Engineering case study · Private source · In development

DeploymentPlatform

A backend control plane for managing deployment records, provider operations, protected inference workloads, and cost-aware lifecycle transitions.

APIPython and FastAPI
LifecycleExplicit deployment state machine
ProviderRunpod integration with adapter boundary
StorageSQLite development and PostgreSQL compatibility

Problem

Provisioning is only one step in a trustworthy deployment lifecycle.

DeploymentPlatform models the control-plane responsibilities around infrastructure: configuration, secrets, estimates, approvals, state changes, health checks, logs, usage records, and teardown. The goal is to make billable and operational transitions explicit instead of hiding them behind a single deploy action.

Lifecycle

State transitions are validated before provider actions run.

The service tracks deployments from creation through queueing, provisioning, build, startup, health checking, running, stop, restart, failure, and deletion. Invalid transitions are rejected and state changes produce operational events.

  1. Configure the project, workload, provider, compute, region, runtime, and environment.
  2. Estimate current GPU and storage cost through the provider adapter.
  3. Approve a time-limited, configuration-bound estimate before any billable provisioning.
  4. Provision and verify the workload, advancing to running only after authenticated health checks pass.
  5. Operate through logs, events, usage estimates, stop, restart, delete, and idle-stop behavior.

Engineering decisions

Cost, health, and credentials are first-class control-plane concerns.

Approval before spend

Billable provisioning requires explicit approval against a current estimate bound to the deployment configuration. Expired, changed, or previously consumed estimates are rejected.

Protected inference

The Runpod adapter provisions a bearer-authenticated gateway that accepts only approved inference routes and the configured model; Ollama remains loopback-only behind the gateway.

Encrypted secrets

Deployment secrets are encrypted at rest and are not returned by the environment API. Events and logs use redaction helpers before persistence.

Health-gated state

A deployment becomes running only after provider health checks pass. Stop, restart, delete, failure handling, and idle-stop behavior follow defined lifecycle transitions.

PythonFastAPIRunpodOllamaDockerSQLitePostgreSQLEncrypted SecretsGitHub Actions