# Deploy Contract `deploy.schema.json` defines the future `deploy/deploy.json` manifest shape. The MVP acceptance environment is DEV only, with endpoint `http://74.48.78.17:6667`. PROD profile fields may be represented in schema for future compatibility, but PROD deployment is not part of MVP acceptance. ## L5 DEV Skeleton - `deploy/deploy.json` is the DEV-only deploy manifest. - `deploy/k8s/base` contains parseable k3s resource skeletons for the frozen HWLAB service IDs. - `deploy/k8s/dev` contains the DEV health contract and endpoint metadata. - `hwlab-cloud-api` declares the DEV DB env contract with `HWLAB_CLOUD_DB_URL` from Secret reference `hwlab-cloud-api-dev-db/database-url` and non-secret `HWLAB_CLOUD_DB_SSL_MODE=require`. The repository records names only, never secret values or a live DB connection string. - `deploy/k8s/prod` is a disabled placeholder gate only. - `deploy/frp` describes the D601-to-master reverse link without secrets. - `deploy/master-edge` describes public edge ownership and health boundaries. Next DEV deploy smoke commands, for a separately authorized deployment task: ```sh npm run check node -e "JSON.parse(require('node:fs').readFileSync('deploy/deploy.json','utf8'))" kubectl apply --dry-run=server -k deploy/k8s/dev curl -fsS http://74.48.78.17:6667/health/live node scripts/dev-edge-health-smoke.mjs --live --write-report ``` Do not run PROD deployment or substitute UniDesk backend, provider-gateway, or microservice proxy for HWLAB runtime services.