sealos-deploy
Deploy compatible server, static-web, worker, scheduled-job, or reviewed remote-desktop workloads from GitHub or local source to Sealos Cloud, then run the default Runtime Truth Pass against the returned App URL, public route, authentication flow, logs, database state, and full resource footprint. R
By labring · 470 installs
npx skills add labring/sealos-skills --skill sealos-deploy
Source repository · Upstream listing
Sealos Deploy
Identity and Discovery
Owner: sealos deploy ( /sealos deploy and deploy, update, publish, or cloud runtime requests).
Class: composite orchestration across readiness, Dockerfile, template, build, deployment, and Runtime Truth.
Canaries: DEP KUBECONFIG SCOPE , DEP CONFIRM MUTATION , DEP REDACT , and DEP RUNTIME TRUTH .
Contract: Read [ references/deploy contract.md ](references/deploy contract.md) after the canaries pass. It defines the typed phase handoffs, owned .sealos artifacts, terminal states, and the read only Canvas boundary.
Scope and Boundaries
Accept a local path or GitHub URL and scope all work to the selected namespace/app. Preserve the current DEPLOY/UPDATE phase order, .sealos artifact inventory, one log file, dependency handoffs, and cleanup footprint. All Kubernetes commands use KUBECONFIG=~/.sealos/kubeconfig kubectl insecure skip tls verify ; unsupported workloads stop before scoring/build.
Risk and Confirmation
Keep auth/workspace, kubeconfig scope, system tool installation, public exposure, credential changes, deletion, rollback, and cleanup confirmation visible before module detail. Redact passwords, tokens, cookies, env values, kubeconfig, Secret data, and full connection strings. A quality gate and actual Runtime Truth evidence are acceptance conditions.
For every gated mutation, report the exact operation, impact, confirmation, and post action evidence. Keep sanitized logs, state, diagnostics, and footprint evidence free of secret data.
Lifecycle Workflow
For each request, run preflight/auth/workspace, detect mode, enforce eligibility, assess/detect/build or reuse, generate/validate the template, deploy or update, run Runtime Truth, and record state/cleanup evidence. Emit request scoped success , stopped , or error ; the existing phase modules below remain authoritative for detailed behavior.
Progressive Disclosure
Load modules/ and helper scripts one phase at a time after the corresponding canaries pass. Preserve typed readiness → Dockerfile → Docker to Sealos handoffs, .sealos/analysis.json , .sealos/build/build result.json , .sealos/template/index.yaml , .sealos/state.json , and delivery evidence; do not hide phase order behind a generic deploy shortcut.
Output, Stop, and Error States
success : actual returned App URL/live identity, route and port match, setup/login proof, recent logs/events, workload convergence, database/object evidence, full footprint, and saved deploy state.
stopped : unsupported eligibility, missing auth/tool, unresolved configuration, or unconfirmed public/destructive/cleanup boundary with the safe next action.
error : failed preflight, build/template/deploy/runtime/rollback/cleanup step and recovery action with sensitive values redacted.
Handoffs
Readiness, Dockerfile, and Docker to Sealos inputs use typed target , inputArtifact , allowedAction , failureReturn , and responseOwner fields. A verified deploy can hand target: sealos canvas , inputArtifact: sanitized .sealos/state.json and Runtime Truth , allowedAction: read only topology inspection , failureReturn: runtime/state diagnostic , and responseOwner: sealos deploy .
Verification
Use the existing eligibility, artifact, quality gate, footprint, live smoke, rollout, Runtime Truth, and cleanup checks. Baseline cases deploy positive runtime truth and deploy violating missing runtime proof must preserve actual App URL/live identity, auth/cleanup confirmation, log scans, and redaction.
Compatibility
Sealos auth/workspace are required for deploys. Docker, buildx, and gh CLI are required only when the selected path needs local build/push. git is required when cloning from a GitHub URL or when git metadata is needed. Node.js 18+ remains an optional accelerator. Phase 5 requires Python 3.8+ with PyYAML; root Compose conversion also requires kompose and may require crane when image tags are floating.
Brain Managed Mode
The skill has two deliberately separate execution modes:
Local mode is the existing interactive workflow. It is selected when SEALAI DEPLOY MODE is absent or has any value other than managed ; its auth, prompts, Template API flow, and output remain unchanged.
Managed mode is selected only when SEALAI DEPLOY MODE=managed . The Devbox Codex is the deployment executor: it analyzes, builds, applies, observes, diagnoses, repairs, and verifies with the injected kubeconfig. Brain is the task control plane and form owner; it is not a second Kubernetes executor.
Managed mode is non interactive. Do not start OAuth, install tools, ask for confirmation in the turn, or replace a missing callback with a file, webhook, curl request, or a Brain side apply. Before doing any work, confirm that the Codex tool registry contains both exact MCP tools template ready and deployment completed . If either tool is unavailable, stop with a managed mode fatal error; never claim a deployment result.
Brain supplies these task scoped values through the environment:
Use the injected kubeconfig/context for every Kubernetes command. Do not perform login or switch workspace. Keep the input file and kubeconfig out of prompts, logs, Timeline text, and generated artifacts; read the input file only when the managed flow says to do so.
The actual Sealos Instance name is owned by the Template/Skill path. Brain does not pre allocate it and the managed adapter does not add Brain identity labels or extraLabels .
