous versions are retained and can be accessed through the API.

CI/CD integration

Full-code apps work with Windmill's git sync and deploy to prod workflows:

  1. Develop locally and commit your .raw_app/ (or __raw_app/) directory to git
  2. Use wmill sync push in CI to deploy to a staging workspace
  3. Promote to production using workspace-to-workspace deployment