<!-- llms-explorer concept facts · https://llms-explorer.com/tree/app-services-cli-deployment/ · pack 2026-10-02 · ~12747 tokens -->

# App Services CLI Deployment

> Depth-first rabbithole dossier for App Services CLI Deployment; source-anchored research pack.

Parent: [MongoDB Atlas Triggers and Functions](https://llms-explorer.com/tree/mongodb-atlas-triggers-and-functions/) · 6 facets · 74 facts · page: https://llms-explorer.com/tree/app-services-cli-deployment/

## Structure and components

- Source: https://www.mongodb.com/docs/atlas/app-services/realm-cli/v1/ 11. `realm-cli` v1 read `app_id` from a legacy `config.json`. Its `export --for-source-control` option stripped `name`, `app_id`, `location` and `deployment_model` so the export could be deployed via GitHub. — https://www.mongodb.com/docs/atlas/app-services/realm-cli/v1/ 12. `realm-cli` v2 renamed the verbs to `push` ("Imports and deploys changes… (alias: import)") and `pull` ("Exports… (alias: export)"). It also added named `--profile` support. — https://www.mongodb.com/docs/atlas/app-services/realm-cli/v2/ 13. `appservices — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#changes-to-the-deploy-model-across-versions`

## How it works

- **Handoffs for concept-family-explorer (not chased here):** GitHub automatic deployment, Admin API v3 deployment endpoints, deployment-model and region migration, managing Triggers after App Services end-of-life, and migrating `realm-cli` scripts to `appservices`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#5-gates-and-saturation`
- - **C1. The Atlas CLI has no `appservices` subcommand.** The parent says "Install Atlas CLI (recommended — bundles the appservices subcommand)" and "Prefer `atlas appservices`". This is not supported. The official `atlas` command reference lists 36 top-level commands, and none is `appservices`, `app-services` or `realm`: https://www.mongodb.com/docs/atlas/cli/current/command/atlas.md - **C2. The CLI is the standalone npm package `atlas-app-services-cli`, and its binary is `appservices`.** Install it with `npm install -g atlas-app-services-cli`: https://www.mongodb.com/docs/atlas/app-services/c — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#corrections-to-inherited-parent-facts`
- - GitHub automatic deployment for App Services (a sibling item). - Changing deployment models and regions (`deploymentMigrations`). - Moving triggers and functions after App Services end of life. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#handoffs-not-researched-here`
- 14. `appservices push` creates or updates a remote app from a local directory. It takes a Client App ID (to update an app) or a name (to create one). "Changes pushed are automatically deployed." https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push/ 15. A push diffs the local config files against the deployed config. It then creates a draft from the diff and deploys that draft. There is no separate "stage" step. https://www.mongodb.com/docs/atlas/app-services/apps/update/ 16. Use `-x/--dry-run` for a no-op preview. Use `-y/--yes` to skip prompts, which non-interactive CI needs. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#push-and-pull-mechanics`
- - Managing Atlas Triggers after App Services EOL (Atlas UI and any Admin API or Terraform path). - The App Services Admin API v3 deployment endpoints as a standalone concept. - Migrating `realm-cli` scripts to `appservices`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#handoffs-not-researched-here`
- Report codes: **M** = mechanism, **H** = history, **E** = edge-cases, **P** = practice. Inherited parent sources are left out of the gate: `/docs/atlas/app-services/cli/` (and its `.md` twin) and the parent's `deploy/automated-deployment` URL. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md`
- **Independent-origin gate (inherited sources excluded).** I counted origins, not hosts. MongoDB counts as one origin across docs, the Admin API, the docs repo, realm-cli source, pkg.go.dev and the GitHub App page. npm counts as vendor-published records. - **Concept level: MET.** It has four vendor-independent origins: softinstigate, siliconangle, dev.to and Wikipedia. Lifecycle and history claims clear three origins: MongoDB, softinstigate, and Wikipedia or siliconangle. - **Push mechanism (P3–P12, R1–R5): PARTIAL.** These rest on the vendor plus user reports on the vendor's own forum. The onl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#5-gates-and-saturation`
- Out of scope: trigger and function runtime behavior, Device Sync, the Data API, auth providers, and the general Atlas CLI. Those are separate frontier items. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#scope`
- **Out of scope.** Sibling and parent topics are separate frontier items: trigger and function semantics, Device Sync, Data API, the Atlas CLI in general, and CI/CD design in general. Parent facts are not repeated here. Only corrections and child-specific details appear. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#scope`
- - https://www.mongodb.com/docs/atlas/app-services/cli/ - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push/ - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy/ - https://www.mongodb.com/docs/atlas/app-services/realm-cli/ - https://www.mongodb.com/docs/atlas/app-services/realm-cli/v1/ - https://www.mongodb.com/docs/atlas/app-services/realm-cli/v2/ - https://www.mongodb.com/docs/atlas/app-services/apps/deploy-github/ - https://www.mongodb.com/docs/atlas/app-services/apps/cicd/ - https://www.mongodb.com/docs/atlas/app-services/deprecation/ - https://www.mo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#sources`
- **Out of scope:** what triggers and functions do at runtime, the auth, rules and sync features, the GitHub app itself, other CI systems, and moving to non-App-Services platforms. Those belong to the parent or sibling frontier items. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#scope`

