Ryvendeil.Deck.Cli
0.1.0-alpha.1
dotnet tool install --global Ryvendeil.Deck.Cli --version 0.1.0-alpha.1
dotnet new tool-manifest
dotnet tool install --local Ryvendeil.Deck.Cli --version 0.1.0-alpha.1
#tool dotnet:?package=Ryvendeil.Deck.Cli&version=0.1.0-alpha.1&prerelease
nuke :add-package Ryvendeil.Deck.Cli --version 0.1.0-alpha.1
Deck CLI
Deck CLI is the C# host coordinator. The current PoC implements:
deck up [--name Deck]as the concise appliance-install alias;deck appliance install|status|start|stop|delete [--name Deck]through oneIApplianceAdaptercontract;deck workspace apply|status|execfor declarative host bootstrap, scoped self-apply and bounded commands in the stable development Pod;- a Windows WSL adapter with structured readiness and graceful Deck Runtime/k0s shutdown before distribution termination; and
deck manifest compile --project ... --profile ... --mode run|publish --output ....
The CLI launches child processes only with bounded argument arrays. It does not construct shell commands. Windows uses wsl.exe --exec with fixed guest executables; macOS retains the same interface but intentionally throws until the Virtualization.framework helper exists and is tested on physical Apple silicon.
A Manifest project calls DeckManifest.RunAsync(args, application). The child protocol accepts a profile and emits canonical mode=model CBOR plus a one-line JSON response. Run/publish is never passed into the Framework resource graph: the CLI verifies canonical CBOR and changes only the mode after evaluation.
On Windows, deck appliance install invokes the checksum-verifying provisioning backend with bounded arguments and can explicitly replace only the named Deck distribution through --recreate true. The backend remains source-release packaging until signed CLI payloads replace the local release inputs. The command shape is also owned by the macOS adapter, which fails explicitly until the Virtualization.framework helper is implemented and tested on Apple silicon.
Public-alpha packages
The public-alpha artifacts are NuGet packages: install Ryvendeil.Deck.Cli as
the deck global tool and reference Ryvendeil.Deck.Framework from a Manifest
project. The repository's manually dispatched Publish public NuGet packages workflow
packs a requested prerelease version for review. Setting publish: true
requires approval of the protected release environment, then exchanges the
workflow's GitHub OIDC identity for a short-lived NuGet publishing key. Set the
repository variable NUGET_USERNAME to the NuGet.org username permitted to
create the trusted-publishing policy for the Ryvendeil organization. It is
the policy creator's individual profile name, not the organization name. No
long-lived NuGet key is stored;
users of either public package need no GitHub credential.
The dispatch input unlist defaults to true for prerelease distribution.
It publishes exact versions, then removes them from NuGet search; consumers can
still install an unlisted package by its exact ID and version. Set it to false
for a searchable release.
The current appliance installer still consumes a source release checkout while the separately versioned, verified appliance payload is completed. A public tool must fail explicitly if those release assets are unavailable; it must not fall back to Docker Desktop, a user package token or an unpinned download.
Workspace loop
From a repository containing .deck/workspace.yaml:
deck workspace apply
deck workspace status --workspace deck
deck workspace exec --workspace deck -- dotnet build Deck.slnx
The declaration currently pins its environment image by digest. The selected
next extension also accepts a repository-relative build declaration: Deck will
resolve it locally with on-demand rootless BuildKit and apply the resulting digest. Both
forms preserve declared Workspace volumes across an environment upgrade.
Toolchain output paths should target declared guest-ext4 volumes rather than
the host source mount; this repository sets .NET ArtifactsPath to
/workspace/.deck-cache/artifacts. The first restore populates durable
Workspace caches, while routine builds reuse them without an application image
build or Pod replacement. The same workspace apply command can run inside its
own Pod, where Kubernetes RBAC restricts it to that Workspace name.
VS Code Remote-SSH
Set spec.ide.kind: vscode and use a published digest-pinned Workspace image
that contains the declared guest toolchains. Then run:
deck workspace ide --workspace deck
The CLI creates one local Ed25519 identity under %LOCALAPPDATA%\\Deck,
projects only its public half into the Workspace-local Secret, starts a fresh
127.0.0.1 Kubernetes port-forward, and opens /workspace through VS Code
Remote-SSH. The initial identity authorisation deliberately rolls the
Workspace once so the projected key is present; subsequent opens reuse its
identity, IDE cache, stable Pod and guest build caches. No application image is
built and no port is exposed beyond the desktop loopback interface.
| Product | Versions Compatible and additional computed target framework versions. |
|---|---|
| .NET | net10.0 is compatible. net10.0-android was computed. net10.0-browser was computed. net10.0-ios was computed. net10.0-maccatalyst was computed. net10.0-macos was computed. net10.0-tvos was computed. net10.0-windows was computed. |
This package has no dependencies.
| Version | Downloads | Last Updated |
|---|---|---|
| 0.1.0-alpha.1 | 87 | 8/28/2026 |
Pre-alpha release. Interfaces and deployment contracts remain subject to change.