Temporal in Sysaro: only mutate deployments Sysaro can actually own
Temporal already participates in Service Fleet, readiness and typed configuration, but Sysaro intentionally does not rewrite an arbitrary existing installation. For foreign deployments the profile remains preview-only.
How the service fits into Sysaro
What already works
Service Catalog discovers a prepared Temporal systemd unit or canonical OCI workload and exposes backend, image and target.
Start, stop and restart use a constrained lifecycle adapter; readiness is checked through a separate loopback TCP probe.
The typed profile covers frontend address/port, metrics port, PostgreSQL persistence, the Temporal database and the visibility database.
Why apply is preview-only today
Temporal packaging and configuration semantics vary substantially between native and OCI deployments.
Sysaro cannot promise deterministic rollback when it does not own the image, volumes, credentials and startup contract of an existing installation.
The Control Plane therefore stores and renders a validated desired profile but reserves destructive apply for a canonical Sysaro-managed OCI deployment.
What the next level adds
Explicit OCI image and volume contracts instead of guessing a third-party unit layout.
Sealed PostgreSQL credentials delivered to the selected Agent without plaintext in desired-state JSON.
Transactional apply/rollback and production workflow topology owned end to end by Sysaro.
What this page does not claim
Detection, lifecycle or a typed subset is not described as complete management of every upstream capability. The canonical current scope is also published in service-evidence.json and the 18-service catalog.