Skip to content

client.deployments

client.deployments — the deployments operations.

On AsyncKindgi every method is the same, awaited.

list(
*,
limit: int | None = None,
cursor: str | None = None,
image_ref_prefix: str | None = None,
signer_key_id: str | None = None,
timeout: float | None = None,
) -> DeploymentCollectionPage

List signed deployments. GET /v1/deployments

Cursor-paginated. Sort order: activatedAt descending (binding-defined tiebreak on deploymentId). Optional ?imageRefPrefix= narrows to deployments whose imageRef starts with the prefix; ?signerKeyId= narrows to a specific signing key (useful for revocation audits).

register(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> DeploymentRecord

Register a signed deployment. POST /v1/deployments

Atomic transaction: check the signing key against the tenant's trust list (the signingKeyRegistry binding), verify the Ed25519 signature over the canonical envelope, read the image's /app/index.json and verify it hashes to the signed indexHash and names the signed artifactVersion (ImageRegistryBinding), validate every tool / guardrail / agent / flow it declares (the image's index is what registers; the request carries none), upsert into the corresponding registries, then record the deployment. All-or-nothing rollback on any failure. Idempotency: same imageDigest re-submitted returns 200 with the existing record (no new version bump). Idempotency-Key also applies at the HTTP layer.

get(*, timeout: float | None = None) -> DeploymentRecord

Fetch a signed deployment record. GET /v1/deployments/{deploymentId}

sync_secrets(
*,
idempotency_key: str | None = None,
timeout: float | None = None,
**fields: Any,
) -> DeploymentSecretsSyncResponse

Sync secrets against a deployment. POST /v1/deployments/{deploymentId}/secrets

Deployment-scoped bulk secret sync. Body carries { envName, secrets: Array<{ name, ref } | { name, value }> }. { name, ref } entries validate against SecretBinding.get — no bytes cross the wire; missing → 404 secret-not-found. { name, value } entries write via SecretBinding.set with writeMode: add-version + tags.deployment = deploymentId and return the created reference. The write scope is derived from the deployment record itself (tenant scope, or project scope when the deployment carries a projectId) and CANNOT be overridden on the wire. Requires the secrets:write capability. Idempotency-Key applies.