torque
Build, verify, plan, apply

Agent-first Kubernetes delivery CLI.

torque is CI in a box for Kubernetes delivery: a file-first loop to build, verify, plan, apply, capture evidence, and inspect what happened. Captures, verifier reports, and chart archives are portable SQLite artifacts for CI, review, and later debugging without a running service.

curl -fsSL https://ingresslabs.github.io/torque/install.sh | sh
Canary and blue-green release promotion
Complex DAG stack orchestration
torque complex DAG stack orchestration workflow
Ship subcommand release flow
torque ship subcommand build verify plan apply explain workflow
DAG performance scheduling
torque DAG performance scheduling workflow
Sandboxed builds and secrets
torque sandboxed build and secret handling workflow
Helmer archives and verifier gates
Helmer HTML plan reports
Kubernetes logs and evidence capture
torque Kubernetes logging, event, and evidence capture workflow
Remote agent mirror sessions
torque remote agent MirrorService session workflow
Capture explain drilldown
torque explain capture drilldown workflow
Secret-safe build and log evidence
torque secret-safe build and log evidence workflow
Drift and plan comparison
torque drift and plan comparison workflow
Stack resume and rerun failed
torque stack resume and rerun failed workflow

Gone in 60 Seconds.

Modern CI/CD is too centralized and too complex. Torque flips that around: one tool for agents and operators, proof-based deploys, and real Kafka, GitLab, and Keycloak stacks on top.

Deploy platforms instead of charts.

One package carries profiles, app assets, Argo, Spark, Flink, Ray, Trino, Iceberg, Redpanda schema contracts, SigNoz, ClickHouse, a public payments API, S3-backed evidence, replay, and verification.

The release should explain itself.

A production Kubernetes PostgreSQL workload where Torque denied an agent twice, allowed it only after proof and policy passed, then captured a replayable stack ledger for review.

Sandboxing Docker like a Pro.

A deeper build systems note on nsjail sandbox profiles, BuildKit and Docker builder topology, S3 cache import/export, cache warming, hermetic mode, Docker auth boundaries, and agent-safe build evidence.

Atlassian Data Center as a Torque stack.

A field note on taking the Atlassian Data Center Helm charts through stack orchestration, secret:// references, verifier gates, Helmer plans, custom image builds, and proof-backed promotion examples.

One Torque talking to another.

The MCP and S3 cache showcase moved into a dedicated blog entry: a shorter field note on agent-driven delivery, the symbolic remote bridge, and the S3 BuildKit cache advisor path.

Secret-safe delivery path
torque secret-safe delivery path architecture diagram
Verifier and agent safety matrix
torque verifier policy coverage and agent safety matrix architecture diagram