[{"data":1,"prerenderedAt":609},["ShallowReactive",2],{"navigation_docs":3,"-apps-deployment-push-to-deploy":213,"-apps-deployment-push-to-deploy-surround":604},[4,142],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":36},"Kinotic Apps","i-lucide-rocket","\u002Fapps","01.apps",[10,14,18,37,58,91,102,122,127],{"title":11,"path":12,"stem":13},"Introduction","\u002Fapps\u002Fintroduction","01.apps\u002F01.introduction",{"title":15,"path":16,"stem":17},"Quick Start","\u002Fapps\u002Fquick-start","01.apps\u002F02.quick-start",{"title":19,"icon":20,"path":21,"stem":22,"children":23,"page":36},"Application Structure","i-lucide-folder-tree","\u002Fapps\u002Fapplication-structure","01.apps\u002F03.application-structure",[24,28,32],{"title":25,"path":26,"stem":27},"Overview","\u002Fapps\u002Fapplication-structure\u002Foverview","01.apps\u002F03.application-structure\u002F01.overview",{"title":29,"path":30,"stem":31},"Applications and Projects","\u002Fapps\u002Fapplication-structure\u002Fapplications-and-projects","01.apps\u002F03.application-structure\u002F02.applications-and-projects",{"title":33,"path":34,"stem":35},"Artifact Types","\u002Fapps\u002Fapplication-structure\u002Fartifact-types","01.apps\u002F03.application-structure\u002F03.artifact-types",false,{"title":38,"icon":39,"path":40,"stem":41,"children":42,"page":36},"Services","i-lucide-network","\u002Fapps\u002Fservices","01.apps\u002F04.services",[43,46,50,54],{"title":25,"path":44,"stem":45},"\u002Fapps\u002Fservices\u002Foverview","01.apps\u002F04.services\u002F01.overview",{"title":47,"path":48,"stem":49},"Publishing Services","\u002Fapps\u002Fservices\u002Fpublishing-services","01.apps\u002F04.services\u002F02.publishing-services",{"title":51,"path":52,"stem":53},"Service Proxies","\u002Fapps\u002Fservices\u002Fservice-proxies","01.apps\u002F04.services\u002F03.service-proxies",{"title":55,"path":56,"stem":57},"Streaming","\u002Fapps\u002Fservices\u002Fstreaming","01.apps\u002F04.services\u002F04.streaming",{"title":59,"icon":60,"path":61,"stem":62,"children":63,"page":36},"Persistence","i-lucide-database","\u002Fapps\u002Fpersistence","01.apps\u002F05.persistence",[64,67,71,75,79,83,87],{"title":25,"path":65,"stem":66},"\u002Fapps\u002Fpersistence\u002Foverview","01.apps\u002F05.persistence\u002F01.overview",{"title":68,"path":69,"stem":70},"Defining Entities","\u002Fapps\u002Fpersistence\u002Fdefining-entities","01.apps\u002F05.persistence\u002F02.defining-entities",{"title":72,"path":73,"stem":74},"Entity Decorators","\u002Fapps\u002Fpersistence\u002Fentity-decorators","01.apps\u002F05.persistence\u002F03.entity-decorators",{"title":76,"path":77,"stem":78},"CRUD Operations","\u002Fapps\u002Fpersistence\u002Fcrud-operations","01.apps\u002F05.persistence\u002F04.crud-operations",{"title":80,"path":81,"stem":82},"Named Queries","\u002Fapps\u002Fpersistence\u002Fnamed-queries","01.apps\u002F05.persistence\u002F05.named-queries",{"title":84,"path":85,"stem":86},"Multi-Tenancy","\u002Fapps\u002Fpersistence\u002Fmulti-tenancy","01.apps\u002F05.persistence\u002F06.multi-tenancy",{"title":88,"path":89,"stem":90},"Migrations","\u002Fapps\u002Fpersistence\u002Fmigrations","01.apps\u002F05.persistence\u002F07.migrations",{"title":92,"icon":93,"path":94,"stem":95,"children":96,"page":36},"Security","i-lucide-shield-check","\u002Fapps\u002Fsecurity","01.apps\u002F06.security",[97],{"title":98,"path":99,"stem":100,"icon":101},"Authentication","\u002Fapps\u002Fsecurity\u002Fauthentication","01.apps\u002F06.security\u002F01.authentication","i-lucide-key-round",{"title":103,"icon":104,"path":105,"stem":106,"children":107,"page":36},"Deployment","i-lucide-cloud-upload","\u002Fapps\u002Fdeployment","01.apps\u002F07.deployment",[108,113,118],{"title":109,"path":110,"stem":111,"icon":112},"Deployment Workflow","\u002Fapps\u002Fdeployment\u002Fworkflow","01.apps\u002F07.deployment\u002F01.workflow","i-lucide-git-branch",{"title":114,"path":115,"stem":116,"icon":117},"Environments","\u002Fapps\u002Fdeployment\u002Fenvironments","01.apps\u002F07.deployment\u002F02.environments","i-lucide-server",{"title":119,"path":120,"stem":121,"icon":6},"Push to Deploy","\u002Fapps\u002Fdeployment\u002Fpush-to-deploy","01.apps\u002F07.deployment\u002F03.push-to-deploy",{"title":123,"path":124,"stem":125,"icon":126},"CLI