client.deployments
client.deployments — the deployments operations.
On AsyncKindgi every method is the same, awaited.
client.deployments.list()
Section titled “client.deployments.list()”list( *, limit: int | None = None, cursor: str | None = None, image_ref_prefix: str | None = None, signer_key_id: str | None = None, timeout: float | None = None,) -> DeploymentCollectionPageList signed deployments. GET /v1/deployments
Cursor-paginated. Sort order: activatedAt descending (binding-defined tiebreak on deploymentId). Optional ?imageRefPrefix= narrows to deployments whose imageRef starts with the prefix; ?signerKeyId= narrows to a specific signing key (useful for revocation audits).
client.deployments.register()
Section titled “client.deployments.register()”register( *, idempotency_key: str | None = None, timeout: float | None = None, **fields: Any,) -> DeploymentRecordRegister a signed deployment. POST /v1/deployments
Atomic transaction: check the signing key against the tenant's trust list (the signingKeyRegistry binding), verify the Ed25519 signature over the canonical envelope, read the image's /app/index.json and verify it hashes to the signed indexHash and names the signed artifactVersion (ImageRegistryBinding), validate every tool / guardrail / agent / flow it declares (the image's index is what registers; the request carries none), upsert into the corresponding registries, then record the deployment. All-or-nothing rollback on any failure. Idempotency: same imageDigest re-submitted returns 200 with the existing record (no new version bump). Idempotency-Key also applies at the HTTP layer.
client.deployments.get()
Section titled “client.deployments.get()”get(*, timeout: float | None = None) -> DeploymentRecordFetch a signed deployment record. GET /v1/deployments/{deploymentId}
client.deployments.sync_secrets()
Section titled “client.deployments.sync_secrets()”sync_secrets( *, idempotency_key: str | None = None, timeout: float | None = None, **fields: Any,) -> DeploymentSecretsSyncResponseSync secrets against a deployment. POST /v1/deployments/{deploymentId}/secrets
Deployment-scoped bulk secret sync. Body carries { envName, secrets: Array<{ name, ref } | { name, value }> }. { name, ref } entries validate against SecretBinding.get — no bytes cross the wire; missing → 404 secret-not-found. { name, value } entries write via SecretBinding.set with writeMode: add-version + tags.deployment = deploymentId and return the created reference. The write scope is derived from the deployment record itself (tenant scope, or project scope when the deployment carries a projectId) and CANNOT be overridden on the wire. Requires the secrets:write capability. Idempotency-Key applies.