Skip to content

Astromesh Orbit

Astromesh Orbit turns one orbit.yaml into a running Astromesh stack on Google Cloud. It renders Terraform from templates, runs it with OpenTofu or Terraform, and wires the pieces together: a Cloud Run service for the runtime, PostgreSQL on Cloud SQL, Redis on Memorystore, Secret Manager, a VPC connector, a service account, and optionally a RAG documents bucket, an Artifact Registry, a monitoring dashboard and Cloud Trace.

Terminal window
astromeshctl orbit init # writes orbit.yaml
astromeshctl orbit plan # validates, renders, plans
astromeshctl orbit apply # asks, then provisions

Orbit is a plugin of the Astromesh CLI: installing astromesh-orbit adds the orbit subcommand to astromeshctl. Cortex drives the same commands from a wizard.

By handWith Orbit
Write and maintain the Terraform for ~20 resourcesKeep a ~40-line orbit.yaml
Create the state bucket before terraform initCreated (with versioning) on first plan or apply
Set up private services access so Cloud SQL has no public IPDone for you when you authenticate with a service-account key
Wire database, Redis, bucket and tracing into the container’s environmentRendered into the Cloud Run service
Check that a dozen APIs are enabledplan checks ten and prints the command for each missing one

Only orbit.yaml belongs in git. The rendered Terraform, its cache and orbit.env live in .orbit/, which orbit init adds to .gitignore. State lives in a GCS bucket, so any machine with the same orbit.yaml and credentials sees the same deployment.

ResourceFromNotes
Cloud Run v2 service astromesh-runtimespec.compute.runtime, spec.imagesPort 8000; public (allUsers can invoke it)
Cloud SQL for PostgreSQL <name>-dbspec.databasePrivate IP only, SSD, daily backups
Memorystore for Redis <name>-cachespec.cacheRedis 7.0 on the default network
Secret Manager secretsspec.secrets<name>-jwt-secret with a generated value; <name>-fernet-key, empty
VPC Access connectoralways10.8.0.0/28 on the default network; Cloud Run egress to private ranges only
Service account astromesh-orbitalwaysCloud SQL client, Redis editor, secret accessor, Run invoker
GCS bucket <project>-<name>-rag-docsspec.storage.rag_documentsOn by default
Artifact Registry <name>-imagesspec.storage.artifact_registryOn by default
Cloud Monitoring dashboardspec.observability.dashboardOn by default
OTel Collector sidecar → Cloud Tracespec.observability.tracingOff by default

Details for each one are in GCP Provider.

orbit eject writes the same Terraform as plain files with no Orbit dependency, plus a terraform.tfvars, pointing at the same state bucket. From there you run terraform yourself; nothing needs migrating.