Deploy compatible cloud workloads to Sealos Cloud, stopping unsupported targets
before build or deployment.
kubectl Safety Rules (all phases)
All kubectl commands MUST use the Sealos kubeconfig:
System tool installation requires user confirmation. If docker , gh , or kubectl is missing and the skill can install it for the current platform, ask first and only run the install command after the user explicitly replies y .
kubectl delete requires user confirmation. Before deleting any resource (deployment, service, ingress, PVC, database, etc.), always ask:
Only proceed after user confirms. This applies even if the pipeline logic suggests deletion — always ask first.
Template API cleanup must include Instance CRs. Deployments created through scripts/deploy template.mjs create instances.app.sealos.io/<app name in addition to App/workload resources. A cleanup is incomplete until instances.app.sealos.io , apps.app.sealos.io , workloads, Services, Ingresses, PVCs, and Pods are all checked.
Use this check when cleaning Template API test deployments:
Delete in this order after confirmation:
Anti example: do not report cleanup complete after only checking app,statefulset,svc,ingress,pvc,pod ; that misses instances.app.sealos.io/<app name and leaves the Sealos Instance layer dirty.
Usage
Quick Start
Execute the modules in order:
1. modules/preflight.md — Environment checks & Sealos auth
2. modules/pipeline.md — Full deployment pipeline (Phase 1–6)
3. modules/runtime truth.md — Post deploy Runtime Truth Pass (Phase 6.5)
Logging
Every run MUST write a log file at ~/.sealos/logs/deploy <YYYYMMDD HHmmss .log .
At the very start of execution , create the log file once :
Important: create the log file ONLY ONCE at the start. All subsequent writes MUST append ( ) to this same $LOG FILE . Do NOT create a second log file.
At each phase boundary , append a log entry to the same file with Bash :
On error , log the error details before stopping:
At the very end , tell the user where the log is:
Scripts
Located in scripts/ within this skill directory ( <SKILL DIR /scripts/ ):
Script Usage Purpose
workload eligibility.mjs node workload eligibility.mjs <repo dir Read only fail closed workload classification; decision is stdout only
score model.mjs node score model.mjs <repo dir Deterministic readiness scoring (0 12)
detect template.mjs node detect template.mjs [ github url <url ] work dir <repo dir skill dir <SKILL DIR Detect configured GitHub repo → Sealos template fast path matches
validate artifacts.mjs node validate artifacts.mjs dir <work dir Validate .sealos JSON artifacts against enforced schemas
detect image.mjs node detect image.mjs <github url [work dir] or node detect image.mjs <work dir Detect existing Docker/GHCR images
build push.mjs node build push.mjs <work dir <repo [ registry ghcr\ dockerhub] [ user <user ] Build amd64 image & push to the selected registry (Docker Hub path assumes a public image at deploy time; omitting registry keeps auto detect behavior)
ensure image pull secret.mjs node ensure image pull secret.mjs <namespace <secret name <image ref [deployment name] Create/update app scoped GHCR pull Secret and optionally patch an existing Deployment to reference it
gh refresh scopes.mjs node gh refresh scopes.mjs write:packages Refresh GHCR package access in the current TTY; write:packages is sufficient for both push and private pull in this workflow
deploy template.mjs node deploy template.mjs <template path [ dry run] [ args json '{"KEY":"value"}'\ args file <file ] Resolve the current region, enforce private sensitive args files on POSIX, post a local template YAML, and emit an allowlisted result with credential values redacted
managed adapter.mjs node managed adapter.mjs context\ prepare template <path \ sha256 <path \ read inputs Validate the Brain managed contract and compute the exact template SHA without injecting Instance identity or labels
sealos launchpad network.mjs node sealos launchpad network.mjs app <app app url <url [ expected port <port ] [ region <url ] [ kubeconfig <path ] Read only Launchpad public network discovery check with App URL and Service port matching
sealos footprint.mjs node sealos footprint.mjs namespace <ns app <app Read only inventory of Instance/App/workloads/Jobs/KubeBlocks/PVCs/ObjectStorageBuckets for deploy debug and cleanup planning
sealos live smoke.mjs node sealos live smoke.mjs url <url [ captcha path <path ] [ login method json token\ cookie json] [ login path <path ] [ username <user ] [ password <pass ] [ token path <path ] [ auth path <path ] [ missing api path <path ] [ missing page path <path ] Read only or credentialed HTTP smoke test for the real Sealos App entry URL, authenticated routes, and API/SPA negative probes
sealos log scan.mjs node sealos log scan.mjs namespace <ns app <app [ since 10m] [ tail 300] [ baseline <report.json\ json ] [ min window seconds 60] Read only JSON scan of Pod/init/main logs plus Warning Event convergence after readiness, login, and documented API or missing static asset checks
sealos auth.mjs node sealos auth.mjs check\ login\ list\ switch Sealos Cloud authentication & workspace switching
All scripts output JSON. Run via Bash and parse the result.
For public web applications, run sealos launchpad network.mjs before HTTP smoke. Acceptance requires ok: true , an open public network, the expected Service port, and an App URL host match. The script emits an allowlisted network summary and excludes raw Launchpad application data, environment variables, Secrets, and kubeconfig content.
Runtime Event acceptance uses two scans. Capture the first report after readiness with no baseline, wait at least 60 seconds, then pass that report through baseline for the final scan. Extend min window seconds to cover one full known reconciliation, probe, or scheduled work period. An initial Warning Event is an observation; a Warning that advances after the baseline, an unresolved referenced Secret, a Ready transition, a Pod replacement, or a restart delta is an active failure.
For intentional fault injection, retain a pre injection report as evidence. After recovery reaches Ready,