Deployment Files
Validate a .cosmoner/deployment.yaml from your own code, with no API key and no network call.
All three SDKs can check a deployment file — the
.cosmoner/deployment.yaml you commit to describe how a repository deploys —
against the format the platform reads. The check runs locally. It needs no API
key and makes no network call, so it works in a test suite, a pre-commit hook
or an offline build.
import { readFileSync } from "node:fs";
import { validateDeployment } from "@cosmoner/sdk";
const { valid, issues, template } = validateDeployment(
readFileSync(".cosmoner/deployment.yaml", "utf8"),
);
for (const issue of issues) {
console.log(`${issue.severity} ${issue.path}: ${issue.message}`);
}error services.0.run_command: Static sites cannot define a run_command
warning services.0.prot: Unknown field "prot" — it will be ignoredPass the file's raw text, not a parsed object. To check a file you generated
rather than read from disk, use validateDeploymentDocument
(validate_deployment_document in Python, Deployment::validateDocument in
PHP), which takes the parsed value instead.
The result
| Field | Description |
|---|---|
valid | Whether the file passes. |
issues | Every finding, each with a severity (error or warning), a path such as services.0.port, and a message. |
template | The file as the platform reads it: defaults filled in, unknown keys dropped. |
template is worth looking at. It is the settings that will actually arrive,
so comparing it with what you wrote catches a field that was silently ignored.
Errors and warnings
An error is something the platform would refuse: malformed YAML, a missing required field, two services with the same name.
A warning is something the platform accepts but you probably did not mean. The main one is an unknown key. The platform drops it rather than rejecting the file, so a file written for a newer field still works on an older deploy. Because of that, an unknown key does not fail the check by default — that would reject a file the platform accepts.
To catch typos anyway, pass strict ({ strict: true } in JavaScript,
strict=True in Python, strict: true in PHP). It changes the verdict, not
the finding: warnings then make valid false.
The same answer everywhere
The JavaScript, Python and PHP validators and the
cosmoner validate command are
tested against one shared set of example files, and they report the same
issues with the same messages in the same order. Checking a file in CI with the
CLI and again in a Python deploy script gives you one answer, not two.
Files are read as YAML 1.2, as the platform reads them: autodeploy: yes is
the string "yes", not a boolean.
Constants
| Name | Description |
|---|---|
DEPLOYMENT_FILE_PATHS | The locations the platform checks for a deployment file, in the order it checks them. Deployment::FILE_PATHS in PHP. |
APP_SCHEMA_URL | The published JSON Schema, for pointing an editor at. Deployment::APP_SCHEMA_URL in PHP. |