rsync -avz --exclude '*.swp' --delete site/ $(WEBUSER)@$(WEBHOST):site/
This way I'm only putting the necessary files on the server and transferring changes is incredibly fast and secure (ssh is used by default).In rare cases where I need to deploy from a repo on the server, I'll clone it to the remote host and use rsync locally to copy the files. But I still avoid serving directly out of the repo. There's too much sensitive information in version control to even risk exposing it during a misconfiguration.