Reference","\u002Fapps\u002Fcli-reference","01.apps\u002F08.cli-reference","i-lucide-terminal",{"title":128,"icon":129,"path":130,"stem":131,"children":132,"page":36},"Reference","i-lucide-book-open","\u002Fapps\u002Freference","01.apps\u002F09.reference",[133,138],{"title":134,"path":135,"stem":136,"icon":137},"Decorators Reference","\u002Fapps\u002Freference\u002Fdecorators","01.apps\u002F09.reference\u002F01.decorators","i-lucide-at-sign",{"title":139,"path":140,"stem":141,"icon":60},"Migration SQL Grammar","\u002Fapps\u002Freference\u002Fmigration-sql-grammar","01.apps\u002F09.reference\u002F02.migration-sql-grammar",{"title":143,"icon":117,"path":144,"stem":145,"children":146,"page":36},"Kinotic OS","\u002Fplatform","02.platform",[147,152,156,161,166,171,175,180,185,190,195],{"title":148,"path":149,"stem":150,"icon":151},"System Architecture","\u002Fplatform\u002Farchitecture","02.platform\u002F01.architecture","i-lucide-boxes",{"title":153,"path":154,"stem":155,"icon":6},"Deployment Guide","\u002Fplatform\u002Fdeployment-guide","02.platform\u002F02.deployment-guide",{"title":157,"path":158,"stem":159,"icon":160},"Configuration","\u002Fplatform\u002Fconfiguration","02.platform\u002F03.configuration","i-lucide-settings",{"title":162,"path":163,"stem":164,"icon":165},"Organization Management","\u002Fplatform\u002Forganization-management","02.platform\u002F04.organization-management","i-lucide-building",{"title":167,"path":168,"stem":169,"icon":170},"System Security","\u002Fplatform\u002Fsystem-security","02.platform\u002F05.system-security","i-lucide-shield",{"title":172,"path":173,"stem":174,"icon":93},"Defense in Depth","\u002Fplatform\u002Fdefense-in-depth","02.platform\u002F06.defense-in-depth",{"title":176,"path":177,"stem":178,"icon":179},"MCP Tools","\u002Fplatform\u002Fmcp-tools","02.platform\u002F07.mcp-tools","i-lucide-bot",{"title":181,"path":182,"stem":183,"icon":184},"Observability","\u002Fplatform\u002Fobservability","02.platform\u002F08.observability","i-lucide-activity",{"title":186,"path":187,"stem":188,"icon":189},"Contributing","\u002Fplatform\u002Fcontributing","02.platform\u002F09.contributing","i-lucide-git-pull-request",{"title":191,"path":192,"stem":193,"icon":194},"System Migrations","\u002Fplatform\u002Fsystem-migrations","02.platform\u002F10.system-migrations","i-lucide-database-zap",{"title":128,"icon":129,"path":196,"stem":197,"children":198,"page":36},"\u002Fplatform\u002Freference","02.platform\u002F11.reference",[199,204,209],{"title":200,"path":201,"stem":202,"icon":203},"CRI Format","\u002Fplatform\u002Freference\u002Fcri-format","02.platform\u002F11.reference\u002F01.cri-format","i-lucide-link",{"title":205,"path":206,"stem":207,"icon":208},"Grind Jobs","\u002Fplatform\u002Freference\u002Fgrind-jobs","02.platform\u002F11.reference\u002F02.grind-jobs","i-lucide-workflow",{"title":210,"path":211,"stem":212,"icon":151},"Project Publishing Design","\u002Fplatform\u002Freference\u002Fproject-publishing-design","02.platform\u002F11.reference\u002F03.project-publishing-design",{"id":214,"title":119,"body":215,"description":597,"extension":598,"links":599,"meta":600,"navigation":601,"path":120,"seo":602,"stem":121,"__hash__":603},"docs\u002F01.apps\u002F07.deployment\u002F03.push-to-deploy.md",{"type":216,"value":217,"toc":584},"minimark",[218,222,231,234,238,241,286,289,292,298,346,375,378,382,385,392,395,399,402,452,456,459,509,512,515,519,522,563,566,570,573,577],[219,220,25],"h2",{"id":221},"overview",[223,224,225,226,230],"p",{},"Every Kinotic project is backed by a git repository, and pushing to that repository's\n",[227,228,229],"strong",{},"default branch"," deploys the project. There is no CI to configure and no pipeline file to\nmaintain — the platform is the pipeline. Each qualifying push is verified, built, and\ndeployed as a tracked job you can watch live.",[223,232,233],{},"Only pushes to the default branch deploy. Pushes to other branches, branch deletions, and\ntag operations are ignored.",[219,235,237],{"id":236},"what-a-deployment-does","What a deployment does",[223,239,240],{},"A deployment runs as a job with six steps, visible with live