Skip to content

Configuration

All Orbit configuration lives in a single orbit.yaml file at the root of your project. This file is the only Orbit artifact committed to version control — everything else (generated Terraform, state, env files) lives in .orbit/ and is gitignored.

apiVersion: astromesh/v1
kind: OrbitDeployment
metadata:
name: my-astromesh # Deployment name (used in resource naming)
environment: production # develop | staging | production
spec:
provider:
name: gcp # Cloud provider: gcp (aws, azure in roadmap)
project: my-gcp-project-id # GCP project ID
region: us-central1 # GCP region
compute:
runtime: # Astromesh core runtime (agent execution)
min_instances: 1 # Minimum running instances (0 = scale to zero)
max_instances: 5 # Maximum instances under load
cpu: "2" # vCPUs per instance
memory: "2Gi" # Memory per instance
database:
tier: db-f1-micro # Cloud SQL machine tier
version: POSTGRES_16 # PostgreSQL version
storage_gb: 10 # Storage allocation in GB
high_availability: false # Enable HA replica (doubles cost)
cache:
tier: basic # basic (no failover) | standard (HA)
memory_gb: 1 # Redis memory allocation
secrets:
provider_keys: true # Create an empty <name>-fernet-key secret
jwt_secret: true # Generate <name>-jwt-secret on first deploy
images:
runtime: fulfarodev/astromesh:latest
env: # Extra env vars for the runtime container
ASTROMESH_LOG_LEVEL: INFO
FieldTypeRequiredDescription
namestringYesDeployment name. Prefix for most cloud resources and the Terraform state. Use lowercase alphanumerics and hyphens (GCP naming rules; Orbit does not check).
environmentstringNoOne of develop (default), staging, production. Recorded in the config; resource names do not depend on it.
FieldTypeRequiredDescription
namestringYesCloud provider identifier. Currently only gcp is supported.
projectstringYes (GCP)GCP project ID where resources will be created.
regionstringYesCloud region for all resources. Example: us-central1, europe-west1.

The runtime compute service accepts the fields below. With no compute.runtime block at all, the runtime gets cpu: "2", memory: "2Gi", max_instances: 5; the table’s defaults apply to fields left out of a block you do declare.

FieldTypeDefaultDescription
min_instancesint1Minimum running instances. Set to 0 to enable scale-to-zero.
max_instancesint3Maximum instances Cloud Run will scale to under load.
cpustring"1"vCPUs per instance, passed to Cloud Run as is (for example "1", "2", "4").
memorystring"1Gi"Memory per instance. Examples: "512Mi", "1Gi", "2Gi", "4Gi".
FieldTypeDefaultDescription
tierstringdb-f1-microCloud SQL machine tier. See GCP pricing.
versionstringPOSTGRES_16Cloud SQL database version, passed as is (for example POSTGRES_15, POSTGRES_16).
storage_gbint10Disk storage in GB. Auto-grows when needed.
high_availabilityboolfalseEnable regional HA with automatic failover. Roughly doubles the database cost.
FieldTypeDefaultDescription
tierstringbasicbasic for single instance, standard for HA with failover.
memory_gbint1Redis memory in GB. Minimum 1, maximum 300.
FieldTypeDefaultDescription
provider_keysbooltrueCreates one empty Secret Manager secret, <name>-fernet-key, with no version. Add a value with gcloud secrets versions add.
jwt_secretbooltrueCreates <name>-jwt-secret with a random 64-character value. It is generated once and kept in Terraform state, so later applies reuse it.
FieldTypeDefaultDescription
runtimestringfulfarodev/astromesh:latestContainer image for the Astromesh runtime.

