Orbit
Orbit वेबहुक
Webhooks push a signed HTTP POST to a URL of your choosing every time a deployment changes state, so your team hears about a failed build in the channel they already watch instead of finding out…
Webhooks हर बार जब कोई deployment अपनी स्थिति बदलता है, तो एक signed HTTP POST को आपकी पसंद के URL पर भेजते हैं, ताकि आपकी टीम को failed build के बारे में उस channel में सुनने को मिले जहां वे पहले से देख रहे हैं, न कि किसी customer से पता चले।
Webhooks कहां हैं
Orbit खोलें, project पर क्लिक करें, और project tab strip में Configure group के अंतर्गत Webhooks चुनें। यह पृष्ठ Webhooks शीर्षक वाला है और यह बताता है कि यह deployments की state बदलने पर HTTP POST notifications प्राप्त करता है, Slack, Discord और generic JSON supported हैं।
Webhooks और Hooks विभिन्न चीजें हैं और एक ही menu में एक दूसरे के बगल में बैठी हैं। Webhooks outgoing हैं: Orbit आपको बताता है कि कुछ हुआ है। Deploy hooks incoming हैं: कुछ Orbit को deploy करने के लिए कहता है। उन के लिए, Triggering Deployments Via Deploy Hooks देखें।

एक Webhook जोड़ना
- Add a webhook card में, इसे एक Label दें। कुछ ऐसा जो जहां यह post करता है उस destination जैसा हो।
- URL को paste करें। इसे
https://के साथ शुरू होना चाहिए। - Trigger on के अंतर्गत, उन events को tick करें जो आप चाहते हैं।
- Add webhook पर क्लिक करें।
Signing secret creation के तुरंत बाद एक बार दिखाया जाता है, एक warning के साथ कि यह फिर से नहीं दिखाया जाएगा। इससे पहले कि आप दूर navigate करें इसे copy करें।
एक project में दस तक webhooks हो सकते हैं। ग्यारहवां जोड़ना limit को नाम देने वाली एक संदेश के साथ अस्वीकार कर दिया जाता है।
पाँच Events
| Event | कब fires होता है |
|---|---|
| Queued | deployment queue में प्रवेश करता है |
| Building | build शुरू होता है |
| Succeeded | deployment live हो जाता है |
| Failed | build या deploy में error आता है |
| Cancelled | deployment खत्म होने से पहले रोका गया था |
जानबूझकर चुनें। एक busy project पर सभी पाँचों को subscribe करना एक उपयोगी alert channel को noise में बदल देता है जिसे सभी mute कर देते हैं। अधिकांश teams के लिए, Failed अकेला सही शुरुआती बिंदु है, Succeeded को केवल वहां जोड़ें जहां एक deploy notification वास्तव में उपयोगी हो, जैसे कि एक production channel।
Slack और Discord
यदि URL एक Slack incoming webhook या एक Discord webhook है, तो Orbit इसे URL से detect करता है और raw JSON की जगह एक formatted message भेजता है। यह पृष्ठ URL field के अंतर्गत कहता है: Slack और Discord URLs auto-detected हैं।
Formatted message project name, event, branch, short commit, build time, deployed URL, और error text carry करता है जब कुछ fail होता है। Colour event के बाद होता है, तो channel में एक red card का मतलब है failure बिना किसी के इसे पढ़े।
कुछ और की जरूरत नहीं है। Slack या Discord में incoming webhook create करें, URL को यहां paste करें, अपनी events चुनें, और आप खत्म हो गए।
Generic JSON Payloads
किसी अन्य URL को एक JSON body प्राप्त होता है। Fields ये हैं:
| Field | Contents |
|---|---|
event | पाँच event names में से एक, prefixed deployment. |
projectId, projectName, projectSlug | कौन सा project |
deploymentId | वह deployment जिसके बारे में यह है |
gitCommit, gitBranch, gitCommitMessage | deploy की जाने वाली code |
buildDurationMs | Build time, जहां known हो |
deployedUrl | जहां यह live हुआ |
panelUrl | KPanel में वापस एक link |
errorMessage | Failures पर present |
triggeredAt | ISO 8601 timestamp |
deliveryId | Deduplication के लिए प्रत्येक delivery पर unique |
अपनी endpoint को idempotent बनाने के लिए deliveryId का उपयोग करें। यदि आप किसी delivery को retry करते हैं, या एक network hiccup एक duplicate का कारण बनता है, तो id आपको recognize करने देता है कि आपने इसे पहले से handle कर चुके हैं।
Signature को Verify करना
हर delivery तीन headers carry करती है:
X-Orbit-Signature-256, exact request body का एक HMAC-SHA256 आपके signing secret का उपयोग करके,sha256=के रूप में formatted है और hex digest के साथ।X-Orbit-Event, event name।X-Orbit-Delivery, delivery id।
Signature को verify करें इससे पहले कि आप एक payload पर act करें। Raw body bytes पर same HMAC compute करें, और string equality की जगह constant-time comparison का उपयोग करके compare करें।
