Publish a Private Marketplace Package
Use this guide to package a deployable template for your organization marketplace. It creates a private release only. It does not deploy an application, grant public visibility, or approve a package.
Know the publication boundary
Section titled “Know the publication boundary”package create ↓unsigned local tar.gz artifact ↓package publish ↓private organization releasePackage publish is private by default. Its public flag requests review after upload; do not use that flag in this workflow. There is no 1ctl command that approves a package. Approval belongs to the platform administrator process.
There is also no package-delete command. Treat a private release as a durable organization record, not a disposable smoke test.
Create a manifest-bundle package
Section titled “Create a manifest-bundle package”Start with a package-specific satusky.toml. The image must be immutable and digest-pinned. The package creator rejects Docker build settings, mutable image tags, environment values, placement, and autoscaling settings.
[app]name = "internal-status-page"port = 8080cpu_request = "100m"cpu_limit = "250m"memory = "128Mi"
[build]image = "registry.example.com/internal-status-page@sha256:<64-hex-digest>"Create the archive with an explicit destination:
1ctl package create \ --config satusky.package.toml \ --output internal-status-page.tar.gzThe command writes an owner-only local artifact and refuses to overwrite an existing path. Without a build target architecture, it declares both amd64 and arm64. Set target_arch to amd64 or arm64 only when the image is single-architecture. The creator records the declaration; it does not inspect the image manifest.
Package an embedded Helm chart when needed
Section titled “Package an embedded Helm chart when needed”Use a self-contained chart for a multi-container or stateful template:
1ctl package create --chart ./chart --output internal-stack.tar.gzChart.yaml needs a semantic version and this annotation:
annotations: satusky.com/supported-architectures: amd64,arm64Every literal image reference must be digest-pinned. The package check does not run Helm or download dependencies. It rejects chart dependencies, hooks, CRDs, symbolic links, mutable image tags, and unsupported nondeterministic template functions.
Templates must meet the marketplace workload security policy. Set pod seccomp to RuntimeDefault and configure every container as non-root, with privilege escalation disabled and all Linux capabilities dropped.
Publish privately and inspect the release
Section titled “Publish privately and inspect the release”Confirm the active organization:
1ctl auth statusPublish without the public flag:
1ctl package publish internal-status-page.tar.gzThe response identifies marketplace ID, release ID, archive digest, and private visibility. Keep the release ID for traceability:
1ctl package list1ctl package status <release-id>Both commands are scoped to the active organization.
Public review is a handoff
Section titled “Public review is a handoff”Only an intentional publisher handoff should use:
1ctl package publish --public --reason "Reason for review" artifact.tar.gzThat command uploads the artifact and requests review; it does not approve the release. This guide deliberately does not exercise that path. Follow the organization administrator process outside 1ctl, and wait for the platform visibility/status before treating a release as public.
Deploy an approved package separately
Section titled “Deploy an approved package separately”Package publication is not readiness. Use the catalog and normal application lifecycle after a package is available:
1ctl marketplace list1ctl marketplace get <package-name>1ctl marketplace deploy <package-name> <deployment-name>1ctl app status <deployment-name>Marketplace deployment acceptance is asynchronous. Inspect package metadata for required secrets, stateful retention, replica limits, health endpoint, and declared architectures before deployment. For the marketplace/runtime boundary, see Marketplace & Templates.