Skip to main content

Instance lifecycle

An instance is either running or it is not. Instances move through these states; the dashboard and CLI use sentence-case labels for API statuses, with started displayed as Starting: Three actions move an instance between these states:
  • Deploy boots a new enclave for an instance that has none: one that is Stopped, Failed, or still Stopping (the deploy runs once the stop finishes). It uses the saved configuration unless you change it first.
  • Update replaces the version a Running instance serves. Depending on the instance it either boots the new version alongside the current enclave or stops it first; see Updating.
  • Stop shuts the enclave down, moving the instance through Stopping to Stopped.
To run the same version on a fresh enclave, Update a blue/green instance to its current tag (no downtime), or Stop and then Deploy any instance (downtime). The dashboard polls for status updates automatically and updates the project counts.

Stopping and deploying an instance

Open an instance’s actions in the dashboard and click Stop to shut down its enclave. Its DNS records are removed so it is unreachable while stopped; its saved configuration and volumes are kept. Click Deploy to bring it up again. The deploy dialog lets you pick a different version or edit the configuration first, and for a Failed instance it shows the last error so you can fix it before trying again. Stopped is not a suspended memory image. Deploy boots a new enclave from the saved configuration and resolves current secret values. With key-secret and private-keyserver delivery, automatic unlock depends on the keyserver releasing the key after attestation. An attached disk at a mount without key-secret still needs the application’s manual unlock flow; an empty optional mount provides no persistent storage. Deployment alone is not proof that a retained disk is usable. See storage prerequisites. In-memory state and ephemeral filesystem writes do not survive Stop.

Deleting an instance

Click Delete on an instance to permanently remove it. This:
  • Stops the running enclave
  • Cancels any in-progress update
  • Deletes the instance’s secret bindings
  • Removes the instance from your org
  • Retains managed volumes as unattached disks; delete those volumes separately to erase their data
Deletion is irreversible. The instance’s configuration, secret bindings, and environment variables are permanently removed.

Using the CLI

The Tinfoil CLI exposes both project-level inspection and the individual instance lifecycle:
See the CLI reference for create flags, update controls, and scripting tips.