progress on the project's\nDeployment page (and, like any job, on the Jobs page):",[242,243,244,251,268,274,280],"ol",{},[245,246,247,250],"li",{},[227,248,249],{},"Resolve deployment target"," — the first deployment picks a node with capacity and\ncreates the project's checkout directory on it; later deployments reuse the same node\nand directory.",[245,252,253,256,257,262,263,267],{},[227,254,255],{},"Sync project source"," — a short-lived, sandboxed build VM brings the checkout to the\npushed commit (an incremental fetch, not a fresh clone — installs stay warm), installs\ndependencies, finds the ",[258,259,261],"a",{"href":260},"#artifacts","artifacts"," the commit contains, and compiles the\nproject. This step is the build gate: a commit that does not build, or whose packages\nare not named validly, never reaches your running services. Your entity definitions are\nsynchronized and published here, so an entity added in this commit has its backing\nstorage created and is ready for data operations; entities already published keep\nserving. Pending migrations in ",[264,265,266],"code",{},".\u002Fmigrations"," are applied in the same step. The\nartifacts it found are reported to the platform, and only after everything succeeded\ndoes it signal the runtime to reload. The step expands on the job run page into the\nbuild VM's log, live while it runs; the VM is kept after its run, whatever the outcome,\nso the log stays readable until the next deployment retires it.",[245,269,270,273],{},[227,271,272],{},"Resolve artifacts"," — binds the artifacts the build VM reported for this commit into\nthe deployment run. The step's row on the job run page lists them: each microservice\nwith the module it starts from, and each UI.",[245,275,276,279],{},[227,277,278],{},"Ensure runtime workloads"," — one long-lived VM per microservice the commit contains,\neach running that microservice from the checkout (mounted read-only) with its own machine\nidentity. The first deployment of a microservice starts its VM. Later deployments leave a\nrunning VM alone: its supervisor sees the reload signal and restarts the service onto the\nnew commit. A VM that was stopped or has crashed, or whose entry module the commit moved,\nis retired and replaced by a fresh one, never started again with the state that may have\nfailed it. A microservice the commit no longer contains keeps its VM running but its\ndeployment is marked orphaned, and a commit that brings it back adopts the VM; the\ndeployment is only ever destroyed on request. A microservice that cannot be left running\nis recorded failed with the reason, the others still deploy, and the step fails naming it.",[245,281,282,285],{},[227,283,284],{},"Publish UIs"," — uploads every UI the build VM built to your organization's storage\nthrough a short-lived publish VM that holds nothing but an upload URL valid for the run,\nthen records each UI's site. The storage was created with your organization, so the step\nonly reads it; a UI's first publish mints its site's hostname and creates the site, which\nis the one slow step a deployment ever takes on the platform's cloud, and later publishes\nkeep the site and switch it to the new commit. A UI the commit no longer\ncontains keeps serving but its deployment is marked orphaned, and a commit that brings it\nback adopts the site. The step expands on the job run page into the publish VM's log.",[223,287,288],{},"The runtime supervisor restarts your services as whole processes, with escalating backoff\nif they crash immediately after a reload.",[219,290,291],{"id":261},"Artifacts",[223,293,294,295,297],{},"A project repository is a Bun workspace, and every deployment finds the\n",[258,296,261],{"href":34}," it contains by where each package\nsits in the tree. Two kinds are deployed today:",[299,300,301,327],"ul",{},[245,302,303,304,307,308,311,312,315,316,319,320,322,323,326],{},"A ",[227,305,306],{},"microservice"," is a directory directly under ",[264,309,310],{},"packages\u002Fmicroservices"," holding a\n",[264,313,314],{},"package.json",". Its entry module is the ",[264,317,318],{},"main"," of that ",[264,321,314],{},", or ",[264,324,325],{},"src\u002Fmain.ts","\nwhen it declares