## Measurements and reference values

- - **D1.** A zipped `node_modules` must not exceed 15 MB. [E] https://www.mongodb.com/docs/atlas/app-services/functions/dependencies.md - **D2.** The most recently used dependency method wins, so a package added in the UI overrides an uploaded archive. [E] - **D3.** App Services transpiles dependencies at deploy time. [E] - **D4.** With drafts disabled, a dependency change takes 5–60 seconds to take effect, and calls in that window can see the old dependencies. This makes M's inference (C26) a sourced fact for the drafts-disabled path. [E, M] - **D5.** `require()` must be called inside function — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2e-function-dependencies`
- | Pass | Focus | New claims | Total | Rate | |---|---|---|---|---| | 0 | CLI, push, pull, config docs | 22 | 22 | 100% | | 1 | Admin API drafts, deploy config, CI/CD doc | 9 | 31 | 29% | | 2 | realm-cli source (step order, errors, polling) | 8 | 39 | 21% | | 3 | Lifecycle, disconfirm Atlas CLI, history | 6 | 45 | 13% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#pass-curve-new-information-rate`
- There were no two consecutive passes under 5%, so this is not saturated. A fifth pass would likely still pay off on D4: deploy atomicity, rate limits, and the GitHub auto-deploy interaction with CLI drafts. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#pass-curve-new-information-rate`
- | Pass | Focus | New claims | Total | New-info rate | |---|---|---|---|---| | 0 | CLI reference | 14 | 14 | 100% | | 1 | deploy, drafts, GitHub, rollback, templates | 15 | 29 | 52% | | 2 | disconfirmation (npm, Atlas CLI, forum, dev.to) | 7 | 36 | 19% | | 3 | pull semantics, independent EOL report | 2 | 38 | 5% | — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#saturation`

