Files
pikasTech-HWLAB/deploy

Deploy Contract

deploy.schema.json defines the future deploy/deploy.json manifest shape.

The MVP acceptance environment is DEV only. Public endpoint source fields live in deploy/deploy.json: frontend http://74.48.78.17:16666 and API/edge http://74.48.78.17:16667. PROD profile fields may be represented in schema for future compatibility, but PROD deployment is not part of MVP acceptance.

L5 DEV Skeleton

  • deploy/deploy.json is the DEV-only deploy manifest.
  • deploy/deploy.json is the single source for health.path, publicEndpoints, frp.proxies, and k3s.serviceMappings.
  • deploy/k8s/base contains parseable k3s resource skeletons for the frozen HWLAB service IDs rendered from the manifest contract.
  • deploy/k8s/dev contains the DEV health contract and endpoint metadata.
  • hwlab-cloud-api declares the DEV DB env contract with HWLAB_CLOUD_DB_URL from Secret reference hwlab-cloud-api-dev-db/database-url and non-secret HWLAB_CLOUD_DB_SSL_MODE=require. The repository records names only, never secret values or a live DB connection string; runtime health reports redacted env injection and DB connection result classifiers.
  • deploy/k8s/prod is a disabled placeholder gate only.
  • deploy/frp describes the D601-to-master reverse link without secrets.
  • deploy/master-edge describes public edge ownership and health boundaries.

Dry-run source rendering:

node scripts/deploy-contract-plan.mjs --pretty
node scripts/deploy-contract-plan.mjs --check

The deploy contract plan renders and validates only. It does not run frps/frpc, does not call kubectl apply, does not restart services, and does not touch PROD. Later work can wire the same source fields into hwlab edge apply or deploy apply.

Next DEV deploy smoke commands, for a separately authorized deployment task:

npm run check
node -e "JSON.parse(require('node:fs').readFileSync('deploy/deploy.json','utf8'))"
kubectl apply --dry-run=server -k deploy/k8s/dev
curl -fsS http://74.48.78.17:16667/health/live
node scripts/dev-edge-health-smoke.mjs --live --write-report

Do not run PROD deployment or substitute UniDesk backend, provider-gateway, or microservice proxy for HWLAB runtime services.