none.",[245,328,303,329,307,332,335,336,338,339,342,343,345],{},[227,330,331],{},"UI",[264,333,334],{},"packages\u002Fui"," whose ",[264,337,314],{}," declares a\n",[264,340,341],{},"build"," script. A package under ",[264,344,334],{}," without one is a library, not a UI, and\nis left alone.",[223,347,348,349,352,353,355,356,359,360,363,364,367,368,371,372,374],{},"An artifact's identity is the unscoped part of the ",[264,350,351],{},"name"," in its ",[264,354,314],{},":\n",[264,357,358],{},"@acme\u002Forders"," is the microservice ",[264,361,362],{},"orders",", ",[264,365,366],{},"@acme\u002Fadmin"," the UI ",[264,369,370],{},"admin",". The directory\nname never matters, so a package can be moved or its directory renamed without changing\nwhat the platform knows it as. The unscoped name must be lowercase letters, digits, and\ninterior dashes, and two artifacts of the same kind cannot share one; either problem fails\nthe deployment in the build VM with a message in its log naming the package. Nested\n",[264,373,314],{}," files deeper in a package are never artifacts of their own.",[223,376,377],{},"The artifacts are found inside the build VM, over the checked-out commit, and recorded on\nthe project's deployment together with the commit they were found in.",[219,379,381],{"id":380},"machine-identities","Machine identities",[223,383,384],{},"Every VM connects to Kinotic as a machine identity the deployment provisions for the project,\none for the build VM and one per microservice, recorded with the deployment. They are\norganization-scope: synchronizing entity definitions and publishing services into your\napplication's zone are things your organization does on its own behalf, so an identity scoped\nto a single application would not be enough to do either. The project's Deployment page lists\nthem, so you can see which credentials exist for a project and what each one is used for.",[223,386,387,388,391],{},"Kinotic stores only a hash of a machine's secret, so a secret can never be handed out a\nsecond time. Every deployment therefore issues the build VM a ",[227,389,390],{},"new"," secret, and the one\nthe previous build used stops working at that moment. A microservice's secret is issued\nwhen its VM is created and stays valid for that VM's life — a later deployment reloads\nthe service inside the running VM rather than replacing it.",[223,393,394],{},"A project's machines can be disabled or removed like any other machine, which cuts the\ncorresponding workload off at its next connection. Removing one is not permanent damage: the\nnext deployment provisions a replacement.",[219,396,398],{"id":397},"microservices","Microservices",[223,400,401],{},"The project's Deployment page lists each microservice the deployment has ensured: its status,\nthe commit it was last ensured for, the module it runs, and its workload. From there you can\nopen the microservice's log, restart its VM in place, or remove the deployment. Removing\ndestroys the VM and its machine identity and forgets the record; a microservice the current\ncommit still contains comes back with the next deployment, so removal is mainly how an\norphaned microservice, one a commit dropped, is finally retired.",[403,404,405,418],"table",{},[406,407,408],"thead",{},[409,410,411,415],"tr",{},[412,413,414],"th",{},"Status",[412,416,417],{},"Meaning",[419,420,421,432,442],"tbody",{},[409,422,423,429],{},[424,425,426],"td",{},[264,427,428],{},"DEPLOYED",[424,430,431],{},"The VM is up and running the microservice as of the ensured commit",[409,433,434,439],{},[424,435,436],{},[264,437,438],{},"FAILED",[424,440,441],{},"The last deployment could not leave the microservice running; the message says why",[409,443,444,449],{},[424,445,446],{},[264,447,448],{},"ORPHANED",[424,450,451],{},"The last deployed commit no longer contains the microservice; the VM keeps running until removed",[219,453,455],{"id":454},"uis","UIs",[223,457,458],{},"Each UI is served from its own site under the platform's sites domain, at a hostname the\nfirst publish mints from your organization, application and UI names. The site serves the\nUI as of the commit recorded on its deployment, and a publish switches it atomically: the\nnew commit's assets are uploaded first, under a path named