const expected = 'sha256=' + crypto
.createHmac('sha256', process.env.ORBIT_WEBHOOK_SECRET)
.update(rawBody)
.digest('hex');
if (!crypto.timingSafeEqual(Buffer.from(expected), Buffer.from(received))) {
return res.status(401).end();
}
Raw request body पर HMAC compute करें, किसी भी JSON parsing और re-serialising से पहले। एक body जिसे parse और stringify फिर से किया गया है आमतौर पर byte-different होता है, और signature कभी भी match नहीं होगा भले ही आपका code कितना ही सही दिखता हो।
Webhook को Test करना
प्रत्येक webhook row में Send test delivery है। यह आपकी endpoint को तुरंत एक real delivery भेजता है और HTTP code की report देता है जो इसे मिला, या failure detail।
एक webhook जोड़ने के तुरंत बाद इसे use करें, इससे पहले कि आप इस पर rely करें। एक firewall rule या एक route जो केवल GET को accept करता है यह पता लगाना एक incident के दौरान की तुलना में अब बहुत आसान है।
Delivery History
प्रत्येक row आखिरी सात दिनों का एक sparkbar carry करता है delivery count, success percentage और average duration के साथ, साथ ही आखिरी fired time और इसका result।
Show delivery history को expand करें individual deliveries के लिए: event, response code, duration, और error text जहां कोई था। किसी भी delivery को Retry delivery के साथ re-sent किया जा सकता है, जो code को report करता है जो इसे मिला।
Deliveries बारह सेकंड के बाद timeout होती हैं। यदि आपकी endpoint slow work करती है, तो पहले 200 के साथ acknowledge करें और बाद में process करें, connection को open रखने की जगह।
Secret को Rotate करना
Rotate secret पर क्लिक करें। नया secret एक बार display होता है, और tooltip स्पष्ट है कि पुराना secret तुरंत invalid हो जाता है।
इसका मतलब एक छोटी window है जहां deliveries एक secret के साथ signed होती हैं जिसे आपकी endpoint नहीं जानती। इसके लिए plan करें: एक quiet moment पर rotate करें, और अपनी endpoint को बहुत अगली action के रूप में update करें।
Rotate करें जब कोई जिसके पास secret का access है चला जाता है, या यदि यह कभी एक shared channel या एक ticket में paste किया गया है।
Disable और Delete करना
Disable webhook deliveries को रोकता है लेकिन configuration और history को रखता है, और row एक Disabled badge दिखाता है। यह सही choice है जब आप alerts को pause कर रहे हैं, उदाहरण के लिए एक planned migration के दौरान जो बहुत सारा noise produce करेगा।
Delete webhook इसे पूरी तरह हटा देता है। Disable को use करें जब तक कि आप निश्चित न हों।
अन्य तरीके Notified होने के लिए
Webhooks flexible option हैं। Settings में दो lighter alternatives बैठी हैं:
- Deploy email notifications, तीन settings के साथ: सभी deploys, failures केवल, या off।
- Notification channels, जो एक webhook URL पर deploy success या failure, build regressions और bundle regressions को post करते हैं, अपने स्वयं के delivery history और test button के साथ।
दोनों के लिए Orbit Project Settings देखें।
Troubleshooting
Deliveries HTTP code के साथ failed के रूप में show होती हैं। आपकी endpoint ने एक error return किया। Code आपको बताता है कि कौन सा: 404 का मतलब path गलत है, 401 या 403 आमतौर पर मतलब है कि आपका अपना signature check इसे reject कर रहा है, और 500 का मतलब है आपका handler throw किया।
Deliveries timeout के साथ fail होती हैं। आपकी endpoint ने बारह सेकंड से अधिक समय लिया। तुरंत 200 return करें और work को asynchronously करें।
कुछ भी deliver नहीं होता है। Check करें कि webhook enabled है और उस event को tick किया गया है जो आप expected करते हैं। एक build जो कभी queue नहीं हुई एक queued event fire नहीं करता है।
Signature कभी भी validate नहीं होता है। लगभग हमेशा raw-body problem जिसे above describe किया गया है। Exact bytes को log करें जो आप hash कर रहे हैं और उनकी length को Content-Length header से compare करें।
एक Slack URL को raw JSON send किया जा रहा है। Slack incoming webhooks hooks.slack.com के अंतर्गत रहते हैं। एक अलग Slack URL को एक के रूप में detect नहीं किया जाएगा।
अगले कहां जाएं
- Triggering Deployments Via Deploy Hooks incoming direction के लिए।
- Orbit Project Settings email notifications और notification channels के लिए।
- Orbit Status Page अपने customers को बताने के लिए, न कि सिर्फ अपनी team को।