What setup owns — and what follows it

ops gcp setup provisions the hostable cloud substrate: APIs, VPC and subnet, Cloud Router/NAT, private buckets, identities, registry access, GKE, Gateway IP, workload identity, Fleet integration, and KMS. It deliberately stops at the cloud/cluster boundary. Finish the deployment through these adjacent owners:

NeedAdjacent operation
DNSRun navigator ops dns setup; DNS may be outside GCP, while setup owns only the stable Gateway IP.
TLS and Gateway manifestsRun navigator ops ship; it renders and applies Gateway, certificate, and routes.
RestateApply the Restate operator and manifests, then let ops ship re-register the worker.
Secret valuesRun navigator ops secrets apply; decrypts and writes Secret Manager plus the Kubernetes Secret.