## Problems, failure modes and limitations

- - **R1.** A draft is "a group of application changes that you can deploy or discard as a single unit". [M] https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/group/endpoint-deploy - **R2.** `POST …/drafts` creates a draft "if none exists" and returns **409** if one already does. [E] https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/operation/operation-admincreatedeploymentdraft - **R3.** If an API or CLI deploy conflicts with an open UI draft, the UI draft becomes undeployable. MongoDB's advice is to make changes "in one place at a time". [M, P] - **R4.** E — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2f-drafts-the-admin-api-and-rollback`
- 27. Once automatic deployment is enabled, App Services "immediately deploys the latest commit for the configured branch and directory": https://raw.githubusercontent.com/mongodb/docs-app-services/master/source/apps/deploy-github.txt 28. In CLI v1.1.0 and later, a CLI push automatically creates a matching GitHub commit. In CLI v1.0.3 and earlier, pushes deploy without a commit. The docs say to avoid CLI changes on those versions because GitHub stops being the source of truth: https://raw.githubusercontent.com/mongodb/docs-app-services/master/source/apps/deploy-github.txt 29. **Stale-repo overwr — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#interaction-with-github-automatic-deployment`
- 16. Automatic GitHub deployment uses the "MongoDB Atlas App Services" GitHub App, published by MongoDB. The app deploys "whenever you push updated configuration files to a GitHub repository." — https://github.com/apps/mongodb-atlas-app-services 17. A push to the configured repository, branch and directory deploys the latest commit immediately. Changes made in the UI are committed back to the repo by the `mongodb-realm` bot. — https://www.mongodb.com/docs/atlas/app-services/apps/deploy-github/ 18. In App Services CLI v1.0.3 and earlier, a CLI push to a GitHub-linked app deployed the change but — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#cli-and-automatic-github-deployment`
- 22. App Services reached end-of-life on 2025-09-30. The services removed on that date were Device Sync, the SDKs, the Data API, GraphQL, Static Hosting and HTTPS Endpoints. — https://softinstigate.com/en/blog/posts/mongodb-deprecates-data-api/ , https://www.mongodb.com/docs/atlas/app-services/deprecation/ 23. MongoDB states: "The App Services Admin API and CLI are not deprecated. However, they have endpoints and commands that rely on deprecated services. These endpoints and commands are deprecated." Database triggers and the Functions they call remain available. Authentication triggers are dep — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#status-after-end-of-life`
- 1. Atlas App Services has reached end of life and MongoDB no longer actively supports it. Every CLI and deploy page now carries the banner: "Triggers remain available in the Atlas UI." https://www.mongodb.com/docs/atlas/app-services/cli/ 2. Database Triggers are not deprecated. Functions remain available, but only in the context of Triggers. Authentication Triggers are deprecated. https://www.mongodb.com/docs/atlas/app-services/deprecation/ 3. "The App Services Admin API and CLI are not deprecated." However, any of their endpoints and commands that rely on deprecated services are deprecated. h — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#lifecycle-status-read-first`
- 25. When GitHub automatic deployment is on, App Services deploys the latest commit on the configured branch and directory at once. https://www.mongodb.com/docs/atlas/app-services/apps/deploy-github/ 26. With CLI v1.1.0 or later, a CLI push to a GitHub-linked app creates a matching commit in GitHub. With CLI v1.0.3 or earlier, a CLI push deploys without committing back. A later commit to the stale repo then overwrites the pushed changes. https://www.mongodb.com/docs/atlas/app-services/apps/deploy-github/ 27. UI edits on a GitHub-linked app are committed back by the `mongodb-realm` bot. If the r — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#interaction-with-github-auto-deploy-ui-drafts-and-the-admin-api`
- - **X1. There is no `atlas appservices` subcommand.** The Atlas CLI top-level reference lists about 36 commands, including `api`, `plugin` and `streams`. None of them is `appservices`, `app-services`, `realm` or `triggers`. No App Services plugin was found. The parent's line "Install Atlas CLI (recommended — bundles the appservices subcommand)" is unsupported. [M, H, E, P] https://www.mongodb.com/docs/atlas/cli/current/command/atlas.md - **X2. The supported install is `npm install -g atlas-app-services-cli`.** The binary is `appservices`. [M, E, P] https://registry.npmjs.org/atlas-app-services — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#1-corrections-to-inherited-parent-facts-child-deltas-highest-impact-first`
- - **H1.** `mongodb-stitch-cli` ran from 1.0.0 (2018-07-02) to 1.13.0 (2020-05-06). npm marks it "Package no longer supported." [H] https://registry.npmjs.org/mongodb-stitch-cli - **H2.** MongoDB Realm entered beta on 2020-06-09. It merged the acquired Realm company with Stitch. [H] https://siliconangle.com/2020/06/09/mongodbs-new-release-helps-unify-data-sources/ - **H3.** `mongodb-realm-cli` 1.0.0 shipped on 2020-06-09 and 2.0.0 on 2021-07-13. Its source is the Go module `github.com/10gen/realm-cli`, licensed Apache-2.0. [H] https://registry.npmjs.org/mongodb-realm-cli · https://pkg.go.dev/gi — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2a-lineage-and-history`
- - **P1.** `push` "Pushes and deploys changes". "Changes pushed are automatically deployed", with no stage step. The target is a Client App ID (update) or a name (create). [M, H, E, P] https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - **P2.** Push flags: `--local`, `--remote`, `--include-node-modules` (a directory or a .zip/.tar/.tar.gz/.tgz archive), `--include-package-json`, `-s/--include-hosting` and `-c/--reset-cdn-cache` (both deprecated with Static Hosting), `-x/--dry-run`, `-n/--deployment-name`, `--project`. Global flags: `-y`, `-f json`, `-o`, `--telemetry`, `-- — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2d-push-and-pull-mechanics`
