# Deliver from CI

> Every test build sent from CI under a code, and the client’s answer coming back as a status: approved, or changes. How to do it with colis, what to watch, and where it is written down.

Canonical: https://colis-site.vercel.app/en/use-cases/livrer-depuis-la-ci · Markdown: https://colis-site.vercel.app/en/use-cases/livrer-depuis-la-ci.md · Français: https://colis-site.vercel.app/use-cases/livrer-depuis-la-ci

Every test build sent from CI under a code, and the client’s answer coming back as a status: approved, or changes.

```yaml
# colis is built from the repository until it is on npm
- run: npm run build && tar cz ./dist > recette.tar.gz
- run: |
    CODE=$(colis envoyer ./recette.tar.gz)
    echo "Build de recette : https://livraison.example.com/$CODE" >> "$GITHUB_STEP_SUMMARY"
  env:
    COLIS_REMOTE: https://livraison.example.com/api/transfers
    COLIS_TOKEN: ${{ secrets.DROP_PASSWORD }}

# later, in any script
# colis statut "$CODE" | head -1   → envoyé, ouvert, validé or à corriger
```

## What is actually going on.
### The problem
Every test build leaves through a different channel: a storage link that never expires, a file too heavy for email, a screenshot in a chat. The tester’s feedback lands somewhere else, and which build was tested is never clear.

### What colis does about it
The pipeline sends the build with `colis envoyer` against your delivery page. The code is the only thing on stdout, so it drops into a message or a pull request comment. The client opens the link, downloads, tests, then approves or describes what is wrong. `colis statut <code> | head -1` gives a script the state, and `--json` the whole receipt.

## The things that are easy to get wrong.
- **The function’s limit** — The CLI sends in one request, through the delivery page’s function, so the file has to fit under `DROP_MAX_SIZE_MB`: 4 MB by default, for Vercel. Above that, send it from the page, which goes straight to the bucket in parts, or raise the limit on a host without that cap.
- **The token is the upload password** — `--token`, or `COLIS_TOKEN` in CI, is the page’s `DROP_PASSWORD`. The CI machine needs no S3 key at all.
- **The page’s options do not ride along** — A parcel the CLI creates takes the deployment’s defaults: no password, no note, the default lifetime. To set them from a terminal, send the `x-drop-*` headers with curl.

Packages: colis, colis-drop. [The CLI, in full](https://github.com/mamadouwhile/colis/tree/main/packages/cli)