Optional GCS resources for RAG documents and custom container images. Both blocks default to enabled: true.

spec:
storage:
rag_documents:
enabled: true # provision the GCS RAG documents bucket
versioning: true # keep object versions
artifact_registry:
enabled: true # provision a Docker Artifact Registry repo
repository: "" # empty -> "<metadata.name>-images"
FieldTypeDefaultDescription
rag_documents.enabledbooltrueProvision a GCS bucket for RAG source documents. The runtime receives its name as ASTROMESH_RAG_BUCKET.
rag_documents.versioningbooltrueKeep object versions on the RAG documents bucket.
artifact_registry.enabledbooltrueProvision a Docker Artifact Registry repository for custom images.
artifact_registry.repositorystring""Repository name. Empty defaults to <metadata.name>-images.

Orbit does not provision a separate vector database for RAG — pgvector runs on the Cloud SQL instance Orbit already deploys. See GCP Provider for details.

Optional. The Cloud Monitoring dashboard is on by default; Cloud Trace is opt-in because its collector sidecar adds a container to every Cloud Run instance.

spec:
observability:
dashboard: true # Cloud Monitoring dashboard (default: true)
tracing:
enabled: false # OTel Collector sidecar -> Cloud Trace (default: false)
collector_image: "otel/opentelemetry-collector-contrib:0.115.1"
FieldTypeDefaultDescription
dashboardbooltrueProvision a Cloud Monitoring dashboard charting Cloud Run golden signals (requests, latency, error rate, instance count).
tracing.enabledboolfalseAdd an OpenTelemetry Collector sidecar to the runtime Cloud Run service and set ASTROMESH_OTLP_ENABLED=1 on the runtime container so it exports spans to Cloud Trace.
tracing.collector_imagestringotel/opentelemetry-collector-contrib:0.115.1Container image for the OTel Collector sidecar.
FieldTypeDefaultDescription
envmap of string → string{}Extra environment variables set on the runtime Cloud Run container, after the ones Orbit sets (see GCP Provider). Values are written into the rendered Terraform and the Cloud Run configuration in plain text, so do not put secrets here.

There is no logging field — Cloud Run ships container logs to Cloud Logging automatically. See GCP Provider for how orbit logs reads them.

The orbit init wizard offers two presets that fill in all values automatically; --preset starter|pro picks one without the prompt. Both presets also write the default storage and observability blocks (tracing off), omitted below.

Best for development, demos, and small teams.

apiVersion: astromesh/v1
kind: OrbitDeployment
metadata:
name: my-astromesh
environment: develop
spec:
provider:
name: gcp
project: my-project-123
region: us-central1
compute:
runtime:
min_instances: 1
max_instances: 3
cpu: "2"
memory: "2Gi"
database:
tier: db-f1-micro
version: POSTGRES_16
storage_gb: 10
high_availability: false
cache:
tier: basic
memory_gb: 1
secrets:
provider_keys: true
jwt_secret: true
images:
runtime: fulfarodev/astromesh:latest

Best for production workloads with auto-scaling and high availability.

apiVersion: astromesh/v1
kind: OrbitDeployment
metadata:
name: my-astromesh
environment: production
spec:
provider:
name: gcp
project: my-project-123
region: us-central1
compute:
runtime:
min_instances: 1
max_instances: 5
cpu: "4"
memory: "4Gi"
database:
tier: db-g1-small
version: POSTGRES_16
storage_gb: 20
high_availability: true
cache:
tier: standard
memory_gb: 4
secrets:
provider_keys: true
jwt_secret: true
images:
runtime: fulfarodev/astromesh:latest

metadata.environment does not change resource names. Most resources are prefixed with metadata.name (and the Terraform state uses it as its prefix), but the Cloud Run service (astromesh-runtime) and the service account (astromesh-orbit) have fixed names, so two deployments in one GCP project collide. Use a GCP project per environment.

After orbit init and a first orbit plan/apply, your project will have:

your-project/
├── orbit.yaml # Committed to git
└── .orbit/ # Gitignored
├── generated/ # .tf files (re-rendered on every plan/apply)
│ └── .terraform/ # provider plugins and backend config
└── orbit.env # Terraform outputs, upper-cased (written after apply)