# Deployments

Agent, Channel, AuthProvider, Policy and CredentialProvider releases use one managed upload API.

## Archive contract

Send a raw ZIP or tar.gz with exactly one of `constal.agent.json`, `constal.channel.json`, `constal.auth-provider.json`, `constal.policy.json`, or `constal.credential-provider.json`. Dependencies are installed from the submitted lockfile.

## Publication

The isolated builder type-checks the SDK contract, computes integrity evidence, publishes an immutable executable artifact, probes it, and creates an opaque deployment revision. CredentialProvider deployments publish reusable code packages into the provider catalog; installation separately binds namespace configuration and bootstrap Credentials.

Runs pin deployment revision, executable artifact, Policies, Resources and Toolset. A stable service name is never a mutable replay target.