- - **G1.** Deploys use the MongoDB-published "MongoDB Atlas App Services" GitHub App. [H] https://github.com/apps/mongodb-atlas-app-services - **G2.** Once enabled, App Services "immediately deploys the latest commit for the configured branch and directory". The `mongodb-realm` bot commits UI changes back. [H, E, P] https://raw.githubusercontent.com/mongodb/docs-app-services/master/source/apps/deploy-github.txt - **G3.** From `appservices` v1.1.0 (2024-02-07), a CLI push creates a matching GitHub commit. On v1.0.3 and earlier it does not, and GitHub stops being the source of truth. [H, E, P] - — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2g-interaction-with-github-auto-deploy`
- - **S1.** "The App Services Admin API and CLI are not deprecated. However, they have endpoints and commands that rely on deprecated services. These endpoints and commands are deprecated." [M, H, E, P] https://www.mongodb.com/docs/atlas/app-services/deprecation.md - **S2.** Database triggers stay available. Functions stay available only "within the context of Triggers"; functions called from a Device SDK must migrate. Auth triggers are deprecated, so pushing them deploys logic that never fires. [H, E, P] - **S3.** Commands marked deprecated: `accessList`, `schema`, `users`, plus push's `-s`/`-c — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2i-lifecycle-after-end-of-life`
- 1. MongoDB says the App Services Admin API and the CLI are not deprecated. Commands that depend on deprecated services are deprecated: https://www.mongodb.com/docs/atlas/app-services/deprecation.md 2. Database triggers are not deprecated. Functions remain available, but only "within the context of Triggers". Functions called directly through a Device SDK must migrate: https://www.mongodb.com/docs/atlas/app-services/deprecation.md 3. Authentication triggers are deprecated. Once App Services Authentication is gone, they no longer fire on login or create events. A pushed config that still contain — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#lifecycle-and-support-status`
- 14. A zipped `node_modules` dependency directory "may not exceed 15MB": https://www.mongodb.com/docs/atlas/app-services/functions/dependencies.md 15. Only one dependency method is in effect at a time: "The most recent method that you used to specify dependencies is the source of truth and overrides previous specifications." For example, a package added by name in the UI overrides an uploaded archive: https://www.mongodb.com/docs/atlas/app-services/functions/dependencies.md 16. App Services transpiles dependencies at deploy time. Accepted archive formats are `.tar`, `.tar.gz`, `.tgz` and `.zip` — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#dependencies-largest-source-of-failures`
- 33. An app can have at most one deployment draft. `POST /groups/{groupId}/apps/{appId}/drafts` creates one "if none exists" and returns 409 if one already does: https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/operation/operation-admincreatedeploymentdraft 34. `ui_drafts_disabled` controls whether a UI save deploys immediately or goes into a draft: https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/group/endpoint-deploy 35. Changing the deployment model or region is done through the UI or Admin API only; the page has no CLI tab. The change "is not a draft" — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#drafts-and-deployment-migration`
- - **D1. Does EOL include Functions?** MongoDB's deprecation page says Functions "continue to be available within the context of Triggers" (https://www.mongodb.com/docs/atlas/app-services/deprecation.md). A third-party summary (DreamFactory; search snippet only, page returned 403) says MongoDB deprecated "the entire Atlas App Services platform, including Functions" (https://dreamfactoryapi.medium.com/mongodb-killed-its-rest-api-heres-what-actually-happened-and-what-to-do-now-b4269226f245). SoftInstigate (2025-02-04) limits the deprecation to the Data API and HTTPS Endpoints and does not mention — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#unresolved-disagreements`
- 1. The first npm release of `mongodb-stitch-cli` ("The MongoDB Stitch Command Line Interface") was 1.0.0 on 2018-07-02. Its last release was 1.13.0 on 2020-05-06. npm now marks it "Package no longer supported." — https://registry.npmjs.org/mongodb-stitch-cli 2. MongoDB Realm launched in beta on 2020-06-09. It combined the acquired Realm company with Stitch, "the company's original serverless platform." — https://siliconangle.com/2020/06/09/mongodbs-new-release-helps-unify-data-sources/ 3. `mongodb-realm-cli` 1.0.0 was published on 2020-06-09, the same day as the Realm launch. 2.0.0 followed on — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#lineage-and-timeline`
- 1. **The parent claim "Install Atlas CLI (recommended — bundles the appservices subcommand)" / "Atlas CLI (`atlas appservices` subcommands)" is wrong.** The current Atlas CLI command reference lists no `appservices`, `app-services` or `realm` top-level command. Its top-level commands run from `accessLists` through `users`, and the list includes `api`, `plugin` and `streams`. https://www.mongodb.com/docs/atlas/cli/current/command/atlas.md The App Services docs still say to install the standalone package: `npm install -g atlas-app-services-cli`. https://www.mongodb.com/docs/atlas/app-services/cl — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#corrections-to-inherited-parent-facts-most-important-first`
- - C11. An app is defined entirely by JSON config files plus JS source files. The root directories are `auth/`, `data_sources/`, `environments/`, `functions/`, `graphql/`, `hosting/`, `https_endpoints/`, `log_forwarders/`, `sync/`, `triggers/` and `values/`, alongside `root_config.json`. https://www.mongodb.com/docs/atlas/app-services/reference/config.md - C12. The names `stitch.json`, `config.json`, `root_config.json` and `app_config.json` are reserved. If a file with one of these names fails its component schema, the CLI throws an error on import. https://www.mongodb.com/docs/atlas/app-servic — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#the-local-unit-of-deployment`
