The Container API spec is roughly two hundred lines of JSON, while the Autopilot one-liner does the same job with sound
defaults. The provisioner reserves a global static IP for the Gateway (so your DNS A record survives a cluster
re-create), creates the Autopilot cluster on the rapid release channel with the Secret Manager add-on, then registers
the cluster as a Fleet member. If you point --config-sync-repo at your fork, it also applies a Config
Sync RootSync so the cluster pulls
its manifests from Git. All three Navigator configs omit that flag: deployment-rendered navigator ops ship is their
sole manifest owner, so a RootSync cannot revert one site's environment-specific render.