# deploy-trigger host units `deploy.sh` needs root (it calls `sudo docker compose ...`). Rather than give the Tailscale-gated `deploy-trigger` container that power directly, it only writes a request file into `../data/deploy-requests/`. These two units are the only thing on the host, outside Docker Compose, that turns a queued request into an actual deploy - and they do it as root, so no sudoers changes or container privileges are needed anywhere else. Install once per deploy host: ```bash sudo ln -s "$(pwd)/deploy-trigger.path" /etc/systemd/system/ sudo ln -s "$(pwd)/deploy-trigger.service" /etc/systemd/system/ sudo systemctl daemon-reload sudo systemctl enable --now deploy-trigger.path ``` Check it's watching: `systemctl status deploy-trigger.path`. Check the last run: `journalctl -u deploy-trigger.service` and `tail -f ../log/deploy/deploy-audit.log`.