Docs

Orbit Yard — Scope of Service

Status: Active (product definition)
Updated: 2026-09-25
Canonical with: PRODUCT.md · PLATFORMS-AND-PORTAL.md · shipping-hub-north-star.md · OPERATOR-NEXT.md · verify-status-layers-design · Overhaul: ship-studio-overhaul-design · human-gate-catalog-design

One sentence

Orbit Yard is a local portal and guide for release work: it sequences the final mile (sign → release → deploy and adjacent lanes) across many project kinds, runs scripts for highly automatable steps, and uses semi-automated wizards when official channels require the human — without replacing vendor platforms.

Value thesis (why pay vs SaaS starter kits)

Indie and multi-repo operators lose time on order and human gates, not on “another template.” Orbit Yard earns its price when the Client makes OSS cuts, marketplace listings, host deploys, and commerce gates finishable without surviving vendor encyclopedias — and when MCP lets agents assist without taking custody of keys. Linking Docs is not a product.


Who we serve

PrimarySecondary (not yet)
Solo / small teams with many repos (OSS + a few paid products) who need one local hub for diverse release workflowsLarge orgs needing multi-tenant cloud control planes
Operators who ship multi-surface products (Web/API + desktop Signet + optional stores/commerce)Teams that want Orbit Yard to replace Cloudflare / Polar / store consoles
Founders / operators who can own vendor accounts but should not need DevOps fluency to finish a cut (Client pathway)People seeking full auto-publish without human attestation
Agent-assisted teams (Cursor / MCP) who keep keys under human controlPeople who only need a single wrangler deploy with no sequence

Power users who already live in Signet / Orbit / gh remain welcome; they are not the only ICP. The Client must not assume CLI literacy.


In scope (the service)

1. Detect

Probe a local project directory for shipping signals (Wrangler/Vercel/Netlify, Tauri/signet.toml, Dockerfile, stores, markets, CI release workflows, legal/trust files, suite.json, etc.).

2. Plan

Build an Adaptive Publish plan (General = short path; Advanced = full OAuth / listing / submit / CI / container / marketing / suite):

  • Ordered steps with honest detail
  • Related desktop_view to the right detail panel
  • Safe local Run / Continue scripts where a CLI exists (Signet, Orbit, docker build, gh list, npm/cargo --dry-run, …)
  • Human-gate CTAs per human-gate-catalog-design: Put / Login CLI / exact deep link / Confirm — not Docs as the path (ship-studio-overhaul-design)

3. Sequence

Drive the minute spine on CLI · TUI · Desktop · MCP:

Continue (Auto / scriptable) · Open / Run → (human + vendor) → Confirm → Next (official-channel gates)

Progress lives in project .ship/publish.json (no secret values). Desktop shows done · required · later. Optional Watch polls local Verify — still never finishes OAuth/store/DNS for you.

4. Orient

  • Doctor — tools required for this layout
  • Pulse — Dashboard Now / Continue mid-publish with step-specific cut hints
  • Assist — checklist overview (not a second wizard)
  • Portal / Env / Secrets — entry URLs + paste-put assist; optional encrypted .km vault export

5. Honesty

  • Offline bridge: Studio does not call vendor HTTPS with secrets
  • Never store secret values in .ship/ plaintext
  • Never claim verified publisher / SmartScreen silence unless true
  • Never auto-docker push, live npm|cargo publish, or gh release create
  • Desktop-only ships: Signet release is the deploy (no fake Orbit desktop host)
  • Status layers (verify-status-layers-design): disk · local CLI · official CLI probe (operator-gated Verify/Watch) · human attest — provider remains authority for irreversible done

Out of scope (not the service)

CategoryExamples
Content / marketingProduct docs sites, feature demos, GIF authoring, narrative copy
Vendor replacementReplacing Cloudflare, Vercel, Apple, Play, Gumroad, Steam UIs
Finishing without the humanOAuth completion, store review, DNS cutover, certificate purchase
Dangerous automationRegistry push, live package publish, store API upload, k8s controllers
Secret custody as productBecoming the team’s password manager (vault export is optional backup only)
Build-system replacementRewriting Signet / Orbit / provider CLIs inside this repo
Portfolio SaaS (v0)Multi-root cloud hub, paid unlock bands, hosted multi-tenant control plane

Human remaining work is listed in OPERATOR-NEXT.md — that checklist is part of the service boundary, not a backlog of Studio bugs.