- - C17. `appservices push` "Pushes and deploys changes". You can omit an explicit deploy step because "Changes pushed are automatically deployed." https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - C18. The target is either the Client App ID of an existing app (update) or the name of a new app (create). https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - C19. Push flags: `--local`, `--remote`, `--include-node-modules` (a directory, or a `.zip`/`.tar`/`.tar.gz`/`.tgz` archive), `--include-package-json`, `-s/--include-hosting`, `-c/--reset-cdn-cache` ( — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#push-what-actually-happens`
- https://raw.githubusercontent.com/10gen/realm-cli/master/internal/commands/push/command.go - C21. Invariant (idempotence): if nothing differs, push exits with "Deployed app is identical to proposed version, nothing to do". https://raw.githubusercontent.com/10gen/realm-cli/master/internal/commands/push/command.go - C22. Limit: `--dry-run` cannot create an app. It stops with "This is a new app. To create a new app, you must omit the 'dry-run' flag to proceed". https://raw.githubusercontent.com/10gen/realm-cli/master/internal/commands/push/command.go - C23. If the user already has a draft (`ErrCo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#push-what-actually-happens`
- - D1. **Is the CLI usable or end of life?** The page banners say App Services "has reached its end-of-life status and is no longer actively supported". The same docs' deprecation page says "The App Services Admin API and CLI are not deprecated", and only the commands that depend on retired services are deprecated. npm shows no deprecation flag. Both readings are recorded here and left unresolved. https://www.mongodb.com/docs/atlas/app-services/cli.md · https://www.mongodb.com/docs/atlas/app-services/deprecation.md · https://registry.npmjs.org/atlas-app-services-cli - D2. **Exact end-of-life da — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#unresolved-disagreements-and-gaps`
- Caveat: third-party coverage of CLI *deployment* itself is thin. Most failure-mode evidence comes from vendor-hosted community forum posts written by users. Claims 21 and 37 and the DreamFactory side of D1 rest on search snippets because the pages returned 403. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#quality-gate`
- - C29. A draft is "a group of application changes that you can deploy or discard as a single unit". https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/group/endpoint-deploy - C30. Invariant: each user can have only one draft at a time, whether created in the UI or through the API. You must discard an existing draft before you can create another. https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/group/endpoint-deploy - C31. Conflict rule: if you deploy through the API (which the CLI uses) while a UI draft has conflicting changes, the UI draft becomes invalid — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#drafts-and-the-server-side-deploy-model-admin-api-v3`
- - **Pick one source of truth.** Use either GitHub auto-deploy or CLI-in-CI, not both with build-time config mutation (claims 26, 29, 35). If CI must transform config, turn off auto-deploy. - **Pin the CLI version in CI.** Use `npm i -g atlas-app-services-cli@2.1.5`. Versions 1.0.3 and earlier break the GitHub source of truth (claim 26), and the product gets no active support (claim 1). - **Grant the least privilege available.** Push needs Project Owner (claim 9), so a CI key holding it can change the whole project. Scope the key to a dedicated project, and put CI egress IPs on its access list — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#trade-offs-and-implications`
- The gate is met with a caveat. Seven hosts were used: mongodb.com docs, registry.npmjs.org, raw.githubusercontent.com (MongoDB's docs repo), github.com (the GitHub App page), pkg.go.dev, siliconangle.com and softinstigate.com. Only siliconangle.com and softinstigate.com are fully independent of MongoDB. npm timestamps are machine records but are published by MongoDB. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#quality-gate`
- - **C1. The Atlas CLI has no `atlas appservices` subcommand.** The parent claims "Install Atlas CLI (recommended — bundles the appservices subcommand)" and "Prefer `atlas appservices`". Both claims are wrong. The top-level `atlas` command list contains no `appservices` or `app-services` command. https://www.mongodb.com/docs/atlas/cli/current/command/atlas/ - **C2. The supported install is the standalone npm package.** Run `npm install -g atlas-app-services-cli`. It installs the binary `appservices`. https://www.mongodb.com/docs/atlas/app-services/cli/ and https://registry.npmjs.org/atlas-app-s — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#corrections-to-inherited-parent-facts`
- The gate is met. The primary source is mongodb.com docs: CLI reference, deploy, rollback, templates, deprecation, Atlas CLI and Admin API pages. The independent hosts are registry.npmjs.org (package release dates and versions), dev.to (field CI recipe) and softinstigate.com (EOL date). The disconfirming sources are the Atlas CLI command list (which contradicts the inherited claim) and the MongoDB community forum (which reports a failure mode). The forum is on mongodb.com, so it is not host-independent. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#quality-gate`
- - https://www.mongodb.com/docs/atlas/app-services/cli/ - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push/ - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-pull/ - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy/ - https://www.mongodb.com/docs/atlas/app-services/deprecation/ - https://www.mongodb.com/docs/atlas/app-services/apps/update/ - https://www.mongodb.com/docs/atlas/app-services/apps/deploy-github/ - https://www.mongodb.com/docs/atlas/app-services/apps/rollback/ - https://www.mongodb.com/docs/atlas/app-services/apps/cicd/ - htt — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#sources`

