ReadonlybackendOptional ReadonlyclockOptional ReadonlyfinalizedReadonlyinitialOptional ReadonlyrouteTuning for the convergence wait the ready-commit attestation performs. The defaults suit every provider this package targets.
ReadonlysecretsReadonlyspecReadonlystore
The execution-fence state this deployment is born in. REQUIRED; no default.
It lives on the OPTIONS and deliberately not on
DeploymentSpec. The spec is the digested canonical description of a deployment (deploymentSpecDigest), and every stored record, drift audit, and migration decision compares against that digest — adding a field to it would change the digest of every deployment already in the fleet and present as fleet-wide drift, scheduling migrations for artifacts nobody touched.It is also provisioning-time-only by nature: after the first pass the fence is live operational state an operator moves through
POST /admin/execution-fence, somigrateFleet,rollbackExternalReleaseanddecommissionDeploymentneither take it nor need it — re-seeding is INSERT-if-absent and can only ever repair a missing row.