Write your own blueprints
What a blueprint template is, why authoring one is safe to delegate, and the ways to publish it.
Every blueprint is one document, a template, written in YAML or JSON:
apiVersion: blueprints.stackship.se/v2, kind: BlueprintTemplate. It declares what the deployer
fills in, which managed resources to provision, and the container instance to create. The format is
described field by field in Template format and Parameters.
What a template can express
A template renders into a container instance and nothing else, in the same shape the Container Instances API accepts, plus managed resources of the types the platform offers. There is no raw Kubernetes in it: it cannot describe a privileged pod, a host path or an access-control object, because the document has nowhere to put them. A deploy is checked against the deployer's own permissions for everything it creates.
That does not make a template harmless to deploy. Its images run with access granted by the
deployer's permissions: the deploy gives the instance's identity Secrets Reader on the instance
vault, the only vault a secretRef may name. Publishing a template, with blueprints/templates/write, therefore decides what deployers in
the boundary expose to code they did not write — see
How a deploy runs.
Parsing is strict. An unknown or misspelled field is an error, not something silently ignored, so a template that validates means what it says.
Two kinds of placeholder
[%name%]tokens are filled in at deploy time, from the parameters, the instance name and the vault name. They are how one template serves many instances.{{domain_suffix}}and{{cert_issuer}}are filled in once, when the platform reads a template from a repository, with the platform's app domain and certificate issuer.
Both are described in Tokens and Platform values.
Where templates are published
| Way | Reaches | How |
|---|---|---|
| A git repository connected as a catalog source | The boundary | One directory per blueprint — Catalog sources |
| The templates API | The boundary | One document per request — Publish templates with the API |
| The platform catalog repository | Every boundary | Chosen by the platform administrator — Platform catalog repository |
A boundary's blueprints are listed only in that boundary. A slug the platform catalog uses cannot be used in a boundary. A catalog source cannot publish a slug that is already taken in the boundary; saving a template through the API replaces the boundary's blueprint with that slug — one a catalog source publishes only until the source's next sync.