Apps and jobs
Tested with: Not yet available on Databasezy · describes the launch design
An app is a container from your image, running as an always-on HTTPS service in the same region as its project’s databases. Jobs run commands in the app’s image once or on a schedule.
How it works
Section titled “How it works”- Image: any image in a registry you authorise. A tag is pinned to its digest when you deploy, so a moved tag never changes a running release.
- Releases: every deploy, restart and rollback is a release; roll back to any earlier one.
- Environment: plain values, project secrets, or references to an instance’s credentials
(
DATABASE_URLfrom an instance). References are resolved in the region; the control plane never stores the value. - Networking: each app gets its own hostname with a managed certificate, and custom domains. Apps reach their project’s instances inside the region, without egress charges.
- Scaling: minimum and maximum replicas, CPU autoscaling, and scale to zero when idle on paid plans.
- Jobs: one-off or cron, with the app’s image and environment.
- Isolation: apps run on node pools separate from databases, one namespace each, with network policies; no customer code runs on the free tier.
Deploy (at launch)
Section titled “Deploy (at launch)”zb apps create web --image ghcr.io/acme/web:1.4.2 --size c1 \ --env-instance DATABASE_URL=orders-db --waitzb apps deploy web --image ghcr.io/acme/web:1.4.3zb apps rollback webzb apps jobs create web nightly --schedule "0 3 * * *" -- node cleanup.jsDeploy from GitHub
Section titled “Deploy from GitHub”Connect the organization’s GitHub App (Integrations), then create the app from a repository instead of an image. Every push to its branch builds and deploys a new release:
zb apps create web --repo acme/web --branch main # a Dockerfile at the rootzb apps create api --repo acme/api --builder buildpacks # no Dockerfile: Paketo buildpackszb apps builds create web --wait # build nowzb apps builds logs web bld_... -f # follow a build's log- Builds run in the app’s region, in an isolated build VM with no access to your databases or to other customers, reaching the internet only for base images and package registries. The source is fetched with a read-only token for that one repository; build logs mask credentials.
- Built images stay in the region’s registry under your organization and are pinned by digest.
- Build minutes are billed per started minute (
app_build_minutes; plans include some). - In a GitHub Actions workflow,
zb apps builds create <app> --wait(Git apps) orzb apps deploy <app> --image ... --wait(image apps) deploys from CI; see the example workflow.
Network access and secrets
Section titled “Network access and secrets”An app can reach the internet by default. Restrict it per app with an egress policy (none, internet, or an
allow-list of hosts and public CIDRs), and give it API keys as cloaked secrets: the variable holds a placeholder,
and the region’s egress proxy adds the real value only on requests to the hosts you bind it to (see
Sandboxes, which work the same way). Apps always reach their project’s
instances.
Rollouts
Section titled “Rollouts”A release replaces the previous one replica by replica. With the canary strategy a new release first receives a
share of the traffic (10 %, then 50 % by default) and is promoted only while its error rate and latency stay within
the limits you set; otherwise it is rolled back and the previous release keeps serving.
Patching and vulnerability reports
Section titled “Patching and vulnerability reports”The region scans the image an app serves and reports known vulnerabilities by severity. With automatic patching on, a Git app is rebuilt when its base image gets a newer digest and an image app is re-resolved when its tag moves.
Builds, egress policies, canary rollouts, previews and scans are enabled region by region; the API answers
501 feature_unavailable where one is not available yet.
| Size | vCPU | Memory | $ / hour | ≈ $ / month (730 h) |
|---|---|---|---|---|
c0 | 0.25 | 512 MiB | $0.00685 | $5 |
c1 | 0.5 | 1 GiB | $0.0137 | $10 |
c2 | 1 | 2 GiB | $0.0274 | $20 |
c3 | 2 | 4 GiB | $0.0548 | $40 |
Each running replica is billed per hour at its size price. A scaled-to-zero app costs nothing for compute.
Pricing
Section titled “Pricing”| Meter | Price | Free | Solo | Team | Enterprise |
|---|---|---|---|---|---|
| App compute Coming soon | By size, per replica-hour | Not available | Pay as you go | Pay as you go | Pay as you go |
| App build minutes Coming soon | $0.01 per minute | Not available | 100 min | 1,000 min | Contract |
| Limit | Free | Solo | Team | Enterprise |
|---|---|---|---|---|
| Apps Coming soon | None | 3 | 20 | Unlimited |