[ Switch to styled version → ]
Early access. Enterprise blueprints are available in assisted deployments and may evolve during rollout. Review generated changes before applying them.
A blueprint is a single JSON document that describes an entire enterprise network. It is designed for infrastructure-as-code workflows and can be applied with a single command to provision the network.
A blueprint is a single JSON document that describes an entire enterprise network: its name, join rule, policies, identity provider, webhooks, audit export, role pre-assignments, and admin token. It is applied with one command to provision everything in a deterministic sequence.
Blueprints are designed for infrastructure-as-code workflows. They can be stored in version control, with changes reviewed in pull requests and applied through CI/CD pipelines.
{
"name": "prod-fleet",
"join_rule": "invite",
"enterprise": true,
"policy": {
"max_members": 100,
"allowed_ports": [80, 443, 1001],
"description": "Production fleet - US East"
},
"identity_provider": {
"type": "oidc",
"url": "https://accounts.example.com/.well-known/openid-configuration",
"client_id": "pilot-prod"
},
"webhooks": {
"audit_url": "https://ops.example.com/pilot-audit",
"identity_url": "https://ops.example.com/pilot-identity"
},
"audit_export": {
"format": "splunk_hec",
"endpoint": "https://splunk.example.com:8088/services/collector",
"token": "hec-token-here"
},
"roles": [
{"external_id": "[email protected]", "role": "admin"},
{"external_id": "[email protected]", "role": "member"}
],
"network_admin_token": "network-specific-secret"
}When a blueprint is applied, the registry executes these steps in order:
Each step is independent. If a later step fails, earlier steps are not rolled back, and the call returns an error immediately. The result's `actions` list names only the steps that succeeded. Failures are surfaced as the returned error, not itemized in the result.
Blueprints are idempotent. Applying the same blueprint twice produces the same result. The registry looks up the network by `name`.
This makes blueprints safe to apply repeatedly in CI/CD pipelines. Re-applying after a partial failure completes the remaining steps without duplicating already-completed ones.
The registry validates the blueprint before applying any changes.
If validation fails, no changes are made and the error is returned immediately. Policy fields like `max_members` and `allowed_ports` are not range-checked on the blueprint path. Those limits apply to the separate `set_network_policy` RPC.
To apply a blueprint:
{
"type": "provision_network",
"blueprint": {
"name": "prod-fleet",
"enterprise": true,
"policy": { "max_members": 100 }
},
"admin_token": "your-admin-token"
}The blueprint is the only payload field besides `admin_token`. The admin token is a global registry token. No network owner is assigned by the blueprint path, and there is no explicit `node_id` on the RPC.
Result format:
{
"network_id": 5,
"name": "prod-fleet",
"created": true,
"type": "provision_network_ok",
"actions": [
"created network 5 (prod-fleet)",
"enabled enterprise features",
"applied network policy",
"configured splunk_hec audit export to https://splunk.example.com:8088/..."
]
}The `created` field indicates whether a new network was created (`true`) or an existing one was updated (`false`).
For programmatic use, load a blueprint from a JSON file with the typed loader in the `common/registry/wire` package, then pass it to the client.
// Go SDK — the typed loader lives in common/registry/wire
import "github.com/pilot-protocol/common/registry/wire"
import "github.com/pilot-protocol/common/registry/client"
bp, err := wire.LoadBlueprint("network.json") // *wire.NetworkBlueprint
// ProvisionNetwork takes a map[string]interface{} blueprint + admin token.
// Marshal the blueprint JSON into a map, or build the map directly.
result, err := c.ProvisionNetwork(blueprintMap, adminToken)`wire.LoadBlueprint` reads and validates the JSON file, returning a typed struct. `client.Client.ProvisionNetwork(blueprint, adminToken)` takes the blueprint as a `map[string]interface{}` and the admin token. There is no explicit `nodeID` argument, and the blueprint path assigns no network owner.
Inspect the provisioning state of a network:
{
"type": "get_provision_status",
"admin_token": "your-admin-token"
}This command takes no `network_id` and returns a registry-wide summary of all networks. Per network, it returns enterprise status, policy, `idp_type`, an `audit` format string, a `webhook_enabled` flag, and an `rbac_pre_assignments` count. This is a summary, not full configs or endpoints. It is used to verify a blueprint was applied.