Responsibility split

┌─ Orbit Yard ─────────────────────────────────────────┐
│ Detect · Plan · Sequence · Orient · Honest Verify     │
│ Status: disk · local CLI · official CLI probe         │
│ Local CLI Runs (safe / dry-run / read-only preferred) │
└───────────────────────────┬───────────────────────────┘
                            │ Open / Run handoff
┌───────────────────────────▼───────────────────────────┐
│ Human + vendor platforms (authority for irreversible) │
│ Tokens · OAuth · store review · DNS · live publish    │
│ docker push · npm/cargo publish · release create      │
└───────────────────────────────────────────────────────┘

Studio succeeds when the operator always knows the next human gate and has a one-action path (Put / Login CLI / exact dashboard deep link) — not a reading assignment.
Studio does not fail when the vendor rejects a submission or DNS is wrong — that remains operator/vendor responsibility.


Delivery surfaces (Client · MCP · CLI)

Same engine (orbityard). Three pathways — like CodaCtrl Studio + CodaCtrl MCP, or Ghidra + Ghidra MCP: humans get a UX client; agents get a protocol; neither replaces the other.

PathwaySurface todayRoleFee bar
ClientDesktop (Tauri); TUI as terminal clientUX-friendly spine for operators without DevOps fluency — exact next human act, never vendor docs as the pathCharge only if a non-technical account-holder can finish gates without encyclopedic docs
MCPorbityard mcp (ship_*)Automated assistance for agents; plan / continue / watch / open gatesKeys and vendor logins stay human-managed; agents orchestrate, they do not own secrets
CLIorbityardShared kernel + power-user/script surfaceNot the default buyer story if Client is good; still required under Desktop and MCP
┌─ Client (Desktop / TUI) ─┐     ┌─ MCP (agents) ─┐
│  Human gates · Put/Login │     │  ship_* tools  │
│  Confirm · plain recover │     │  no key custody│
└────────────┬─────────────┘     └────────┬───────┘
             └────────────┬───────────────┘
                          ▼
                   orbityard (CLI kernel)
         detect · plan · publish · portal · secrets put · …

Surface laws

  1. Client primary for paid UX — human gates use catalog CTA law: Put / Login / exact deep link / Confirm — never “go read Workers Secrets” as the path (overhaul).
  2. MCP assists; humans hold keys — paste/put and OAuth stay operator-initiated (TTY or vendor UI).
  3. CLI is kernel, not the product pitch — if Client is excellent, most buyers never open a shell; orbityard still powers Client + MCP.
  4. No vendor-onboarding theater — in-app coaches that still dump people into encyclopedias are CANCELLED (vendor-handoff-coach-design).
  5. One spine — Publish remains the integrated workflow; detail panels open from the current step.

Detail: surfaces-cli-tui-desktop.md · Human gates: OPERATOR-NEXT.md


Success criteria (service outcomes)

  1. For a bound project, Advanced/General plan matches layout (no nonsense Orbit desktop deploy, no missing CI after release).
  2. Operator can complete a cut without assembling eight nav destinations by hand.
  3. Mid-flight state survives restart (.ship/publish.json).
  4. Dogfood: cargo test -p orbityard · scripts/dogfood-advanced-*.sh.
  5. Real proof: publish at least one of your products end-to-end using Studio for sequence.
  6. Client honesty: a founder-owned account can finish a secret/OAuth gate via Put/Login without being stranded on jargon docs as the primary path.

Allowed future growth (still in scope)

  • New Adaptive lanes only when a real ship needs them (release-surface map)
  • Deeper safe Runs / Verify honesty
  • Better Desktop/TUI ergonomics on the same spine
  • Suite URL sync and multi-product paste cues

Deferred / not promised

  • Mobile store API upload
  • Kubernetes / Helm automation
  • Hosted multi-tenant SaaS control plane
  • Auto-finishing OAuth or store review

Positioning line (release)

Orbit Yard — local final-mile hub: Client for humans, MCP for agents, CLI as kernel. Sign → release → deploy, sequenced. Vendors and humans still do the irreversible bits.