Skip to content

cwp launch

shipped 1.0.0
cwp launch <env> [flags]

Acts on the environment you name. There is no local default, so you name one.

tree ← site

ArgumentWhat it isDefault
<env>environment to launch
FlagWhat it doesDefault
--with-agentwith —dry-run on a host with no shell: install and remove the PHP agent so the plan is realoff

Plus the shared flags --json, -v, --verbose, -q, --quiet and --dry-run.

What it does

Runs the launch list against an environment and, when no line fails, sets its stage to live. Every line is a check cwp already has:

✓ launch — prod — 7 checks
✓ perimeter — site public
✓ edge — none in front
✗ captcha — turnstile site key on prod is the sandbox key, and every submission passes
  → cwp edge captcha prod writes the zone's widget into the builder
✓ mail guard — not installed
✓ scrub — none
! inventory — recorded from dev, not prod
  → cwp pull --only inventory prod
✓ reasons — none spent
✗ 1 of 7 — prod stays in build
  → fix the lines marked ✗ above, then run cwp launch prod again

A failure stops the launch and names its fix. A warning prints and does not stop it. When every line holds, cwp writes the stage with its reason, and cwp log prod carries the entry:

    # because: cwp launch: 7 checks passed | since: 2026-09-05 | by: cwp launch
    stage: live

The lines. The perimeter as declared, against what the site and the edge hold. The edge’s TLS mode, script rewriting and captcha widgets. The captcha key, the mail guard and the scrub’s placeholder accounts, judged as launch. The inventory’s source. The reasons in cwp.yml whose until is spent.

A second run against an environment already live is the same list without the write.

cwp launch prod
cwp launch prod --dry-run     # the list, and nothing set

What it does not do

  • It does not take --force. A launch with a red line is not one.
  • It does not write to the environment. It reads, and it writes one line in cwp.yml and one entry in the environment’s log.
  • It does not read the backup age. No provider says when it last took a backup. Take one before the launch, the way an upward write does.
  • It does not go back. live to build is cwp config set environments.prod.stage build --because "…".

TODO