Group servers. Push once. Serve everywhere.
An environment is a set of servers that run the same code — Development, UAT, Live, or a grouping per client, each with its own servers, its own domains, its own variables and its own push rules. Add machines by IP, attach them, and every push lands on the whole group with each server confirming on its own.
One push, every server
The ciphertext goes up once; every engine in the environment pulls it, decrypts it in RAM and reports back on its own line. You see three confirmations, or two and a failure with the reason — never a fleet that is silently half-deployed.
Push and reload are separate
A push uploads the build and moves the environment's pointer; the fleet keeps serving the previous build until it is reloaded. Deploying and rolling out are two deliberate acts, so you push at any hour and choose when it goes live.
Zero-downtime reloads
A reload is an authenticated, timestamp-fresh signal — stale signals are rejected as replay — and an atomic swap: the new image comes up beside the old one, in-flight requests finish against the old, requests after the swap see the new. Under two seconds across a fleet, typically.
Compare, then promote — the same bytes, not the same commit
The Compare pane shows one card per environment: the version hash it points at, when that build was pushed and by whom. A version hash is derived from content, so identical hashes mean byte-identical builds. Same hash in UAT and Live means the same artifact — a stronger statement than "built from the same commit", and the one that matters when something behaves differently in one place.
Promotion repoints an environment at a build that already exists. No bytes move, nothing is re-encrypted, no rebuild happens — which is why what you tested in UAT is exactly what ships. It is also how you roll back: promote the previous build and the environment returns to it, in the time a reload takes. A bad deploy is a minor event, not an incident.
What an environment holds
Its servers
Any number, attached by address. A server belongs to one environment; a license is bound to the server's own IP and keys the builds it may decrypt.
ServersIts domains
Development and Live hold different lists, which is what lets the same project serve staging.example.com and example.com from different machines. Point the A record at the servers, or at a load balancer in front; adding a domain in Cipher does not change DNS, and both steps are needed.
Its variables
Database URLs, API keys, feature flags — per environment, encrypted at rest beside the build, injected into the process in memory at start. A change needs a reload, not a push, and is logged as a change — the fact, not the value.
Its push rules
No push between Development, UAT and Live without explicit rights. Who may push where is a permission per environment, granted per member.
TeamIts board
Monitoring shows one card per server — hostname, IP, uptime, latency and heap on fixed scales so machines compare at a glance — polled every ten seconds while the window is in front of you. An unreachable server shows a greyed dial and a dash, never a needle parked in the green.
Its record
Every push, promotion, reload, reset and variable change in the environment is in the activity log with the actor, the time and the originating address.
ActivityReset an environment. Watch every server answer.
Trigger a fleet-wide reset and Cipher tracks each machine independently — the engine on every box re-fetches the encrypted build, decrypts it fresh into RAM and reports. The one that fails is shown as a failure with its reason, because that is the state that matters when you are on call. There is no "the fleet is probably fine".
The same independence is what makes a server disposable. Nothing irreplaceable lives on it; a lost box is replaced by installing the engine on a fresh one and letting the environment push itself back.
Development, UAT, Live — and one per client if you need it
Write to us with how your fleet is laid out today, and we will show you how it looks as environments in Cipher.