strata

Getting Started:

  • strata
    • Table of Contents
    • Key Features
    • Prerequisites
    • Installation
    • Quick Start
    • Configuration
    • CLI Reference
    • AI Integration via MCP
    • Deployment Workflow
    • Testing
    • Troubleshooting
      • Inspecting Resolved Values Before Deploy
      • Using Dry-Run to Validate Deployment
      • Debugging a Failed Deployment
    • Contributing
    • Security
    • License
    • Acknowledgments
    • Contact
    • Glossary
    • Core Concepts
      • Separation of Concerns
      • Version Control Everything
      • Declarative Configuration
      • Audit Trail
  • Documentation Index
    • 🚀 Getting Started
    • ďż˝ Reference
    • �📖 User Guides
      • Core Concepts
      • Operational Guides
      • Advanced Topics
    • 🏗️ Architecture & Design Decisions
      • Decision Records (ADRs)
    • đź’» Developer Documentation
      • Extension (VS Code)
      • CLI (Python)
      • Contributing
    • 📚 Examples & Tutorials
    • đź”— External Resources
      • Related Technologies
      • Community & Support
    • đź“‹ Version-Specific Documentation
      • Current Version (v0.16.1)
    • 🎯 Quick Navigation by Use Case
      • “I’m new to strata”
      • “I’m using the CLI”
      • “I’m using the VS Code Extension”
      • “I want to contribute”
      • “I have a question or issue”
      • “I need to integrate with strata”
    • đź“„ File Structure
    • 🔍 Search Tips
    • 📞 Support & Feedback
  • Strata Glossary
    • Core Concepts
      • Configuration
      • Workspace
      • Deployment
      • Environment
      • Tenant
      • Module
      • Resource
      • Provider
      • Namespace
      • Remote
      • Provisioner
      • Network
      • Firewall
      • Manifest / Deployment Manifest
    • Configuration Schema Concepts (ADR 0001)
      • apiVersion
      • kind
      • meta
      • spec
    • Layering & Multi-Tenancy Concepts (ADR 0003)
      • Layer
      • Layering
    • State & Audit Concepts
      • Drift
      • Deployment Manifest
      • Promotion Record
      • SBOM (Software Bill of Materials)
    • Promotion Concepts (ADR 0011)
      • Ring
      • Progression
      • Strategy
      • Wave
      • Scope
      • Gate
      • Promotion Target
      • Version-Lock
    • Integration & Backend Concepts
      • Integration
      • Backend
    • Operational Concepts
      • Solution
      • Profile

VS Code Extension:

  • VS Code Extension
  • Publishing
    • Automated publishing (CI)
      • Adding the VSCE_PAT secret
    • Manual publishing
    • Bumping the extension version
    • Verifying a release
  • Installation
    • From the Marketplace
    • From source
    • Requirements
    • Activation
    • Settings
  • Features
    • Activity Bar
      • Status Bar
    • Tree Views
      • Workspace
      • Files
      • Repositories
      • Tools
    • Command Palette
    • Diagnostics (Problems Panel)
    • CodeLens
    • File Decorations
    • Hover and Go-to-Definition
    • Snippet Provider
    • Dependency Graph
    • Chat Integration
    • Auto-Refresh
    • Walkthrough
    • Task Provider
  • Tree Views
    • Workspace
    • Files
    • Repositories
    • Tools
    • Interactivity
  • Real-Time Validation & Diagnostics
    • When Validation Runs
    • Problems Panel
    • Error Details
    • Quick Fixes
    • Validation Phases
      • Phase 1: Structural (Pydantic)
      • Phase 2: Dynamic (Cross-Reference & Profile)
    • Validation Coverage
    • File Decorations
    • Error Change Notifications
    • Configuration
    • Troubleshooting
  • CodeLens
    • Available Lenses
      • Validate
      • Schema
      • Build DryRun
      • Deploy DryRun
      • Guide
    • Enabling/Disabling
    • Viewing CodeLens
    • Terminal Integration
    • Keyboard Shortcut
    • Styling
    • Troubleshooting
  • Chat Integration
    • How to Use
    • Slash Commands
      • /status
      • /validate
      • /guide
      • /build
      • /deploy
    • Freeform Questions
    • Follow-Up Suggestions
    • Workspace Context Injection
    • Error Handling
    • Privacy
    • Limitations
    • Examples
      • “How do I set up a new deployment?”
      • “What’s blocking me from deploying?”
      • “Check this file for me”
  • Settings
    • All Settings
    • Details
      • strata.cliPath
      • strata.validateOnSave
      • strata.validateOnType
      • strata.showCodeLens
      • strata.showStatusBar
      • strata.autoExportSchemas
      • strata.showFileDecorations
      • strata.defaultProfile
    • Workspace vs User Settings
      • User Settings (.config/Code/settings.json)
      • Workspace Settings (.vscode/settings.json)
    • Command-Line Configuration
    • Programmatic Access
    • Troubleshooting
  • Keyboard Shortcuts
    • Built-in Shortcuts
    • Extension Commands (via Command Palette)
    • Custom Keyboard Bindings
    • Common Workflows
      • Quick Validate & View Errors
      • Explore Schema While Editing
      • Build & Deploy Workflow
      • Switch Profile & Refresh
    • Tips
    • See Also

MCP Server for AI Agents:

  • MCP Server Integration Guide for AI Agents
    • Quick Start
    • What’s Possible with MCP
    • Key Principles
    • Documentation Map
    • Available Tools
      • Workspace & Schema
      • Authoring
      • Build Pipeline
      • Deployment
      • Monitoring & Diagnostics
    • Who Should Read This?
    • Prerequisites
    • Next Steps
    • Support & Examples
  • Setup & Installation
    • Prerequisites
    • Step 1: Install the MCP Optional Dependency
      • Option A: Install in Your Project Environment
      • Option B: Install in a Global Environment
      • Verify Installation
    • Step 2: Start the MCP Server
      • Specify Workspace Explicitly
    • Step 3: Configure Your MCP Client
      • Claude (via Claude Desktop)
      • Claude API / Python SDK
      • GitHub Copilot
      • Generic MCP Client (Python / Node.js)
    • Step 4: Test the Connection
      • In Claude Desktop
      • Programmatically
    • Troubleshooting
      • Error: “command not found: strata”
      • Error: “The mcp package is required”
      • Error: “Not inside a strata workspace”
      • Server starts but client can’t connect
    • Environment Variables
    • Next Steps
  • Claude Deployment Assistant: End-to-End Example
    • Scenario
    • Prerequisites
    • Step 1: Configure Claude Desktop
    • Step 2: Verify MCP Connection
    • Step 3: Full Workflow — Claude Guides You
      • 3a. Generate Deployment YAML
      • 3b. Validate the YAML
      • 3c. Preview the Build
      • 3d. Ask for Improvements
    • Step 5: Monitor & Verify
    • Step 6: Troubleshoot Issues
    • Summary: Claude Workflow Checklist
    • Tips & Best Practices
      • 1. Always Validate Before Building
      • 2. Always Preview Before Deploying
      • 3. Use Claude for Analysis, CLI for Action
      • 4. Ask for Improvements
      • 5. Multi-Step Workflows
    • Next Steps
  • GitHub Copilot Integration
    • Current State: CLI-Based Extension
    • Vision: MCP-Enhanced Copilot
      • Idea 1: Inline Copilot Chat with Strata Tools
      • Idea 2: CodeLens with Copilot Quick Actions
      • Idea 3: Inline Error Explanations
      • Idea 4: Diff View with Copilot Commentary
      • Idea 5: Multi-File Deployment Planning
      • Idea 6: Collaborative Deployment Comments
    • Implementation Roadmap
      • Phase 1: MVP (Current State)
      • Phase 2: MCP Integration (Proposed)
      • Phase 3: Enhanced AI Features
      • Phase 4: Collaborative Workflows
    • Security Considerations
      • MCP Scope in VS Code Extension
      • Best Practice
    • Example Implementation: Validate Command
    • Testing the Integration
      • Local Testing
      • End-to-End Test
    • Next Steps
    • See Also
  • Security & Workflows
    • Security Model
      • Core Principle: “AI Previews, Humans Execute”
      • Destructive Operations Note
    • API Keys & Secrets Management
      • âś… Secrets Are Never Exposed via MCP
      • How MCP Tools Handle Secrets
      • Best Practice: Never Paste Secrets in Prompts
    • Audit Logging
      • What’s Logged?
      • Querying Audit Logs via MCP
      • Example: Claude Auditing a Deployment
      • Integration with Compliance Tools
    • Approval Workflows
      • Pattern 1: AI Suggests, Human Approves, CLI Executes
      • Pattern 2: Slack/Teams Bot with Approval Gate
      • Pattern 3: Role-Based Access Control (RBAC)
    • Network Security
      • MCP Transport: Stdio (Local Only)
      • Remote MCP via SSH (Advanced)
    • Secrets Management Integration
      • Pattern 1: Local .strata/secrets/ Directory
      • Pattern 2: Bitwarden Integration
      • Pattern 3: AWS Secrets Manager
      • Best Practice: Least Privilege
    • Production Checklist
    • Common Threats & Mitigations
    • See Also
  • AI-Assisted Troubleshooting
    • Scenario: Infrastructure Drift Detection
    • Use Case 1: Detect What Changed
      • The Problem
      • The Claude Workflow
    • Use Case 2: Analyze Recent Deployments
      • The Problem
      • The Claude Workflow
    • Use Case 3: Diagnose a Failed Deployment
      • The Problem
      • The Claude Workflow
    • Use Case 4: Compare Two Deployments
      • The Problem
      • The Claude Workflow
    • Use Case 5: Suggest Configuration Improvements
      • The Problem
      • The Claude Workflow
    • Use Case 6: Rollback After Failed Deployment
      • The Problem
      • The Claude Workflow
    • Use Case 7: Cross-Environment Consistency Check
      • The Problem
      • The Claude Workflow
    • Use Case 8: Generate Post-Mortem Report
      • The Problem
      • The Claude Workflow
    • Best Practices for AI-Assisted Troubleshooting
      • 1. Always Validate Before Deploying
      • 2. Query History Before Major Changes
      • 3. Use Dry-Runs for Safe Testing
      • 4. Compare Before Assuming Drift
      • 5. Document Findings
    • Next Steps
  • MCP Tools Reference
    • Overview
    • Query Tools (Read-Only)
      • workspace_status(work_path: str = None) → dict
      • validate_file(file_path: str, work_path: str = None, deep: bool = False) → dict
      • list_schemas() → dict
      • get_schema(kind: str) → dict
      • deploy_status(file: str, work_path: str = None, stage: str = None) → dict
      • deploy_history(work_path: str = None, lines: int = 20, operation: str = None) → dict
      • audit_query(work_path: str = None, last: int = 20, since: str = None, stage: str = None) → dict
    • Preview Tools (Dry-Run)
      • build_plan(file: str, work_path: str = None) → dict
      • deploy_plan(file: str, work_path: str = None, stage: str = None) → dict
    • Action Tools
      • scaffold_file(kind: str, name: str, extra_vars: dict = None) → dict
      • build_run(file: str, work_path: str = None) → dict
      • build_sbom(file: str = None, work_path: str = None, scan: str = None, report: str = "inventory") → dict
      • deploy_health(file: str, work_path: str = None, stage: str = None) → dict
    • MCP Resources
      • strata://schema/{kind}
      • strata://workspace
    • Error Handling
      • Success Field
      • Error Codes
      • Example Error Response
    • Rate Limits & Timeouts
    • See Also

Platform Reference:

  • Platform Reference
    • What’s Here
    • Navigation
  • Getting Started
    • Prerequisites
    • Install
    • Initialize a Workspace
      • Scaffold with a template
      • Save your workspace as a template
      • After upgrading strata
    • File Structure
    • Register Repositories
    • Set an Active Profile
    • Validate
    • Preview Changes
    • Deploy
    • If Something Goes Wrong
    • Persist Your Preferences
    • Shell Completion
    • Next Steps
  • Value Proposition
    • What strata does
    • How it helps
      • Config sprawl
      • Secret management
      • Environment drift
      • Deployment orchestration
    • What strata owns vs. what it doesn’t
    • The Escape Hatch
      • Where the generated Terraform lives
      • Walking away
      • No lock-in by design
  • strata — CLI Command Reference
    • Standard Options
    • Exit Codes
    • Idempotency & Retry Safety
    • Command Groups
    • sln
      • sln init
      • sln update
      • sln clean
      • sln status
      • sln export
    • vars
    • tools
      • tools status options
    • new
      • Template resolution order
      • Bundle templates
    • config
      • config set KEY VALUE
      • config unset KEY
      • config list
      • config log {#config-log}
    • log
      • log list
    • profile
      • profile add NAME
      • profile remove NAME
      • profile list [--name NAME]
      • profile activate NAME
      • profile show NAME
    • ref
      • ref <type> add NAME PATH
      • ref <type> remove NAME
      • ref <type> list
      • ref <type> show NAME
    • repo
      • repo add NAME URL
      • repo list [--name NAME]
      • repo remove NAME [--purge]
      • repo sync [--name NAME] [--force]
      • repo status [--name NAME]
    • build
      • build run
      • build plan
      • build sbom
      • build clean
    • validate
      • validate run
      • validate graph
    • guide
      • Workspace mode
      • File mode (--file)
      • Project customisation
    • schema
      • schema list
      • schema get KIND
    • policy
      • policy list
      • policy check
    • secret
      • secret generate
      • secret mask
    • deploy
      • deploy run
      • deploy destroy
      • deploy show
      • deploy list
      • deploy plan
      • deploy history
      • deploy health
      • deploy output
      • deploy lock
        • deploy lock status
        • deploy lock release
        • deploy lock history
    • env
      • env info
      • env output
      • env show
      • env status
      • env drift
      • env doctor
    • audit
      • audit changes
      • audit resend
      • audit export
      • audit diff
      • Audit configuration
      • SIEM sink configuration
    • service
      • service list
      • service status
      • service deploy
      • service destroy
    • manifest
      • manifest list
      • manifest show
      • manifest export
    • mcp
      • mcp serve
      • values list
      • values get
      • values set
      • values resolve
    • version
    • help
  • strata — DevOps Workflow Guide
    • Setup Assumptions
    • Global Options
    • Phase 1 — Initialize the Workspace
      • 1.1 Create the workspace
      • 1.3 Create the workspace from a template (optional)
    • Phase 2 — Register Repositories
      • 2.1 Add repositories
      • 2.2 Clone / pull them all (when not using --clone)
      • 2.3 List registered repos
      • 2.4 Check git state of all repos
    • Phase 3 — Set Up Profiles
      • 3.1 Create profiles
      • 3.2 Activate the working profile
      • 3.3 List / inspect profiles
    • Phase 4 — Register File References
      • 4.1 Register configuration files (merged into platform config)
      • 4.2 Register environment overlays
      • 4.3 Register secret files (plain file on disk — no vault layer yet)
      • 4.3b Register data files (non-YAML assets)
      • 4.5 Inspect resolved values for a deployment
    • Phase 4b — Create New Config Files
      • Bundle templates (multi-file scaffolding)
    • Phase 5 — Validate YAML Files
      • 5.1 Structural validation (Pydantic schema)
      • 5.2 Deep validation (cross-references against active profile)
    • Phase 6 — Build
      • 6.1 Dry-run first (plan only — no files written)
      • 6.2 Full build
      • 6.3 Clean build artifacts
      • 6.4 Preview what build run would change
    • Phase 7 — Deploy
      • 7.1 Dry-run (init + validate + plan — no apply)
      • 7.2 Deploy a single stage (selective)
      • 7.3 Full deploy
      • 7.4 Force (skip approval gates)
      • 7.5 Destroy (tear down infrastructure)
      • 7.6 Outputs, plan details, and history
      • 7.7 Health checks
      • 7.8 Execution history
      • 7.9 Declare approval metadata
    • Phase 8 — Inspect and Debug
    • Phase 9 — Maintenance
    • Full Example Session (New Workspace)
    • Day-to-Day Cycle (Existing Workspace)
    • Complete Command Reference
      • Workspace
      • Configuration
      • Logs
      • Logging Config
      • Repositories
      • Profiles
      • File References
      • Validation
      • Build
      • Deploy
      • Values
  • CLI Preferences and Defaults
    • Option A: Environment Variables
    • Option B: Workspace Config (strata config set)
    • Resolution Order (highest to lowest priority)
    • Work Path Resolution (special case)
    • Keyword Reference
  • CI / CD Integration
    • Exit Codes
    • Machine-Readable Output
    • Environment Variables
    • GitHub Actions
      • Azure authentication
    • Azure Pipelines
    • Tips
      • Cache uv packages
      • Run in Docker
      • Parallelise validation across multiple files
      • Suppress console noise
    • State Locking in CI
      • Recovering from a crashed pipeline
      • GitHub Actions — concurrent run guard
      • Azure Pipelines — exclusive lock
      • Checking lock status from CI
  • Platform Architecture
    • Core Principles
    • Multi-Repository Structure
    • Configuration Hierarchy
    • Deployment Workflow
    • Compliance & Audit
    • Version Control Strategy
    • Best Practices
    • Troubleshooting
    • Summary
  • strata CLI - Exit Codes
    • Exit Code Definitions
    • Usage by Command
    • Examples
      • Bash
      • PowerShell
  • Manifest CLI Reference
    • Commands
      • strata manifest list
        • Options
        • Output
        • Examples
      • strata manifest show
        • Arguments
        • Options
        • Output
        • Examples
      • strata manifest export
        • Options
        • Output Structure
        • Summary File
        • Examples
    • Integration with strata audit
    • Common Workflows
      • Audit Manifest Before Deploying
      • Create Compliance Evidence Package
      • Query Manifest History
    • Troubleshooting
      • No Manifests Found
      • Manifest File Not Readable
      • Export Directory Not Created
    • Exit Codes
    • See Also
  • Deployment Manifest Schema
    • Root Structure
      • apiVersion
      • kind
    • Metadata Section
      • meta.name
      • meta.annotations
      • meta.labels
    • Specification Section
      • Core Fields
        • spec.deployment_name
        • spec.workspace_name
        • spec.action
        • spec.status
        • spec.timestamp
        • spec.user
        • spec.platform_version
        • spec.build_duration_seconds
        • spec.deploy_duration_seconds
    • Artifacts Section
      • artifacts.platform
      • artifacts.repositories
      • artifacts.images
      • artifacts.providers
      • artifacts.sbom
    • Stages Section
    • Policy Results Section
    • Optional Sections
      • Signatures (Future Support)
    • Complete Example: Build Manifest
    • Complete Example: Deploy Manifest
    • Validation Rules
    • Type Definitions
      • GitCommit
      • ContainerImage
      • ProvisionerInfo
      • SbomReference
      • PlatformArtifact
      • DeploymentStage
      • PolicyResult
    • See Also
  • SBOM Plugin API Reference
    • Lockfile Parser Base Class
      • strata.builders.sbom.lockfile_parsers._base.LockfileParser
        • Auto-Registration
        • Abstract Properties
          • ecosystem (property)
        • Abstract Methods
          • filename_patterns() -> List[str]
          • parse(path: Path) -> List[RawDependency]
      • RawDependency NamedTuple
        • Construction
        • Usage in parse() method
    • Collector Base Class
      • strata.builders.sbom.base_sbom_collector.BaseSbomCollector
        • Lifecycle
        • Abstract Methods
          • get_collector_name() -> str
          • collect(platform, work_path, deployment_build_path) -> List[SbomComponentModel]
        • Protected Methods
          • _reset_warnings() -> None
          • _warnings: List[str]
        • Public Methods
          • get_warnings() -> List[str]
    • Component Model
      • strata.models.sbom_model.SbomComponentModel
        • Fields
        • Construction
        • Types — When to Use Each
    • Plugin Loader & Registry
      • CollectorPluginLoader
        • Methods
          • load(work_path: Path) -> List[BaseSbomCollector] (static)
      • LockfileParserRegistry
        • DEFAULT_REGISTRY
        • Methods
          • find(filename: str) -> Optional[LockfileParser]
          • all_patterns() -> List[str]
          • all_parsers() -> List[LockfileParser]
    • Configuration Models
      • .strata/collectors.yaml Schema
        • Example
    • Common Patterns
      • De-duplicate Components by purl
      • Handle Optional Configuration
      • Add Custom Properties (Warnings/Metadata)
      • Parse with Graceful Fallback
    • Error Handling
      • ValueError in Parsers (Gracefully Caught)
      • ValueError in Collectors (NOT Caught)
      • PlatformError in Plugin Loader
    • Platform Artifact Structure
      • Module Structure
    • See Also
  • Provisioner Plugin API Reference
    • BaseDeployer
      • Constructor
      • Step Name Constants
      • Abstract Methods
        • get_deployer_name() → str
        • get_supported_steps() → List[str]
        • validate_workspace() → Tuple[bool, List[str]]
        • validate_environment() → Tuple[bool, List[str]]
        • setup() → Tuple[bool, List[str]]
        • check() → Tuple[bool, List[str]]
        • plan() → Tuple[bool, List[str]]
        • apply() → Tuple[bool, List[str]]
        • destroy() → Tuple[bool, List[str]]
        • plan_destroy() → Tuple[bool, List[str]]
        • show_plan() → Tuple[bool, Dict[str, Any], List[str]]
        • output() → Tuple[bool, Dict[str, Any], List[str]]
      • Non-Abstract Methods (override as needed)
        • status() → Tuple[bool, Dict[str, Any], List[str]]
        • health() → Tuple[bool, Dict[str, Any], List[str]]
        • collect_outputs() → Tuple[bool, Dict[str, Any], Dict[str, Any], List[str]]
        • describe_plan() → List[str]
        • save_plan_json() → Tuple[bool, Optional[Path], List[str]]
      • Protected Helpers
        • _get_timeout(step: str, default: int) → int
        • _resolve_iac_model() → Optional[WorkspaceIacModel]
    • DeployerFactory
      • DeployerFactory.create(provisioner_type, *, stage, deployment_service, configuration_service, build_path, work_path, verbose, force, resolved_values, solution_controller) → BaseDeployer
      • DeployerFactory.resolve_type(stage, deployment_service) → Tuple[Optional[str], List[str]]
      • DeployerFactory.register(name, deployer_class)
      • DeployerFactory.load_plugins(work_path)
      • DeployerFactory.is_known_type(type_str) → bool
      • DeployerFactory.get_known_types() → List[str]
      • DeployerFactory.reset()
    • Built-in Provisioner Types
    • See Also

Internals:

  • Models
    • YAML Document Structure
    • Constrained Types
    • Supported Kinds
    • Two-Phase Validation
    • Lifecycle Stages
    • Validation Rules
    • Writing a New Model
  • Services Documentation
    • Overview
    • Basic Usage
    • BaseService.load() (Recommended)
    • Service Caching
    • Lifecycle Hooks
    • BaseService API Reference
    • ConfigurationService (Singleton)
  • Configuration Service
    • Load Order
    • Repo Map
    • Two-Phase Validation
    • Caching
    • Key Methods
    • ConfigurationModel Fields
    • Example
  • Integrations Documentation
    • Overview
    • Creating an Integration
    • Using the Factory
    • Singleton Pattern
    • BaseIntegration API
    • IntegrationRegistry
    • Capability Protocols
      • Store-specific notes
        • Vault and Consul — feature flags via KV prefix
        • Flagsmith — variables via identity traits
        • Flagsmith — feature flag seeding limitations
    • IntegrationModel Configuration
    • Runtime inspection
    • Workspace drop-ins
    • Per-integration reference
      • Git
        • Environment variables
        • Auth methods
      • Terraform
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • Troubleshooting
      • OpenTofu
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • Troubleshooting
      • Ansible
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • AnsibleDeployer step mapping
        • Strata variable files
        • SSH private key injection
        • Minimal YAML configuration
        • Troubleshooting
      • Docker
        • Environment variables
        • Auth methods
      • Helm
        • Environment variables
        • Auth methods
        • Which deployer uses it
        • Troubleshooting
      • Bitwarden (Secrets Manager)
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • HashiCorp Vault
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • OpenBao
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • HashiCorp Consul
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • Azure Key Vault
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • Azure App Configuration
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
      • Infisical
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • Using as a secret or variable store
      • etcd
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • Using as a variable or KV store
      • Flagsmith
        • Environment variables
        • Auth methods
        • Minimal YAML configuration
        • Using as a feature flag store
  • MCP Server
    • Installation
    • Quick Start
      • VS Code (GitHub Copilot)
      • Claude Desktop
    • Transport Options
    • Server Instructions
    • Tool Reference
      • workspace_status
      • validate_file
      • list_schemas
      • get_schema
      • scaffold_file
      • build_plan
      • build_run
      • build_sbom
      • deploy_plan
      • deploy_history
      • deploy_status
      • deploy_health
      • audit_query
    • MCP Resources
    • Response Envelope
    • Example: AI-Assisted Deployment Workflow
  • Builders Documentation
    • Overview
    • BaseBuilder
      • Extending BaseBuilder
    • PlatformBuilder
      • Constructor
      • Three-Phase Pipeline
        • before_build(deployment_service, work_path, build_path) → bool
        • build(deployment_service, work_path, build_path, dry_run=False) → bool
        • after_build(deployment_service, work_path, build_path, dry_run=False) → bool
      • Build Path
    • TerraformBuilder
      • Constructor
      • Requirement Tracking
      • Three-Phase Pipeline
        • before_build(deployment_service, work_path, build_path, dry_run=False) → bool
        • build(deployment_service, work_path, build_path, dry_run=False, platform_model=None) → bool
        • after_build(deployment_service, work_path, build_path, dry_run=False) → bool
      • Output Files
    • AnsibleBuilder
      • Constructor
      • Three-Phase Pipeline
        • before_build(deployment_service, work_path, build_path, dry_run=False, solution_controller=None) → bool
        • build(deployment_service, work_path, build_path, dry_run=False, platform_model=None, solution_controller=None) → bool
        • after_build(deployment_service, work_path, build_path, dry_run=False, solution_controller=None) → bool
      • Output Files
      • Playbook Variable Access
    • ComposeBuilder
      • Output Location
      • Service Naming
        • Cross-Module Dependencies
      • Environment Variable Sources
      • Volume Conventions
      • Healthcheck Types
      • Module YAML Example
      • Generated docker-compose.yml
      • .env File and Secret Injection
      • configuration: Escape Hatch
      • Three-Phase Pipeline
        • before_build → bool
        • build(deployment_service, work_path, build_path, dry_run=False) → bool
        • after_build → bool
    • HelmBuilder
      • Output Location
      • Service Naming
      • Environment Variable Sources
      • PVC Persistence
      • meta.yaml Contents
      • Module YAML Example
      • Generated myns/authentik/values.yaml
      • Generated myns/authentik/meta.yaml
      • ${KEY} Injection at Deploy Time
      • configuration: Escape Hatch
      • Three-Phase Pipeline
        • before_build → bool
        • build(deployment_service, work_path, build_path, dry_run=False) → bool
        • after_build → bool
    • SbomBuilder
      • Output Location
      • Report Modes
      • Collector Pattern
      • Floating Tags
      • Three-Phase Pipeline
        • before_build
        • build
        • after_build
      • DependencyFileCollector — Scope Control
      • CVE Audit (--audit)
      • Built-in lockfile formats
      • Extending the SBOM
        • Workspace plugins
        • Writing a collector plugin
        • Writing a lockfile parser plugin
        • Test isolation
    • Typical Build Sequence
  • Deployers Documentation
    • Overview
    • BaseDeployer
      • Constructor
      • Abstract interface
      • Step constants
      • Typical call sequence
    • TerraformDeployer
      • Constructor
      • Step → Terraform command mapping
      • validate_workspace
      • validate_environment
      • collect_outputs
      • IaC model resolution priority
      • Working directory
      • Resolved values (TF_VAR injection)
    • AnsibleDeployer
      • Constructor
      • Step → Ansible command mapping
      • validate_workspace
      • validate_environment
      • IaC spec options
      • Auto-discovery
      • Strata variable files
      • Topology-based inventory
      • SSH key management
    • ScriptDeployer
      • Constructor
      • Step → lifecycle phase mapping
      • validate_workspace
      • validate_environment
      • Script types
      • Environment variables injected into every script
      • Timeout
      • Script entry types
    • Deployment YAML for ScriptDeployer
    • ComposeDeployer
      • Step → Docker command mapping
      • Constructor
      • validate_workspace
      • validate_environment
      • Resolved values (compose env injection)
      • Deployment YAML example
    • HelmDeployer
      • Step → Helm command mapping
      • validate_workspace
      • validate_environment
      • Chart source resolution
      • Deployment YAML example
  • Validators Documentation
    • Overview
    • BaseValidator
      • Extending BaseValidator
    • PlatformValidator
      • Constructor
      • Properties
      • Three-Phase Pipeline
        • before_validate(work_path) → bool
        • validate(work_path) → bool
        • after_validate(work_path) → bool
      • Kind → Service Mapping
      • With Configuration Service (Phase 2)
      • Error Accumulation
  • Lifecycles
    • Configuration
    • Template Substitution in Scripts
    • Template Substitution in Scripts
    • Environment Variables
    • Phase Reference
      • validate
      • solution
      • config
      • build
      • deploy run
        • Hierarchical execution
      • deploy destroy
      • deploy health
      • ScriptDeployer steps
    • Phase Naming Convention
    • Gate Behaviour
    • Examples
    • Best Practices
  • Policies
    • Overview
    • Configuration
      • Fields
    • Policy Types
      • Built-in types
      • tenant_zone
      • resource_type_restrictions
      • required_tags
      • naming_pattern
      • script
      • ref_convention
      • sbom_pinned_versions
      • sbom_allowed_registries
      • sbom_denied_packages
      • sbom_max_components
      • sbom_license
      • cost_threshold
    • Enforcement Levels
    • Phases
    • Example Configuration
      • Single policy — zone enforcement
      • Two policies — zone enforcement + required tags
      • Complete example — naming, tags, SBOM, zone, and OPA
    • See Also
  • Custom Exception System
    • Hierarchy
    • Base Exception Features
    • Common Usage
    • Service Error Handling Pattern
    • Accessing Errors
    • Testing
    • Best Practices
  • Logging Framework
    • Quick Start
    • Configuration Options
      • 1. From YAML File (Recommended)
      • 2. Programmatic
    • Features
      • Correlation IDs
      • Context Data
      • Performance Tracking
    • Integration
      • ELK Stack
      • Azure Application Insights
    • Best Practices
    • Default Config Files
  • strata - Utilities Documentation
    • config.py
    • system.py
    • configuration_loader.py
    • service_cache.py
    • templater.py
    • ansible_utils.py
    • sbom_utils.py
    • version.py

Config File Formats:

  • Configuration Files
    • File Types
    • Architecture
    • Naming Conventions
    • Quick Start
  • Configuration
    • Purpose
    • Schema
    • Providers
    • Topologies
    • Layering — Artifact Path Hierarchies
      • Layering Schemes
      • Layer Definition
      • Artifact Path Resolution
      • Migration from layering to layerings
      • Mutual Exclusion
    • Example
    • Configuration Schema Fields
    • Merge Behavior
    • Validation
    • Path Convention Policy
      • Declaring conventions
      • Enforcement policy
      • Inline convention (deploy-repo mode)
      • Validation rule types
    • Checkov IaC Security Policy
      • Declaring the integration
      • Enabling the policy
      • How it works
      • Severity gate
      • Graceful degradation
    • OPA Policy
      • Installation
      • Declaring the policy
      • Writing OPA rules
      • OPA input document
      • Mode selection
      • Graceful degradation
    • Secret Stores
      • github — GitHub Actions secrets
    • Deployment Artifacts
      • Manifest Storage
      • Terraform Output Artifact Storage
    • Integrations
      • Supported SIEM types
        • splunk — Splunk HTTP Event Collector (HEC)
        • elk — ELK / Logstash
        • otel — OpenTelemetry (OTLP/HTTP)
        • sentinel — Azure Sentinel (DCR Logs Ingestion API)
      • Integration field reference
    • Notes
  • Workspace Configuration
    • Schema
    • Lifecycle Phases
    • Providers
    • Provisioners
      • Build Output Profile (Terraform only)
      • Provisioner types
    • Topology
    • Namespaces
    • Variables & Secrets
    • Examples
    • Execution Flow
    • Best Practices
    • Multi-Topology
    • Validation
    • Troubleshooting
    • Advanced
  • Deployment Configuration
    • Conceptual Model
    • Schema
    • Properties & Custom
    • Workspace Reference
    • Environments
    • Configurations
    • Features, Variables & Secrets
    • Configuration Merge Order
    • Examples
    • Use Cases
    • Deployment Workflow
    • Stages
      • provisioner vs topology
      • scope — stage filtering
      • Steps
    • Cross-Stage Outputs
      • STRATA_CONTEXT and STRATA_SENSITIVE
      • Stage secret scoping
      • How it works
      • Sensitive output handling
      • Injection format
      • Console output
    • Provisioner Stage Types
    • Deploying ArgoCD ApplicationSets
    • Best Practices
    • Locking
      • Lock Backend by Provisioner Type
      • Example — Azure Blob lock
      • Example — Terraform Cloud lock
      • Example — Consul lock
      • Managing locks manually
    • Validation
    • Troubleshooting
    • Summary
  • Environment Configuration
    • Purpose
    • Schema
    • Properties & Custom
    • Overrides
      • Module Overrides
      • Resource Overrides
      • Provider Overrides
      • Remote Reference Overrides
      • Build Output File Overrides (Terraform)
    • Variables
    • Secrets
    • Features
    • Audit
      • Event Policy
      • Sinks
        • Built-in sink types
        • Integration-backed sinks (SIEM)
      • Deploy-Log Structure
      • Forwarding via CLI
      • Sink field reference
    • Examples
    • Workspace & Environment Relationship
    • Multi-file Composition
      • Per-section merge strategy
    • Configuration Merge Order
    • Use Cases
    • CLI Integration
    • File Location
    • Best Practices
    • Validation
    • Troubleshooting
    • Environment vs Workspace
    • Summary
  • Provider Configuration
    • Schema
    • Provider Types
    • Examples
    • Variables vs Secrets
    • Workspace Integration
    • Environment-Specific Provider Overrides
    • Validation
    • Troubleshooting
  • Resource Configuration
    • Schema
    • Resource Types
    • Examples
    • Disks vs Volumes
    • Workspace Integration
    • Cost Tracking
    • Best Practices
    • Common Patterns
    • Validation
    • Troubleshooting
  • Firewall Configuration
    • Schema
    • Rule Structure
    • Examples
    • Rule Processing
    • Best Practices
  • Module Configuration
    • Schema
    • Source
      • Git-based source
      • Chart-based source (Helm / ArgoCD)
    • Deployer Types
    • Services
      • Environment variable sources
      • Service naming in compose output
      • Mounts
    • References
    • Lifecycle Hooks
    • Properties
    • Examples
      • Multi-container compose module (Authentik)
      • Single-container compose module (Caddy)
      • Helm chart module
    • Module Categories
    • Namespace Integration
    • Build Output
    • Validation
    • Troubleshooting
    • Schema
    • Source Types
    • Examples
    • Module Categories
    • Path Resolution
    • Namespace Integration
    • Module Patterns
    • Best Practices
    • Validation
    • Troubleshooting
    • Dependencies
  • Namespace Configuration
    • Schema
    • Lifecycle Phases
    • Examples
    • Script Execution
    • Workspace Integration
    • Module Organization
    • Common Patterns
    • Namespace Types
    • Best Practices
    • Validation
    • Troubleshooting
  • DNS Configuration
    • When to Use
    • Schema
    • Top-level Fields
    • spec.references Fields
    • Zone Fields
    • Record Fields
    • Record Type Reference
    • Example
    • Variable and secret records
      • var: — build-time variable resolution
      • secret: — deploy-time injection
    • Linking to a Workspace
    • Build Output
      • Terraform — dns.auto.tfvars.json
      • Terraform — dns_secret_records.auto.tfvars.json
      • Ansible — strata_dns.yml
    • Validation Rules
    • Best Practices
  • Network Configuration
    • When to Use
    • Schema
    • Top-level Fields
    • spec.references Fields
    • Network Fields
    • CidrSource Fields
    • Subnet Fields
    • Peering Fields
    • Examples
      • Haven (simple flat network)
      • Enterprise (multi-network with peerings and variable CIDRs)
    • CIDR Overlap Detection
      • Subnet-to-subnet overlap
      • Subnet containment
      • Cross-network overlap
      • Variable and secret CIDRs
    • Cross-Kind References
    • Variable and Secret CIDRs
      • var: — build-time variable resolution
      • secret: — deploy-time injection
    • Linking to a Workspace
    • Build Output
    • Validation Rules
    • Merge Behaviour
    • Template
    • Best Practices
  • Deployment Manifest Configuration
    • Purpose
    • Schema
    • Storage Types
      • Local Filesystem Storage
      • GitOps Repository Storage
    • Manifest Content
    • Examples
      • Local — Development
      • GitOps — Multi-Environment
    • Troubleshooting
    • Integration with Deployment Configuration
  • Tenant Configuration
    • Conceptual Model
    • Schema
    • Field Reference
      • spec.code and meta.name
      • spec.zones
      • spec.environments
      • spec.properties
      • spec.custom
      • spec.configuration
      • spec.references
    • Properties / Custom vs Configuration
    • Validation
    • Zone Policy
    • Example
    • CLI
  • Workflow Configuration
    • Schema
      • Field Reference
    • Built-in Check Functions
    • Default Workflow
    • Resolution Order
    • Customization Examples
      • Reorder steps
      • Add a project-specific step
      • Simplify for a compose-only project
    • Dynamic Steps
  • Promotion Record
    • Purpose
    • Conceptual Model
    • Schema
    • Example
    • Key Fields
    • Workflow
      • Initiating a Promotion
      • Viewing Promotion History
      • Rollback
    • Storage
    • Relationship to Other Kinds
  • Version Lock
    • Purpose
    • Conceptual Model
    • Schema
    • Example — Thin Reference (Promotion)
    • Example — Inline Pins (Manual Lock)
    • Key Fields
    • Workflow
      • Manual Locking
      • Promotion
      • Validation
      • Rollback
    • Relationship to Version Manifest
  • Version Manifest
    • Purpose
    • Conceptual Model
    • Schema
    • Example
    • Key Fields
    • Workflow
      • Creating a Manifest
      • Updating Versions
      • Locking a Manifest
      • Applying in Deployments
    • Relationship to Version Lock

Guides:

  • Audit Command Group — Deployment History and Compliance
    • What is an Audit Trail?
    • audit changes — List Recent Deployments
      • Filter by time range
      • Machine-readable output
      • Use cases
    • audit diff — Compare Two Deployments
      • Compare to production
      • Machine-readable output
      • Use cases
    • audit export — Generate Compliance Reports
      • Export to file
      • Export to SIEM (Splunk, ELK, Azure Sentinel)
      • Machine-readable output
      • Use cases
    • audit resend — Retry Failed Exports
      • Use cases
    • Common Workflows
      • Workflow 1: Compliance audit preparation
      • Workflow 2: Troubleshoot “what changed?”
      • Workflow 3: Enable continuous audit logging to Splunk
      • Workflow 4: Incident response — find root cause
      • Workflow 5: Cost tracking and optimization
    • Audit Trail Storage
      • Where are audit records stored?
      • Accessing audit records locally
      • Backup and retention
    • Troubleshooting
      • “No audit records found”
      • “Export to Splunk failed”
      • “Export to Azure Sentinel failed”
    • Best Practices
    • See Also
  • Deploying Infrastructure
    • Before You Deploy
      • 1. Validate the deployment file
      • 2. Check the dry-run plan
      • 3. Verify state lock status
    • Running a Deployment
      • Basic deployment
      • Non-interactive mode (CI/CD)
      • Deploy a single stage
      • Dry-run: verify without applying
    • Understanding Deployment Output
      • Console output structure
      • Key fields to watch
      • Structured output (JSON/NDJSON)
    • Handling Deployment Failures
      • Exit codes and meanings
      • Partial failure (a stage failed mid-deployment)
      • State inspection after failure
      • Stale locks
    • Deployment Stages and Execution
      • Sequential vs. parallel stages
      • Stage dependencies
      • Conditional stages
    • Lifecycle Hooks and Customization
      • Before/After hooks
      • Failure handling
    • Deployment Validation and Safety
      • Pre-deployment checklist
      • Approval gates (in CI/CD)
    • Audit Trail and Compliance
    • Common Scenarios
      • Scenario 1: Rollback a deployment
      • Scenario 2: Deploy just one module’s changes
      • Scenario 3: Deployment takes too long
      • Scenario 4: Re-run a deployment exactly as it was before
    • Best Practices
    • See Also
  • Environment Command Group — Inspecting Deployments
    • What is strata env?
    • env info — Workspace Context
      • Use cases
      • Scripting
    • env output — Terraform Outputs
      • List all outputs
      • Get a single output value
      • Get output for a specific provisioner
      • Raw output (for scripts)
      • Machine-readable output
      • Use cases
    • env show — Full Resolved Environment
      • Filter by stage
      • Machine-readable output
      • Use cases
    • env status — Infrastructure Status
      • Single deployment status (live backend query)
      • Multiple deployments status (path or all)
      • Filter by stage
      • Offline mode (no backend queries)
      • Use cases
    • env drift — Detect Infrastructure Drift
      • Detect and report specific resources
      • Machine-readable output
      • Use cases
    • env doctor — Diagnose Connectivity Issues
      • Check specific integration
      • Machine-readable output
      • Use cases
    • Common Workflows
      • Workflow 1: Pre-deployment checklist
      • Workflow 2: Post-deployment verification
      • Workflow 3: Troubleshooting a stalled deployment
      • Workflow 4: CI/CD monitoring
    • Tips and Tricks
      • Extract all outputs to environment variables
      • Monitor infrastructure with Prometheus
      • Compare environments
      • Automated health check in monitoring tools
    • See Also
  • Multi-Repository Setup
    • Why Multi-Repo?
    • Repository Registration
      • Registering a repository
        • Remote git repository
        • Local repository (already on disk)
      • Listing registered repositories
      • Syncing repositories
      • Removing a repository
    • Repository Status and Version Tracking
      • Check repository status
    • Referencing Repositories in YAML
      • The @repo_name syntax
      • Resolution at build time
      • Benefits
    • Version Pinning and Promotion
      • Pin a repository to a specific version
      • Promotion workflow
      • Tagging strategy
    • CI/CD Integration
      • Syncing repositories in your pipeline
      • Checking out a specific repository version
      • Example: Multi-stage promotion pipeline
      • Detecting version updates
    • Handling Repository Changes
      • Adding a new file to a repository
      • Updating a repository (switching branch or tag)
      • Rolling back to a previous repository version
    • Multi-Repo Workflows
      • Workflow 1: Shared modules, separate deployments
      • Workflow 2: Monorepo split across multiple working directories
      • Workflow 3: Enterprise setup with central module registry
    • Troubleshooting
      • “Repository not found” error
      • “Reference not resolved” error
      • Repository is dirty (uncommitted changes)
      • Slow sync (large repositories)
    • Best Practices
    • See Also
  • Secrets, Variables, and Features — The Resolution Pattern
    • The Common Pattern
    • The Three Types
    • Store Types (Backends)
      • Shared stores (all three types support these)
      • Secrets-only stores
      • Variables-only stores
    • Declaring Values
      • Constant values (inline)
      • Environment variables (runtime lookup)
      • External stores (Vault, Key Vault, Bitwarden, etc.)
    • Layering: Workspace → Environment → Deployment
      • Example: Layering a variable
      • Same layering rule for secrets and features
    • Referencing Values in YAML
      • Variables: var: <key>
      • Secrets: secret: <key>
      • Features: feature: <key> or featureFlags: {}
    • Practical Examples
      • Example 1: Multi-environment database credentials
      • Example 2: Feature flags for canary deployment
      • Example 3: GitHub Actions with env var secrets
    • Security Best Practices
      • Never commit secrets to git
      • Variables can be in git (they’re non-sensitive)
      • Secrets are never logged
    • Auto-Generated Secrets
    • Troubleshooting
      • “Secret key not found”
      • “Variable referenced but not declared”
      • Secret appears in logs
    • See Also
  • Service Command Group — Deploy Individual Services
    • What is a “Service” in strata?
    • service list — Discover Available Services
      • Machine-readable output
      • Use cases
    • service status — Check Service Health
      • Verbose output (with pod details)
      • Machine-readable output
      • Use cases
    • service deploy — Update a Service
      • Non-interactive mode (CI/CD)
      • Dry-run (preview changes)
      • Use cases
    • service destroy — Remove a Service
      • Dry-run before destroying
      • Use cases
    • Common Workflows
      • Workflow 1: Canary deployment
      • Workflow 2: Update a service without redeploying infrastructure
      • Workflow 3: Hotfix a crashing service
      • Workflow 4: CI/CD service pipeline
    • When to Use service vs. deploy
    • Troubleshooting
      • “Service not found” error
      • Service deployment hangs (waiting for replicas)
      • Service shows as degraded
    • Best Practices
    • See Also

Platform Examples:

  • Platform Examples
    • Available Examples
    • How These Examples Are Structured
  • Azure AKS
    • Architecture Overview
    • Configuration
    • Workspace
    • Provider
    • Network
    • Resources
      • AKS Cluster
      • PostgreSQL Flexible Server
      • Azure Container Registry
      • Key Vault
    • Namespace
    • Module
      • Traefik Ingress Controller
    • Environment
    • Deployment
  • AWS EKS
    • Architecture Overview
    • Configuration
    • Workspace
    • Provider
    • Network
    • Resources
      • EKS Cluster
      • RDS PostgreSQL
      • Elastic Container Registry
      • S3 Artifacts Bucket
    • Namespace
    • Module
      • AWS Load Balancer Controller
    • Environment
    • Deployment
  • GCP GKE
    • Architecture Overview
    • Configuration
    • Workspace
    • Provider
    • Network
    • Resources
      • GKE Autopilot Cluster
      • Cloud SQL for PostgreSQL
      • Artifact Registry
      • Cloud Storage Bucket
    • Namespace
    • Module
      • NGINX Ingress Controller
    • Environment
    • Deployment
  • Hetzner Compose
    • Architecture Overview
    • Configuration
    • Workspace
    • Provider
    • Resource
      • Application Server
    • DNS
    • Namespace
    • Modules
      • Traefik Reverse Proxy
      • Application Stack
    • Environment
    • Deployment
  • Kamatera Swarm
    • Architecture Overview
    • Configuration
    • Workspace
    • Provider
    • Firewall
    • Resources
      • Swarm Manager
      • Infrastructure Workers
      • Application Workers
    • Namespace
    • Module
      • Traefik Ingress
    • Environment
    • Deployment

Guides:

  • How Deployments Work
    • The five things you need to know
    • Simple example — one server, one Ansible playbook
      • Workspace
      • Deployment
      • Terraform outputs.tf (simple)
      • What happens at runtime
      • provisioner: vs topology: on a stage
    • Complex example — multi-stage production pipeline
      • What we’re building
      • Workspace
      • Deployment
      • Terraform outputs.tf (complex)
      • Data flow through all five stages
    • How outputs travel between stages
      • STRATA_CONTEXT seed
      • STRATA_SENSITIVE seed and scoping
    • Topology — when to use it
  • How Deployment Locking Works
    • Why locking exists
    • How the lock fits into deploy run
    • Configuring locking
    • Backend selection
    • End-to-end example — azurerm backend
      • 1. Deployment file
      • 2. Lock acquired
      • 3. Concurrent run is blocked
      • 4. Stages execute
      • 5. Lock released
    • What happens when a run crashes mid-deploy
    • Manual lock management
      • Check who holds the lock
      • Force-release a stuck lock
      • View the audit trail
    • The delegate strategy
    • Dry runs never lock
  • Helm Modules
    • Overview
    • Defining a Helm Module
      • Registry chart (third-party)
      • Local chart (your own)
      • Source modes
      • Spec fields reference
    • Wiring into a Deployment
      • 1. Namespace references the module
      • 2. Workspace topology references the namespace
      • 3. Deployment stage references the topology
    • Build Output
      • meta.yaml
      • values.yaml
    • Deploy
      • What executes
      • Safety flags
      • Dry-run only
      • Destroy
    • GitOps Integration
    • Examples
      • Minimal — deploy a registry chart with custom values
      • Structured services — generate values from definitions
  • What strata Does — A Practical Overview
    • Configuration as YAML layers, not copy-paste
      • Cross-repo references
    • Secret resolution — never in git
      • Auto-generated secrets
    • Variable stores for non-sensitive config
    • Build — generate your Terraform/Helm inputs
      • Preview changes before you apply
    • Deploy — run the provisioner pipeline
      • Supported provisioners
      • Other deploy subcommands
    • Version management — pin and lock chart/image versions
    • Promotions — advance versions across rings
    • Deployment locking
    • Lifecycle hooks — run scripts at any phase
    • Policy guardrails
    • Schema validation on any YAML file
    • Inspect resolved values before you deploy
    • Tool health check
    • Secret utilities
    • CI-friendly by design
    • Dev container out of the box
    • Workspace templates
    • Create config files from templates
    • Inspect JSON schemas
    • Persistent CLI defaults
    • Extend strata without touching core code
      • Custom integrations
      • Custom policies
    • The escape hatch
  • Frequently Asked Questions
    • What timestamp format does strata use?
    • What is strata?
    • How does strata work with Terraform?
    • How does strata work with Ansible?
    • How does strata work with Helm and Docker Compose?
    • Why not Terragrunt?
    • Why not Ansible?
    • Why YAML and not HCL?
    • Can I use this with existing Terraform state?
    • Can I mix provisioners?
    • Does strata support multiple clouds?
    • What happens if I delete .strata/?
    • How do I roll back a deployment?
    • Can multiple people deploy at the same time?
  • Configuration FAQ
    • What is the difference between a workspace and a deployment?
    • Do I need an environment file, or can I put everything in the deployment?
    • What is the difference between variables and secrets?
    • How do variables layer across workspace, environment, and deployment?
    • What does meta.name allow?
    • What is the difference between properties, custom, and labels?
    • When do I need a configuration file?
    • How many provisioners does a workspace need?
    • How do I share a provider file across multiple workspaces?
    • How do environment overrides work?
    • Can the same workspace be deployed to multiple environments simultaneously?
    • How do I provide an SSH key for Ansible without putting it in the YAML?
    • How do I adopt strata with existing Terraform state?
    • How do I configure multiple stages in a deployment?
    • How do I roll back a deployment?
  • Cookbook: Add a New Environment
    • When to use this
    • Step-by-step
      • 1. Copy the existing environment file
      • 2. Edit the new environment
      • 3. Create a deployment file for the new environment
      • 4. Validate
      • 5. Build and review
      • 6. Build for real
      • 7. Deploy (when ready)
    • Checklist
    • Common mistakes
  • Environment Composition
    • Why compose?
    • Merge semantics
    • Example: base + prd
      • environments/base.yaml
      • environments/prd.yaml
      • Effective result
    • Tracing value origins with --trace
      • JSON output with --trace
    • Common patterns
      • Base + region + environment
      • Shared security policy
      • Tenant overlays
    • Merge validation
    • See also
  • Pattern: Change a Value Across All Environments
    • The layering model
    • Recipe: Change a resource property everywhere
    • Recipe: Change a variable in all environments
    • Recipe: Change a variable in only one environment
    • Verification workflow
    • Tips
  • Troubleshooting: What Changed?
    • The 5-minute investigation
      • 1. Check current drift
      • 2. Check execution history
      • 3. Check git history for the deployment file
      • 4. See the exact diff for a suspicious commit
      • 5. Rebuild and compare
    • Common scenarios
      • “A variable value changed unexpectedly”
      • “A new resource appeared / disappeared”
      • “Secrets stopped resolving”
      • “Terraform apply failed but config looks right”
    • Timeline reconstruction
    • Prevention
  • Setting Up Azure OIDC for GitHub Actions
    • Prerequisites
    • Step 1: Create (or identify) an App Registration
    • Step 2: Add a Federated Credential
    • Step 3: Grant Azure Role Assignments
    • Step 4: Configure GitHub Variables
    • Step 5: Update the Calling Workflow
    • Verifying the Setup
    • Switching Back to Client Secret
    • Troubleshooting
  • Deployment Manifests Guide
    • Overview
    • What is a Deployment Manifest?
      • Build Manifest
      • Deploy Manifest
      • The Build → Deploy Workflow
    • Why Use Deployment Manifests?
      • Compliance & Audit
      • Operational Visibility
      • Rollback & Recovery
    • Setup
      • 1. Enable Manifests in Configuration
      • 2. Reference in Your Deployment
      • 3. Deploy
    • Reading a Manifest
      • Key Fields
    • Common Tasks
      • List All Manifests
      • View a Manifest
      • Export Manifests for Compliance
      • Compare Two Deployments
      • Extract Terraform Outputs
      • Check Deployment Duration
      • Inspect SBOM
      • Failed Deployment Details
    • GitOps Workflow
      • Downstream Automation
    • Troubleshooting
      • Manifest Not Written
      • GitOps Push Failed
      • Manifest Has Empty artifacts.content
      • Export Audit Trail with Manifests
    • Build Manifests
      • When are Build Manifests Created?
      • Build Manifest Structure
      • Key Differences from Deploy Manifests
      • Querying Build Manifests
      • Workflow: Review Build Before Deploying
    • Best Practices
    • See Also
  • Deployment Manifests for Compliance & Audit
    • Compliance Frameworks
      • NIS2 Directive (EU)
      • ISAE 3402 Type 2 (SOC 2)
      • PCI DSS (Payment Card Industry)
    • Evidence Collection
      • Build-Time Evidence
      • Deploy-Time Evidence
    • Audit Workflows
      • Internal Audit: “What Changed?”
      • External Audit: “Prove Compliance”
      • Post-Incident: “What Exactly Happened?”
    • Policy & Governance
      • Build-Time Policy Enforcement
      • Change Windows
      • Approval Workflows
    • Regulatory Reporting
      • Quarterly Audit Report
    • Manifest Storage for Compliance
      • Local Filesystem (Development)
      • GitOps (Production)
    • Integration Points
      • SIEM / Log Aggregation
      • Compliance Scanning
      • Change Management System
    • Best Practices
    • See Also
  • SIEM Audit Forwarding
    • Overview
    • Supported Backends
    • Setup: Automatic Forwarding
      • Step 1 — Declare the integration
      • Step 2 — Configure the audit sink
      • Step 3 — Deploy
    • Setup: On-Demand Forwarding (--siem)
    • Syslog with CEF Format
      • CEF Message Structure
      • Default syslog (JSON)
    • All Sink Types
    • Splunk HEC Reference
      • Configuration
      • Event Structure
      • Verify Connectivity
      • Environment Variable
    • Azure Sentinel Reference
      • Configuration
      • Authentication options
    • ELK Reference
      • TCP (Logstash JSON codec input)
      • HTTP (Elasticsearch Bulk API)
    • OpenTelemetry Reference
      • To Grafana Loki