## Comparisons and alternatives

- - **The parent claims an Atlas CLI `atlas appservices` subcommand exists.** The current Atlas CLI root reference lists no `appservices`, `app-services`, `realm` or `triggers` subcommand. The App Services CLI is still the separate `appservices` binary from npm `atlas-app-services-cli`. https://www.mongodb.com/docs/atlas/cli/current/command/atlas/ , https://www.mongodb.com/docs/atlas/app-services/cli/ . **Verdict:** the parent's install advice ("Install Atlas CLI… bundles the appservices subcommand") is unsupported. - **The parent calls `appservices` "legacy" alongside `realm-cli`.** The primary — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#unresolved-disagreements-and-corrections-to-inherited-context`
- 1. **Supported or end-of-life?** The deprecation page says the CLI is "not deprecated" (S1). Every CLI page's banner says App Services is "no longer actively supported" (X4). npm kept shipping after end-of-life (S4). P reads this as "available, unsupported, maintenance-mode". No source says whether `push` regressions still get fixed. [M, H, E, P] 2. **The 2025-09-30 end-of-life date.** M treats it as **unverified**: the forum notice returned 403 and Wikipedia gives only the September 2024 announcement. H and P treat it as confirmed via softinstigate plus the deprecation page. 3. **What softins — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#3-disagreements-kept-side-by-side`
- - **Atlas CLI versus standalone CLI.** The parent skill says to prefer `atlas appservices`. Official docs and the Atlas CLI command list show no such command (C1, C2). The parent claim looks like an error, not a version difference. No source supports it. - **Is CLI push safe with GitHub auto-deploy on?** The docs say it is safe from CLI v1.1.0 (claim 26). A 2024 field report says auto-deploy still built from the raw repo contents (claim 35). The report predates CLI 2.x and involves CI mutating files the repo did not hold, so the two may not conflict. No source settles the question. - **What "n — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#unresolved-disagreements`
- - **L1.** An app is a tree of JSON config plus JS source: `auth/`, `data_sources/`, `environments/`, `functions/`, `graphql/`, `hosting/`, `https_endpoints/`, `log_forwarders/`, `sync/`, `triggers/`, `values/` and `root_config.json`. [M] https://www.mongodb.com/docs/atlas/app-services/reference/config.md - **L2.** These file names are reserved: `stitch.json`, `config.json`, `root_config.json`, `app_config.json`. If one fails its component schema, the import errors. [M] - **L3.** `root_config.json` requires `name`, which must be 1–32 characters from `[A-Za-z0-9_-]`. It also holds `deployment_mo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2c-the-local-unit-of-deployment`
- `.md` and trailing-slash forms are the same page. **Inherited** sources are excluded from the gate. - https://www.mongodb.com/docs/atlas/app-services/cli/ (inherited; also cited as `cli.md`) - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-pull.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy-configure.md - https://www.mongodb.com/docs/atlas/app-services/apps/cicd.md - https://www.mongodb.com/docs/atlas — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#6-source-list-union-of-the-four-reports-no-urls-added`
- - Concurrency when two CI jobs push with the same key, given disagreement 6. - Deploy rate limits and size limits beyond the 15 MB dependency cap. - When GitHub auto-deploy first shipped (Stitch-era docs were not retrieved). - `appservices apps diff` / `apps create`, and the `secrets` and `function run` pages. - Whether a mistyped `--remote` combined with `-y` creates a new app instead of failing. This is an **untested inference** from P1 plus `-y` [E]; check it with `--dry-run`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#4-open-gaps-not-answered-by-any-report`
- 1. I returned the synthesis inline and wrote no file. Bash was denied in this run, so I couldn't check sibling run folders for an output-file convention. I didn't touch the concept tree, as you asked. If your pipeline expects a file, the obvious path is `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/synthesis.md`. Default: inline only. 2. Two factual conflicts need one more fetch before the tree uses them. The last `mongodb-realm-cli` version is 2.6.0 in one report and 2.6.2 in another (both cite https://regis — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#needs-input`
- - Claim 9 says the push target can be a new app name, and claim 10 says `-y` auto-accepts prompts. A mistyped `--remote` value with `-y` might therefore create a new app instead of failing. This was not tested and no source confirms it. Check it with `--dry-run` before relying on either behavior. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#open-risk-inference-not-a-sourced-claim`
- - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - https://www.mongodb.com/docs/atlas/app-services/cli.md - https://www.mongodb.com/docs/atlas/app-services/deprecation.md - https://www.mongodb.com/docs/atlas/app-services/apps/cicd.md - https://www.mongodb.com/docs/atlas/app-services/functions/dependencies.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy.md - https://www.mongodb.com/docs/atlas/app-services/apps/change-deployment-models.md - https://www.mongodb.com/docs/atlas/cli/current/command/atlas.md - https://www.mongodb.com/docs/api/doc/a — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#sources`

