Deploy Contract
deploy.schema.json defines the future deploy/deploy.json manifest shape.
The MVP acceptance environment is DEV only. Public endpoint source fields live in
deploy/deploy.json: frontend http://74.48.78.17:16666 and API/edge
http://74.48.78.17:16667. PROD profile fields may be represented in schema
for future compatibility, but PROD deployment is not part of MVP acceptance.
L5 DEV Skeleton
deploy/deploy.jsonis the DEV-only deploy manifest.deploy/deploy.jsonis the single source forhealth.path,publicEndpoints,frp.proxies, andk3s.serviceMappings.deploy/k8s/basecontains parseable k3s resource skeletons for the frozen HWLAB service IDs rendered from the manifest contract.deploy/k8s/devcontains the DEV health contract and endpoint metadata.hwlab-cloud-apideclares the DEV DB env contract withHWLAB_CLOUD_DB_URLfrom Secret referencehwlab-cloud-api-dev-db/database-urland non-secretHWLAB_CLOUD_DB_SSL_MODE=disable. Runtime DB readiness dials the redacted host parsed from that Secret URL.cloud-api-dbis only an optional desired alias until Service plus Endpoint/EndpointSlice ownership and rollout/apply contract exist; see docs/reference/dev-runtime-boundary.md. The repository records names only, never secret values or a live DB connection string; runtime health reports redacted env injection and DB connection result classifiers.hwlab-cloud-apideclares the DEV Code Agent provider contract withOPENAI_API_KEYfrom Secret referencehwlab-code-agent-provider/openai-api-keyandHWLAB_CODE_AGENT_OPENAI_BASE_URLthrough the DEV egress/proxy path. Source checks verify the Secret ref and base-url contract only; they do not prove provider connectivity and must not print API key material. Controlled apply reports also check that the livehwlab-cloud-apiDeployment preserves the same env names andsecretKeyRefname/key metadata after apply without reading Kubernetes Secret data.hwlab-cloud-apialso declaresHWLAB_CLOUD_RUNTIME_ADAPTER=postgresandHWLAB_CLOUD_RUNTIME_DURABLE=trueso DEV can use the Postgres-backed runtime adapter once the schema is applied./health/livemust still remain degraded if DB auth, DB connectivity, or runtime schema readiness is blocked.deploy/k8s/prodis a disabled placeholder gate only.deploy/frpdescribes the D601-to-master reverse link without secrets.deploy/master-edgedescribes public edge ownership and health boundaries.
Dry-run source rendering:
node scripts/deploy-contract-plan.mjs --pretty
node scripts/deploy-contract-plan.mjs --check
The deploy contract plan renders and validates only. It does not run frps/frpc,
does not call kubectl apply, does not restart services, and does not touch
PROD. Later work can wire the same source fields into hwlab edge apply or
deploy apply.
Desired-state commit/image convergence review:
node scripts/deploy-desired-state-plan.mjs --plan --pretty
node scripts/deploy-desired-state-plan.mjs --target-ref origin/main --check
node scripts/deploy-desired-state-plan.mjs --target-ref origin/main --pretty
node scripts/deploy-desired-state-plan.mjs --target-tag <tag> --pretty
node scripts/deploy-desired-state-plan.mjs --promotion-commit <sha> --check
The desired-state plan reads only deploy/deploy.json,
deploy/artifact-catalog.dev.json, deploy/k8s/base/workloads.yaml, and the
optional artifact report snapshot. It checks that commit IDs, service image
tags, workload images, and present env mirrors such as HWLAB_COMMIT_ID,
HWLAB_IMAGE, HWLAB_IMAGE_TAG, and HWLAB_SKILLS_COMMIT_ID converge. It
also blocks if hwlab-cloud-api loses the Code Agent provider Secret ref
hwlab-code-agent-provider/openai-api-key, the OPENAI_API_KEY env name, or
the DEV egress proxy base-url env. Without --check, --target-ref or
--target-tag reports a uniform older desired-state as a read-only promotion
plan. With --check, any explicit target is a hard current-main/commit-pinning
gate: stale deploy, catalog, workload image, or runtime mirror fields are
blocked before apply.
deploy/deploy.json is the deploy truth, but artifact catalog and workload
refs are part of the same desired-state contract. Promotion updates must move
all three together by using the refresh command in blocked mode or
publish-report mode, then run --target-ref origin/main --check or the
promotion commit check. Report files are contextual evidence only and must not
override these desired-state files.
This is source/dry-run support only. It does not prove a registry image exists, does not build, pull, push, apply, restart, or touch PROD, and must not be used as M3 DEV-LIVE evidence.
D601 Native k3s Guard
DEV deploy and smoke commands must target D601 native k3s with
KUBECONFIG=/etc/rancher/k3s/k3s.yaml. Do not use the default kubeconfig if it
points at docker-desktop, desktop-control-plane, or 127.0.0.1:11700.
Control-plane confusion is tracked in
pikasTech/unidesk#138.
Next DEV deploy smoke commands, for a separately authorized deployment task:
npm run check
node -e "JSON.parse(require('node:fs').readFileSync('deploy/deploy.json','utf8'))"
KUBECONFIG=/etc/rancher/k3s/k3s.yaml kubectl apply --dry-run=server -k deploy/k8s/dev
curl -fsS http://74.48.78.17:16667/health/live
node scripts/dev-edge-health-smoke.mjs --live --write-report
Do not run PROD deployment or substitute UniDesk backend, provider-gateway, or microservice proxy for HWLAB runtime services.