Skip to content

kindgi deploy

Deploy a signed pack image to Kindgi. Reads deploy-envelope.json (or runs kindgi build inline) + POSTs to /v1/deployments.

Terminal window
kindgi deploy [--env <name>] [--from-envelope <path>] [--endpoint <url>] [--token <bearer>] [--tenant <id>] [--idempotency-key <str>] [--dry-run] [--sync-secrets] [--allow-missing-env] [--target <t>] [--build-endpoint <url>] [--out <dir>] [--artifact-version <v>] [--published-at <iso>] [--signing-key <path>] [--signer-key-id <id>] [--registry-push-creds <ref>] [--skip-integrity-gate] [--skip-image-pull] [--skip-sign] [--path <dir>]

Flags:

  • --allow-missing-env: Deploy, with a warning, even when a name in the pack's env.required has no value for --env.
  • --artifact-version <value>: For an inline build: the artifact version. Default: today's date as YYYYMMDD.1 (UTC).
  • --build-endpoint <value>: For an inline build: the build server (kindgi build --endpoint). Default: the env block's build.
  • --dry-run: Print the equivalent curl request instead of sending it. A missing envelope is still built first.
  • --endpoint <value>: The API to deploy to. Default: the env block's endpoint, else the CLI's API URL (--url, KINDGI_API_URL, config files).
  • --env <value>: The environment: its block in kindgi.config.ts and its .env.&lt;name&gt; file. Default: staging.
  • --from-envelope <value>: The envelope to deploy. Default: deploy-envelope.json in --out; when there is none, kindgi build runs first.
  • --idempotency-key <value>: The Idempotency-Key header. Default: a hash of the request body, so the same image deployed again returns the same deployment.
  • --out <value>: Where the envelope is looked for, and an inline build writes. Default: .kindgi/build under the pack root.
  • --path <value>: The pack root. Default: the current directory.
  • --published-at <value>: For an inline build: the publish time (ISO 8601). Default: the Unix epoch.
  • --registry-push-creds <value>: For an inline build: a reference to the registry push credentials for the build server to use.
  • --signer-key-id <value>: For an inline build: the key id the signature names. Default: the env block's signerKeyId, else the key file's name.
  • --signing-key <value>: For an inline build: the Ed25519 private key (PEM) to sign with. Default: the env block's signingKey.
  • --skip-image-pull: For an inline build: check the image's index by hash only, without pulling the image.
  • --skip-integrity-gate: For an inline build: sign without checking the image's index against the local one.
  • --skip-sign: For an inline build: write an unsigned envelope, which the deploy then refuses unless --dry-run.
  • --sync-secrets: After the deploy lands, also send the values in .env.&lt;env&gt; to the deployment's secrets. Off by default.
  • --target <value>: For an inline build: the build target. Default: the env block's buildTarget, else the env name.
  • --tenant <value>: Refuse unless the envelope was signed for this tenant (checked before sending). Also passed to an inline build.

Every command also takes the global flags.