## Facts and statements

- In scope: deploying an Atlas App Services app with the `appservices` CLI (`atlas-app-services-cli`) and its predecessor `realm-cli`. That covers `push` and `pull` semantics, dependency upload, auth in CI, interaction with GitHub automatic deployment, drafts, and the CLI's status after App Services end-of-life. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#scope`
- **In scope.** This report covers the command-line tools that deploy Atlas App Services (formerly Stitch and Realm) app configuration: `stitch-cli`, `realm-cli` v1 and v2, and `appservices`. It also covers how they push and pull configuration, how CLI pushes interact with automatic GitHub deployment, and their status after App Services reached end-of-life. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/history.md#scope`
- In scope: the `appservices` CLI and the deployment paths it shares an app with. That covers CLI push and pull, GitHub automatic deployment, Admin API drafts, rollback, and environment templating. The report covers operational use, trade-offs and limits, all as they stand after the App Services end of life. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#scope`
- 31. App Services can redeploy any of an app's 25 most recent deployments, from the UI or the Admin API. For older versions, you must redeploy config files from source control. https://www.mongodb.com/docs/atlas/app-services/apps/rollback/ 32. A redeploy restores configuration only. The rollback page does not document a CLI redeploy. With the CLI, the usual rollback is to check out an older commit and push it again (an inference from claims 14 and 31). https://www.mongodb.com/docs/atlas/app-services/apps/rollback/ 33. On a GitHub-linked app, a rollback also produces a `mongodb-realm` bot commit — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#rollback`
- - **A1.** The CLI authenticates with `appservices login --api-key=<pub> --private-api-key=<priv>`, using a programmatic API key pair. [M, P] - **A2.** Write access needs **Project Owner**. Read-only access works with Project Read Only. A CI deploy key therefore holds the broadest project role. [M, E, P] - **A3.** The key's API Access List must include the caller's IP. CI runners with changing egress IPs need an entry that covers them. [M, E, P] - **A4.** Profiles are plaintext YAML files that hold the key and a session token, which the CLI reuses until it expires. Paths: macOS `~/Library/Appli — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2b-install-auth-and-profiles`
- 8. `push` deploys immediately: "Changes pushed are automatically deployed." There is no separate review step unless you use `--dry-run`: https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md 9. The `push` target "can be either the application Client App ID of an existing app … or the Name of a new app you would like to create". The same command therefore either updates an existing app or creates a new one: https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md 10. `-y, --yes` auto-accepts every prompt. MongoDB's CI guide uses `appservices push --remote=$REALM — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#push-semantics`
- 22. Write access needs a programmatic API key with the **Project Owner** role. Read-only access can use Project Read Only. This means a CI deploy key holds the broadest project role: https://www.mongodb.com/docs/atlas/app-services/cli.md 23. The key's API Access List must include the caller's IP. "The IP Address of the user who will be using the API Key is required to use the key." That is a problem for CI runners with ephemeral IPs: https://www.mongodb.com/docs/atlas/app-services/cli.md 24. If you log in with a named profile, every later command must also pass `--profile`, "otherwise App Serv — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#authentication-in-ci`
- **In scope:** how the `appservices` CLI deploys an App Services app. That covers the install, auth, profiles, the local config directory and the `.mdb` metadata, the `push` and `pull` mechanics, drafts and the deploy pipeline it drives through the Admin API, the automatic-deployment controls, the documented limits, and the CLI's current lifecycle status. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#scope`
- - C1. The CLI is distributed on npm as `atlas-app-services-cli` and needs Node.js. https://www.mongodb.com/docs/atlas/app-services/cli.md - C2. The npm package was created on 2022-12-08. Its declared source is `github.com/10gen/baas`, directory `cmd/cli`, and its license is Apache-2.0. https://registry.npmjs.org/atlas-app-services-cli - C3. Recent releases: 2.0.2 (2024-09-16), 2.0.3 and 2.0.4 (both 2024-10-14), 2.1.0 (2025-02-11), 2.1.1 (2025-03-24), 2.1.2 (2025-07-25), 2.1.4 (2025-08-08), 2.1.5 (2025-10-09). https://registry.npmjs.org/atlas-app-services-cli - C4. Authentication uses a MongoDB — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#install-auth-profiles`
- Disconfirming evidence was found for the parent's `atlas appservices` claim (C1) and for its framing of App Services as an active product (C3). — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#quality-gate`
- - C28. `appservices pull` exports the remote app into a local directory. It can include dependencies (`--include-node-modules` or `--include-package-json`) and hosting files. It supports `-x/--dry-run`, `-t/--template` (frontend template IDs) and `--project`. https://www.mongodb.com/docs/atlas/app-services/cli/appservices-pull.md — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#pull`
