From 3b189a53f3a81e2e1fd1f976f05f03b5701a0ae1 Mon Sep 17 00:00:00 2001 From: marcopiraccini Date: Wed, 1 Jul 2026 15:05:39 +0200 Subject: [PATCH 1/2] supports for ICC managed deployment Signed-off-by: marcopiraccini --- README.md | 34 +++++++++++++++++++++++ cli/deploy.js | 40 ++++++++++++++++++++++++--- lib/icc.js | 75 +++++++++++++++++++++++++++++++++++++++++++++++++++ 3 files changed, 146 insertions(+), 3 deletions(-) create mode 100644 lib/icc.js diff --git a/README.md b/README.md index 05457cd..7921116 100644 --- a/README.md +++ b/README.md @@ -232,6 +232,40 @@ Deploy with an environment file: desk deploy --profile --dir ./my-watt-project --envfile ./my-watt-project/.env ``` +#### Deploy through ICC's deploy API (`--via-icc`) + +By default `desk` templates the Deployment + Service and applies them directly +(the skew-protection `observe` model: you create the workload, ICC manages +routing). Use `--via-icc` to instead drive the deploy through ICC's deploy API, +which lets you exercise the `manage` and `advise` actuation modes: + +```sh +desk deploy --profile skew-protection --via-icc \ + --app-id --deploy-token plt_deploy_... \ + --image --version v1 --min-replicas 1 +``` + +What happens depends on the app's mode (Settings → Skew Protection → Mode): + +* `manage` — ICC creates the Deployment + Service itself; `desk` applies nothing. +* `advise` — ICC returns the manifests as a plan and `desk` applies them with + `kubectl` (use `--dry-run` to print the plan without applying). +* `observe` — ICC rejects the deploy API (this is the default direct path above). + +Flags: + +* `--app-id` — the ICC application UUID (from the app URL `…/watts/`). Required. +* `--deploy-token` — a scoped deploy token (`plt_deploy_…`), or set + `PLT_DEPLOY_TOKEN`. Mint one in the app's Settings → Deploy Tokens. Required. +* `--icc-url` — ICC base URL (default `https://icc.plt`). TLS verification is + disabled for this call (local self-signed cert); for local testing only. + +`--via-icc` still builds/pushes the image when `--dir` is used; the image must +exist before ICC can reference it (`--image ` for a prebuilt one). `manage` +mode also requires the `plt-pod-manager` RBAC to create Deployments/Services +(shipped in the helm chart; run `helm upgrade`). See +`skew-protection/TESTING.md` for the full manual test walkthrough. + ## Troubleshooting Use `DEBUG=plt-desk*` to view debug statements. The output can be narrowed down diff --git a/cli/deploy.js b/cli/deploy.js index fecece2..6e77366 100644 --- a/cli/deploy.js +++ b/cli/deploy.js @@ -6,13 +6,14 @@ import { loadContext } from '../lib/context.js' import { error, info } from '../lib/utils.js' import * as registry from '../lib/registry.js' import * as deploy from '../lib/deploy.js' +import { deployViaIcc, handleIccDeploy } from '../lib/icc.js' import { getClusterStatus } from '../lib/cluster/index.js' export const options = { command: 'deploy', strict: true } export default async function cli (argv) { const args = minimist(argv, { - bool: ['dry-run', 'headless'], + bool: ['dry-run', 'headless', 'via-icc'], string: [ 'dir', 'image', @@ -24,7 +25,10 @@ export default async function cli (argv) { 'replicas', 'min-replicas', 'max-replicas', - 'npmrc' + 'npmrc', + 'app-id', + 'deploy-token', + 'icc-url' ], alias: { dir: 'd', @@ -36,7 +40,8 @@ export default async function cli (argv) { hostname: 'h' }, default: { - namespace: 'platformatic' + namespace: 'platformatic', + 'icc-url': 'https://icc.plt' } }) @@ -117,6 +122,35 @@ export default async function cli (argv) { } } + // ICC-driven deploy: hand the image to ICC's deploy API and let the app's + // actuation mode decide (manage = ICC creates the workload; advise = ICC + // returns manifests that desk applies). This is the CI path a customer uses, + // and the way to exercise manage/advise modes end to end. + if (args['via-icc']) { + const appId = args['app-id'] + const token = args['deploy-token'] || process.env.PLT_DEPLOY_TOKEN + if (!appId) { error('--via-icc requires --app-id '); process.exit(1) } + if (!token) { error('--via-icc requires --deploy-token or PLT_DEPLOY_TOKEN'); process.exit(1) } + if (!version) { error('--via-icc requires --version