Deploy ​
| Workflow | Type | Description |
|---|---|---|
| deploy.backend.authorize_secrets | Atomic | — |
| deploy.backend.canary | Atomic | — |
| deploy.backend.cleanup | Atomic | — |
| deploy.backend.header_based | Atomic | — |
| deploy.backend.immediate | Linear | Provision backend container capacity immediately |
| deploy.backend.registry_token | Atomic | — |
| deploy.cloudrun.rollback | Dag | Restore Cloud Run traffic to a previously stable revision. |
| deploy.cloudrun.rollout-canary | Linear | Roll out a Cloud Run revision through staged traffic percentages with rollback support. |
| deploy.cloudrun.rollout-immediate | Dag | Deploy a Cloud Run revision and move all traffic to it after readiness. |
| deploy.cloudrun.teardown | Dag | Tear down a Cloud Run deployment: delete the service and (if bound) its domain mapping. Idempotent. |
| deploy.database.deprovision | Dag | Tear down a provisioned database: delete the Cloud SQL instance (cascades) and its credentials secret. Idempotent. |
| deploy.database.provision-postgres | Linear | Provision a PostgreSQL database for a deployment target using Cloud SQL primitives. |
| deploy.database.run-migrations | Linear | Run database migrations for a release through the configured runner backend. |
| deploy.domain.bind | Dag | Bind a deployed service or static target to a custom domain and DNS records. |
| deploy.domain.unbind | Dag | Reverse deploy.domain.bind: delete the Cloud Run domain mapping and (if identifiers given) the DNS record. Idempotent. |
| deploy.job.run-once | Linear | Run a single one-off command in an image through the configured runner backend (schema bootstrap, ad-hoc migration, backfill) — the flat, ceremony-free sibling of deploy.database.run-migrations that needs no deployment target or release. |
| deploy.k8s.import-cluster | Atomic | Adopt every Deployment on a Kubernetes cluster as DeploymentTargets — lists namespaces, filters out k8s internals (kube-*, default, ltinteg-system), and runs the per-namespace upsert for each. One run = full cluster onboarding. |
| deploy.k8s.import-namespace | Atomic | Adopt every Deployment in a Kubernetes namespace as a DeploymentTarget row, keyed by (cloud_connection, namespace, app_name). |
| deploy.k8s.rollout-rolling | Linear | Roll out a release to a KUBERNETES DeploymentTarget by driving k8s.app.update. |
| deploy.k8s.rollout-set-image | Linear | Roll out a release to a KUBERNETES DeploymentTarget by driving k8s.app.set-image. Helm-safe — only touches the container image. |
| deploy.k8s.sync-all | Atomic | Bulk-refresh DeploymentTarget.status / last_ready_check_at / provider_metadata for every KUBERNETES target in an org (optionally narrowed by cloud_connection or namespace). |
| deploy.k8s.sync-target-status | Atomic | Read live Deployment status for a KUBERNETES DeploymentTarget and refresh its status / last_ready_check_at / provider_metadata. |
| deploy.platform.release | Linear | Orchestrate a full LtInteg platform deployment through Deploy. |
| deploy.platform.teardown | Linear | Reverse of deploy.platform.release: best-effort teardown of domains, static sites, services (+images), and databases. |
| deploy.release.rollback | Linear | Ship the release from a previously COMPLETED DeploymentRollout back to its DeploymentTarget by dispatching the same strategy. Creates a new rollout row; logs ABORTED on the rollout being rolled away from. |
| deploy.release.start | Linear | Create a DeploymentRelease + DeploymentRollout for a target and dispatch the appropriate strategy workflow. Rejects with target_busy if another rollout is active. |
| deploy.rollout-static-bluegreen | Linear | Prepare a candidate slot and switch traffic for a static target |
| deploy.rollout-static-canary | Linear | Shift a small percentage of traffic to a staging distribution before full promotion |
| deploy.rollout-static-immediate | Linear | Promote a static release immediately to the live slot |
| deploy.service.bind-config | Atomic | Resolve deployment target, release, environment, and runtime config into a Cloud Run service contract. |
| deploy.service.bind-secrets | Linear | Materialize runtime secrets in GCP Secret Manager and grant service-account access. |
| deploy.static.build-and-publish | Linear | Build a Vite/SPA on a runner (git clone + build) and stage the built dist/ into a GCS serving bucket, emitting the bucket/prefix/static_url/bundle_ref handoff that deploy.static.publish consumes — the fully-GCP counterpart of cloudflare.pages.build-and-deploy. |
| deploy.static.publish | Dag | Publish frontend/static build artifacts through Deploy without using SPAD. |
| deploy.static.teardown | Dag | Tear down a static deploy: delete published objects under bucket/prefix and (if identifiers given) the DNS record. Idempotent. |
| deploy.target-dispatch | Linear | Dispatch queued deployments for a deployment target |