- The base path is `https://services.cloud.mongodb.com/api/admin/v3.0/groups/{groupId}/apps/{appId}`. https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/group/endpoint-deploy - C33. The deploy config field `ui_drafts_disabled` controls UI edits. If it is `true`, every UI save deploys at once. If it is `false`, UI edits collect in a draft. `automatic_deployment.{enabled, provider:"github", installation_ids}` controls auto-deploy. https://www.mongodb.com/docs/api/doc/atlas-app-services-admin-api-v3/operation/operation-adminconfiguredeployment - C34. The CLI exposes the auto-deplo — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#drafts-and-the-server-side-deploy-model-admin-api-v3`
- - https://www.mongodb.com/docs/atlas/app-services/cli.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-push.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-pull.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy.md - https://www.mongodb.com/docs/atlas/app-services/cli/appservices-deploy-configure.md - https://www.mongodb.com/docs/atlas/app-services/apps/cicd.md - https://www.mongodb.com/docs/atlas/app-services/reference/config.md - https://www.mongodb.com/docs/atlas/app-services/reference/config/app.md - https://www.mongodb.com/ — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#sources`
- 8. The CLI authenticates with an Atlas programmatic API key pair: `appservices login --api-key=<pub> --private-api-key=<priv>`. https://www.mongodb.com/docs/atlas/app-services/cli/ 9. Write access needs a key with the Project Owner role. Read-only access works with Project Read Only. https://www.mongodb.com/docs/atlas/app-services/cli/ 10. The key's API Access List must include the caller's IP address. CI runners with changing egress IPs therefore need an access-list entry that covers them. https://www.mongodb.com/docs/atlas/app-services/cli/ 11. Named profiles (`--profile`) store the key and — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#authentication-and-identity`
- - **E1.** The pattern is one app per stage, each with its own App ID. Create with `appservices push -y --project=<id>` and update with `appservices push --remote=$APP_ID -y`. Delete ephemeral apps afterwards. [M, H, E, P] cicd URL - **E2.** A 2023 third-party recipe used `npm i -g mongodb-realm-cli`, then `realm-cli login … -y`, then `pull`, overlay the build output, then `push -s -c -y`. It depends on Static Hosting and is off the recommended path. [E, P] https://dev.to/ninefyi/github-actions-for-mongodb-atlas-app-services-2mhg — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/rabbithole-synthesis.md#2h-multi-environment-pipeline`
- More passes would likely add to two areas. The first is forum threads blocked by 403 (`invalid app diff request`, breaking-schema push, `root_config.json`). The second is `appservices apps diff` and `apps create`. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/edge-cases.md#saturation-note`
- - C35. MongoDB's documented pattern is one app per stage (dev, staging, prod), each with its own Client App ID. To create an app: `appservices push -y --project=<id>`. To update one: `appservices push --remote=$APP_ID -y`. https://www.mongodb.com/docs/atlas/app-services/apps/cicd.md - C36. The doc gets a new app's ID by parsing `appservices app describe` output with `sed`. Using `-f json` (C10) is the more robust variant; that is our inference. https://www.mongodb.com/docs/atlas/app-services/apps/cicd.md — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#multi-environment-pipeline-pattern`
- - H1. MongoDB acquired Realm in spring 2019. In September 2024 it announced the deprecation of Device Sync. https://en.wikipedia.org/wiki/Realm_(database) - H2. The CLI lineage is `realm-cli` (Go, `github.com/10gen/realm-cli`) → `appservices` (npm `atlas-app-services-cli`, from 2022-12, source at `10gen/baas/cmd/cli`). The two share the push design and flag vocabulary, but `appservices` adds `--deployment-name` (not in the realm-cli master flag list) and drops `--include-dependencies`. https://github.com/10gen/realm-cli · https://registry.npmjs.org/atlas-app-services-cli · https://www.mongodb. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/mechanism.md#history-only-what-is-specific-to-this-concept`
- Method: `/rabbithole` depth passes. Pass 0 used the official CLI reference. Pass 1 covered the deploy, draft, GitHub, rollback and template mechanics. Pass 2 looked for disconfirming evidence in the npm registry, the Atlas CLI command list, the community forum and third-party posts. Pass 3 covered pull semantics and an independent deprecation report. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#scope`
- 21. The `"environment"` field in the root config selects a values file. The `%(%%environment.values.<key>)` expansion pulls values from that file. With no environment set, the app resolves `environments/no-environment.json`. https://www.mongodb.com/docs/atlas/app-services/reference/config/template-expansions/ 22. Expansions work only on string-valued fields, not on boolean, number, object or array fields. https://www.mongodb.com/docs/atlas/app-services/reference/config/template-expansions/ 23. Expansions resolve **once, at app creation**. After that, the app holds a resolved copy of the config — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#environments-and-templating`
- Not reached: GitHub source for the CLI. The npm repository field points to the private `10gen/baas` repo. Two of five attempted fetches returned 404 or 403. — source: `~/.global-ai-hub/research-tests/mongodb-full-frontier-20261002/full-frontier-run/app-services-cli-deployment-3bc20afd51/reports/practice.md#quality-gate`

## Related concepts

- CLI — is a part of App Services CLI Deployment
- App — is a part of App Services CLI Deployment
- Services — is a part of App Services CLI Deployment
- Deployment — is a part of App Services CLI Deployment
