Production deploys are platform-owned; this repo contributes configuration,
the revision envelope, and conformance expectations.
Envelope
deploy/revision.schema.json binds commit + two image digests + green gates
build identity, issued by Luci. The platform rejects or holds a candidate
whose compatibility baseline no longer matches production.
Local verification
mise run images builds both final images from the recorded bases.
mise run boot-test runs the two-container pod with fake providers and
asserts readiness within 60 seconds (exits 77 without podman).
Quadlet templates
deploy/quadlet/ holds the pod + container templates the platform repins:
service drops all capabilities and mounts only its data volume; agent mounts
only its volume and scoped secrets, never host sockets.
Open platform work
Luci extensions and the host deploy API are tracked in deploy/contract.md;
until they exist, deployment-related client calls fail closed with clear
errors (see src/agent/deploy-client.ts).
# Deployment
Production deploys are platform-owned; this repo contributes configuration,
the revision envelope, and conformance expectations.
## Envelope
`deploy/revision.schema.json` binds commit + two image digests + green gates
+ build identity, issued by Luci. The platform rejects or holds a candidate
whose compatibility baseline no longer matches production.
## Local verification
- `mise run images` builds both final images from the recorded bases.
- `mise run boot-test` runs the two-container pod with fake providers and
asserts readiness within 60 seconds (exits 77 without podman).
## Quadlet templates
`deploy/quadlet/` holds the pod + container templates the platform repins:
service drops all capabilities and mounts only its data volume; agent mounts
only its volume and scoped secrets, never host sockets.
## Open platform work
Luci extensions and the host deploy API are tracked in `deploy/contract.md`;
until they exist, deployment-related client calls fail closed with clear
errors (see `src/agent/deploy-client.ts`).