What setup owns — and what follows it
ops gcp setup provisions the hostable cloud substrate: APIs, VPC and subnet, Cloud Router/NAT, private buckets,
identities, registry access, GKE, Gateway IP, workload identity, Fleet integration, and KMS. It deliberately stops at
the cloud/cluster boundary. Finish the deployment through these adjacent owners:
| Need | Adjacent operation |
|---|---|
| DNS | Run navigator ops dns setup; DNS may be outside GCP, while setup owns only the stable Gateway IP. |
| TLS and Gateway manifests | Run navigator ops ship; it renders and applies Gateway, certificate, and routes. |
| Restate | Apply the Restate operator and manifests, then let ops ship re-register the worker. |
| Secret values | Run navigator ops secrets apply; decrypts and writes Secret Manager plus the Kubernetes Secret. |