      • To Datadog (native OTLP)
      • To Sumo Logic (OTLP endpoint)
    • Retry Behavior
    • Event Fields Reference
    • Filtering Events
    • Resend Historical Entries
    • Troubleshooting
      • SIEM integration not found
      • Authentication errors
      • No events appearing in Splunk
      • CEF messages not parsed
    • See Also
  • Extending strata SBOM — Custom Collectors and Parsers
    • Overview
      • 1. Lockfile Parsers — zero-config drop-in
      • 2. Collectors — config-driven
    • Quick Start
      • Option A: Add a Lockfile Parser (easiest)
      • Option B: Add a Collector (advanced)
    • Lockfile Parser API
      • Base Class: LockfileParser
        • 1. ecosystem (property)
        • 2. filename_patterns() method
        • 3. parse(path: Path) -> List[RawDependency] method
      • RawDependency — Return Type
      • Auto-Registration
    • Collector API
      • Base Class: BaseSbomCollector
        • 1. get_collector_name() method
        • 2. collect() method
        • 3. Warnings handling
      • SbomComponentModel — Return Type
    • Complete Example: Python Private Index Parser
    • Complete Example: Custom Collector — Terraform Variables
    • Testing Custom Plugins
      • Testing Lockfile Parsers
      • Testing Collectors
      • Running Tests
    • Auto-Discovery Behavior
      • Lockfile Parsers (.strata/lockfile_parsers/)
      • Collectors (.strata/collectors/)
    • Lifecycle & Error Handling
      • Lockfile Parser Lifecycle
      • Collector Lifecycle
    • Debugging & Troubleshooting
      • Enable debug logging
      • Check which plugins are loaded
      • Test parse in isolation
      • Verify collector is loaded
    • Best Practices
      • Lockfile Parsers
      • Collectors
    • Integration with strata
      • Build Phase
      • Audit Export
    • See Also
  • Custom SBOM Plugin Examples
    • Example 1: Ruby Bundler Gemfile.lock Parser
    • Example 2: Go go.mod Parser
    • Example 3: Composer (PHP) Parser
    • Example 4: Custom Collector — Database Schemas
    • Example 5: Custom Collector — External APIs
    • Testing Examples
      • Test a Lockfile Parser
      • Test a Collector
    • Integration Testing
    • See Also
  • CVE Vulnerability Scanning
    • Quick Start
    • Overview
    • Backends
      • Installing Scanners
      • Check Scanner Availability
    • Scanning with --audit
      • Basic Scan
      • Filter by Severity
      • Generate Reports
    • Allowlist: Ignore Known Issues
      • Create an Allowlist
      • How Allowlists Work
    • Policy: cve_max_severity
      • Default Behavior
      • Configure in Workspace YAML
      • Enforcement Levels
      • Disable the Policy
    • Understanding CVE Results
      • Console Output
      • CVE Finding Fields
      • JSON Audit Result
    • Remediation
      • 1. Update to Fixed Version
      • 2. Suppress with Allowlist (Temporary)
      • 3. Use Vulnerability Data
    • SBOM Integration
    • Deployment Manifests
    • CI/CD Integration
      • GitHub Actions
      • GitLab CI
      • Generic CI (exit code check)
    • Troubleshooting
      • No Scanner Found
      • Scan Takes Too Long
      • False Positives in Allowlist Not Working
      • Policy Blocking Build, Need to Investigate
    • See Also
  • Scaffolding Templates
    • Overview
    • Layer 1 — Single-file templates
    • Layer 2 — Bundle directory templates
    • Layer 3 — Solution bundles
      • Defining solution bundles
      • How resolution works
      • Usage
    • Fleet and multi-tenant patterns
      • Recommended directory layout
      • Onboarding a new customer
      • Onboarding a customer into multiple zones
      • Team-shared variable defaults
    • Template resolution order (full)
    • Adding new template sources
      • Add a workspace single-file template
      • Add a workspace bundle directory
      • Add a solution bundle
  • Operating Strata at Scale — Multi-Tenant Design
    • Scenario
    • Three-Layer Bootstrap Architecture
      • Layer 0: Global Bootstrap (one-time)
      • Layer 1: Zone Bootstrap (per zone, stable)
      • Layer 2: Tenant Bootstrap (per tenant, per zone)
      • Tenant Slots (dedicated, per-tenant)
    • Workspace-per-Layer Pattern
      • Why one workspace per layer?
      • The three workspaces
      • Why this works at 400+ deployments
      • Layer boundaries are enforced by convention
      • Example deployment structure
    • New Concepts
      • Tenant Registry (kind: tenant)
        • Environment Merge Order
        • Per-Tenant File (tenants/{code}.yaml)
        • Tier Environment Files
        • Why One File Per Customer?
        • Validation Rules
      • Generated Deployments (per customer)
    • Variable Flow: Tenant Metadata → Terraform
      • spec.configuration is metadata, not Terraform input
      • How values actually reach Terraform
      • Pattern A — Tier-wide constants (same value for all customers in a tier)
      • Pattern B — Tenant-specific constants
      • Pattern C — CI-injected values
      • Feature flags → Terraform booleans
      • Secrets
      • Declaring required keys (spec.references)
      • Merge precedence (lowest → highest)
    • Cross-Workspace References
      • Why strata should know about it
      • How it works
      • Terraform can still use remote state directly
      • Validation rules
    • Hybrid Ownership Model
    • Zones and Data Residency
      • Zones in Configuration
      • Zones in Configuration
      • How zones link to providers
      • Customers reference zones
      • Zone deployments
      • Validation rules
      • Audit Trail
    • CLI Commands
      • strata tenant Command Group
      • Onboarding
      • Lifecycle
      • Slot Generation
      • Status Dashboard
      • Bulk Operations
    • Repository Strategy
    • Directory Structure
      • Config Repository ({team}-config)
      • Build Output
    • Scale Characteristics
    • Implementation Phases
      • Phase 1: Tenant Model + Directory-Based Discovery
      • Phase 2: Deployment Generation
      • Phase 3: Cross-Workspace Inputs
      • Phase 4: Lifecycle Commands
      • Phase 5: Data Residency Enforcement
    • Application Deployment via ArgoCD
      • How it works
      • ApplicationSet Generation
    • Open Questions
  • Building a Provisioner Plugin
    • Quick Start
    • Discovery Mechanism
    • The BaseDeployer Contract
      • Optional overrides
    • Constructor and Instance Variables
      • Accessing secrets and variables
      • Accessing the workspace model
    • Step Name Constants
    • Return Value Conventions
    • Timeout Helpers
    • Testing Your Plugin
    • Complete Examples
    • Checklist
  • Detecting Infrastructure Drift
    • What is drift?
    • Quick start
    • How it works
    • Severity levels
    • Command reference
      • drift run flags
    • Using severity thresholds
    • Checking one stage
    • Setting a baseline
    • Acknowledging expected drift
      • drift acknowledge flags
    • Viewing drift history
      • drift history flags
    • JSON output for CI
    • Drift history
    • Customising severity rules
    • Using drift in CI
      • Nightly scheduled drift check
    • Exit codes
    • Prerequisites
    • Related
  • Cost Estimation and Visibility
    • Overview
    • Prerequisites
    • Quick Start
    • Supported Providers
    • Commands
      • strata cost show
      • strata cost diff
      • strata cost history
    • Cost During Deploy (--dry-run)
    • Cost Policy (cost_threshold)
    • Configuration Reference
      • Integration entry (configuration.yaml)
    • Troubleshooting
  • Azure Lifecycle Scripts
    • Quick start — use a built-in script
    • Built-in scripts
      • azure_aks_credentials.py
      • azure_acr_login.py
      • azure_resource_group_ensure.py
    • Write a custom script
    • AzureScript reference
    • Environment variables in all lifecycle scripts
  • AWS Lifecycle Scripts
    • Quick start — use a built-in script
    • Built-in scripts
      • aws_eks_credentials.py
      • aws_ecr_login.py
      • aws_s3_bucket_ensure.py
    • Write a custom script
    • AWSScript reference
    • Environment variables in all lifecycle scripts
  • GCP Lifecycle Scripts
    • Quick start — use a built-in script
    • Built-in scripts
      • gcloud_gke_credentials.py
      • gcloud_artifact_registry_login.py
      • gcloud_gcs_bucket_ensure.py
    • Write a custom script
    • GCloudScript reference

Skills:

  • Strata Onboarding — AI Skill File
    • What is strata?
    • The Dependency Chain (Key Mental Model)
    • YAML Document Envelope (Required on Every File)
    • Onboarding Command Sequence
    • Cross-File References
    • Deployment Stages
    • Secret and Variable References
    • Common Patterns
      • Workspace with resources and modules
      • Deployment referencing workspace + environments
      • Module with services
    • Anti-Patterns to Avoid
    • Validation and Fix Suggestions
    • Guided Onboarding
    • Reference Examples
strata
  • Search


© Copyright 2025, Huybrechts XYZ.

Built with Sphinx using a theme provided by Read the Docs.