AI Agent Deployment Guide
Use Gordon's declarative app workflow. Do not edit daemon state or infer workload identity from domains.
Required files
~/.config/gordon/gordon.toml # Daemon configuration
app.toml # Declarative app manifest
Workflow
Define services, routes, networks, volumes, secrets, readiness, and backups in
app.toml.Validate and persist the manifest:
gordon apps apply --file app.tomlRegister required secret values without placing them in the manifest:
gordon apps secrets set APP --service SERVICE KEYDeploy the accepted revision:
gordon apps deploy APPVerify state and workload logs:
gordon apps show APP gordon apps logs APP --service SERVICE
The local CLI uses the authenticated owner-only Unix socket. To target another Gordon instance, use the configured authenticated HTTP/TLS remote transport.
Registry authentication
Generate a scoped token on the server, then pass it to the registry client through standard input. Never place tokens in manifests, command history, fixtures, or logs.
Safety rules
- Use app and service names as workload identity; domains are routing addresses only.
- Keep secret values outside manifests and app state.
- Reuse the same idempotency key only to inspect or retry the same mutation request.
- Do not delete retained volumes or secrets during app removal.