BEAM_TOKEN through your CI provider’s secret store. The CLI reads it directly; you do not need an interactive browser login or a command that prints or writes the token.
Image are installed remotely and do not make local imports available.
GitHub Actions
Save a workspace token as the repository or environment secretBEAM_TOKEN. This example deploys the same handler to distinct app names on main and staging.
app.py
.github/workflows/beam.yml:
beam --no-input deploy --name app-prod --dockerfile Dockerfile --port 8000. Python SDK installation is still needed for the CLI, but your container’s application dependencies belong in its Dockerfile.
Readiness and rollback
A successful deploy creates an active version; it does not prove that requests can be served yet. Record the deployment ID returned by the command, then runbeam deployment wait <deployment-id> --timeout 300 for an endpoint or ASGI deployment. Add an application-level smoke check appropriate to your workload.
See deployment lifecycle for rollout options and rollback. Keep deployment credentials scoped to the intended workspace and restrict which branches can access production CI secrets.