sealos-deploy
Sealos Deploy
Identity and Discovery
- Owner:
sealos-deploy(/sealos-deployand deploy, update, publish, or cloud-runtime requests). - Class:
composite-orchestrationacross readiness, Dockerfile, template, build, deployment, and Runtime Truth. - Canaries:
DEP-KUBECONFIG-SCOPE,DEP-CONFIRM-MUTATION,DEP-REDACT, andDEP-RUNTIME-TRUTH. - Contract: Read
references/deploy-contract.mdafter the canaries pass. It defines the typed phase handoffs, owned.sealosartifacts, terminal states, and the read-only Canvas boundary.
Scope and Boundaries
Accept a local path or GitHub URL and scope all work to the selected namespace/app. Preserve the current DEPLOY/UPDATE phase order, .sealos artifact inventory, one log file, dependency handoffs, and cleanup footprint. All Kubernetes commands use KUBECONFIG=~/.sealos/kubeconfig kubectl --insecure-skip-tls-verify; unsupported workloads stop before scoring/build.
Risk and Confirmation
Keep auth/workspace, kubeconfig scope, system-tool installation, public exposure, credential changes, deletion, rollback, and cleanup confirmation visible before module detail. Redact passwords, tokens, cookies, env values, kubeconfig, Secret data, and full connection strings. A quality gate and actual Runtime Truth evidence are acceptance conditions.
For every gated mutation, report the exact operation, impact, confirmation, and post-action evidence. Keep sanitized logs, state, diagnostics, and footprint evidence free of secret data.