salesforce-deploy-integration

v2026.09.24

Deploy a Salesforce-connected application through immutable artifacts, environment binding, canary traffic, reconciliation, and rollback. Use when releasing adapter code. Trigger with "deploy a Salesforce integration".

GitHub
安装命令
npx skhub add jeremylongshore/salesforce-deploy-integration
Markdown
SKILL.md

Salesforce-Connected Application Deployment

Overview

Release customer-owned adapter code independently of Salesforce metadata while proving the target org, secrets, API contract, and business invariants.

Prerequisites

  • Immutable application artifact, source commit, dependency lock, SBOM or equivalent inventory, and deployment target
  • Approved Salesforce app and principal, target-org identity, supported API contract, and secret references
  • Preview environment, canary, health and business checks, capacity budget, rollback, and incident owners

Tool Discipline

Use Read, Glob, and Grep to inspect approved repository and evidence files, WebFetch to re-check current first-party Salesforce documentation, and Write or Edit only for secretless plans, fixtures, configuration, and redacted receipts.

Current Contract

A Salesforce-connected application may run on many compute platforms; Salesforce does not define one universal deployment target. The application must bind to the customer-approved org, OAuth app, API version, limits, schema, and event contract.

Authentication

Inject only secret references through the target platform after environment approval. Never bake Salesforce tokens, keys, usernames, org IDs, or production domains into images, frontend bundles, build logs, or artifacts.

Instructions

  1. Freeze the artifact digest, source SHA, dependencies, configuration schema, Salesforce API contract, and migration set.
  2. Verify target environment, org identity expectation, app type, principal, scopes, permissions, secret references, egress, and observability.
  3. Deploy to preview with synthetic Salesforce fixtures and prove startup, health, timeout, redaction, idempotency, and rollback.
  4. With approval, bind an authorized sandbox and run read-only plus bounded mutation contract checks.
  5. Define production canary percentage or workload, time box, stop signals, shared-limit budget, and reconciliation queries.
  6. Promote the same artifact, verify org identity before traffic, monitor technical and business invariants, and halt on breach.
  7. Reconcile outcomes, complete or rollback, revoke temporary access, and record artifact, deployment, and verification IDs.

Approval Boundaries

Do not deploy a different artifact, inject production secrets, route production traffic, run migrations, or expand a canary without named approval.

Output

Return artifact and environment identity, configuration contract, sandbox proof, canary plan, deployment IDs, signals, reconciliation, rollback status, and owners.

Error Handling

ConditionResponse
Artifact or configuration digest changedStop promotion and rebuild the review evidence for the new candidate.
Application connects to the wrong orgCut traffic, revoke credentials, assess data exposure, and invoke incident response.
Salesforce limit margin drops below the approved stop signalPause intake and reconcile queued work before resuming.

Example

A redacted completion receipt might look like this:

artifact=sha256-recorded; target=production; org=matched; canary=5-percent; signals=healthy; reconciled=yes; rollback=ready

Resources

Next Steps

Run the workflow first in the lowest-risk authorized org and preserve its redacted receipt. Schedule a review against the next Salesforce seasonal release and the customer change calendar.

发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.24

发布时间

Sep 24, 2026

分类

未分类

许可证

MIT

源路径

skills/.curated/salesforce-deploy-integration

默认分支

main

最新提交

e5a6c3b

Tree SHA

c2dc8e8