by the commit and cached for a\nyear, and the site's index is replaced last.",[403,460,461,469],{},[406,462,463],{},[409,464,465,467],{},[412,466,414],{},[412,468,417],{},[419,470,471,481,491,500],{},[409,472,473,478],{},[424,474,475],{},[264,476,477],{},"PROVISIONING",[424,479,480],{},"The site is being created: its hostname is registered, its certificate issued, and it does not yet serve the recorded commit",[409,482,483,488],{},[424,484,485],{},[264,486,487],{},"READY",[424,489,490],{},"The site serves the UI as of the recorded commit",[409,492,493,497],{},[424,494,495],{},[264,496,448],{},[424,498,499],{},"The last deployed commit no longer contains the UI; the site keeps serving until removed",[409,501,502,506],{},[424,503,504],{},[264,505,438],{},[424,507,508],{},"The site could not be created; the message says why",[223,510,511],{},"A failed site can be provisioned again, which completes whatever the earlier attempt left\nmissing. Removing a UI deployment takes its site down, deletes the UI's published files and\ndeletes the record; a UI the current commit still contains comes back with the next\ndeployment, at a site minted anew. Deleting the project removes every one of its UI\ndeployments the same way.",[223,513,514],{},"The project's deployment page lists each UI with its site, status and the commit the site\nserves, and offers both actions; the project's and the application's overview pages list the\npublished UIs with their sites as well.",[219,516,518],{"id":517},"deployment-status","Deployment status",[223,520,521],{},"The project's deployment record tracks one status at a time:",[403,523,524,532],{},[406,525,526],{},[409,527,528,530],{},[412,529,414],{},[412,531,417],{},[419,533,534,544,554],{},[409,535,536,541],{},[424,537,538],{},[264,539,540],{},"DEPLOYING",[424,542,543],{},"A deployment job is running for the latest qualifying push",[409,545,546,551],{},[424,547,548],{},[264,549,550],{},"RUNNING",[424,552,553],{},"The recorded commit built successfully and every microservice's VM is serving it",[409,555,556,560],{},[424,557,558],{},[264,559,438],{},[424,561,562],{},"The last deployment failed; the reason is recorded on the status",[223,564,565],{},"The project's Deployment page shows this status alongside the deployed commit and the\nmost recent deployment job's steps, live while a deployment runs — so it always answers\nexactly what the last push did, step by step.",[219,567,569],{"id":568},"failure-behavior","Failure behavior",[223,571,572],{},"A failed build fails the deployment and leaves the previously deployed commit running —\nthe runtime VMs are only ever signaled after a successful sync. The build VM of a failed sync\nis kept (not discarded) so its logs can be inspected from the workload logs view; it is\ncleaned up on the next successful deployment of the project.",[219,574,576],{"id":575},"concurrent-pushes","Concurrent pushes",[223,578,579,580,583],{},"Deployments are serialized per project with ",[227,581,582],{},"latest-wins",": pushes arriving while a\ndeployment is running collapse to the newest commit, which deploys next. Intermediate\ncommits are skipped rather than queued — the checkout converges to the newest push, and\neach skipped commit is still reachable in git history. Redeliveries of the same push are\nharmless: syncing a commit twice converges to the same checkout.",{"title":585,"searchDepth":586,"depth":586,"links":587},"",2,[588,589,590,591,592,593,594,595,596],{"id":221,"depth":586,"text":25},{"id":236,"depth":586,"text":237},{"id":261,"depth":586,"text":291},{"id":380,"depth":586,"text":381},{"id":397,"depth":586,"text":398},{"id":454,"depth":586,"text":455},{"id":517,"depth":586,"text":518},{"id":568,"depth":586,"text":569},{"id":575,"depth":586,"text":576},"How a git push to your project's repository becomes a running deployment.","md",null,{},{"icon":6},{"title":119,"description":597},"ArIe3lXewlLUGOLQSy7wlwDoNGPQCu58C1PQiO97Y20",[605,607],{"title":114,"path":115,"stem":116,"description":606,"icon":117,"children":-1},"Development, staging, and production environment configuration.",{"title":123,"path":124,"stem":125,"description":608,"icon":126,"children":-1},"Command reference for the Kinotic CLI.",1788549866821]