kindgi deploy
Deploy a signed pack image to Kindgi. Reads deploy-envelope.json (or runs kindgi build inline) + POSTs to /v1/deployments.
kindgi deploy [--env <name>] [--from-envelope <path>] [--endpoint <url>] [--token <bearer>] [--tenant <id>] [--idempotency-key <str>] [--dry-run] [--sync-secrets] [--allow-missing-env] [--target <t>] [--build-endpoint <url>] [--out <dir>] [--artifact-version <v>] [--published-at <iso>] [--signing-key <path>] [--signer-key-id <id>] [--registry-push-creds <ref>] [--skip-integrity-gate] [--skip-image-pull] [--skip-sign] [--path <dir>]Flags:
--allow-missing-env: Deploy, with a warning, even when a name in the pack'senv.requiredhas no value for--env.--artifact-version <value>: For an inline build: the artifact version. Default: today's date asYYYYMMDD.1(UTC).--build-endpoint <value>: For an inline build: the build server (kindgi build --endpoint). Default: the env block'sbuild.--dry-run: Print the equivalentcurlrequest instead of sending it. A missing envelope is still built first.--endpoint <value>: The API to deploy to. Default: the env block'sendpoint, else the CLI's API URL (--url,KINDGI_API_URL, config files).--env <value>: The environment: its block inkindgi.config.tsand its.env.<name>file. Default:staging.--from-envelope <value>: The envelope to deploy. Default:deploy-envelope.jsonin--out; when there is none,kindgi buildruns first.--idempotency-key <value>: TheIdempotency-Keyheader. Default: a hash of the request body, so the same image deployed again returns the same deployment.--out <value>: Where the envelope is looked for, and an inline build writes. Default:.kindgi/buildunder the pack root.--path <value>: The pack root. Default: the current directory.--published-at <value>: For an inline build: the publish time (ISO 8601). Default: the Unix epoch.--registry-push-creds <value>: For an inline build: a reference to the registry push credentials for the build server to use.--signer-key-id <value>: For an inline build: the key id the signature names. Default: the env block'ssignerKeyId, else the key file's name.--signing-key <value>: For an inline build: the Ed25519 private key (PEM) to sign with. Default: the env block'ssigningKey.--skip-image-pull: For an inline build: check the image's index by hash only, without pulling the image.--skip-integrity-gate: For an inline build: sign without checking the image's index against the local one.--skip-sign: For an inline build: write an unsigned envelope, which the deploy then refuses unless--dry-run.--sync-secrets: After the deploy lands, also send the values in.env.<env>to the deployment's secrets. Off by default.--target <value>: For an inline build: the build target. Default: the env block'sbuildTarget, else the env name.--tenant <value>: Refuse unless the envelope was signed for this tenant (checked before sending). Also passed to an inline build.
Every command also takes the global flags.