Import source, review detected defaults, and deploy one reproducible manifest.
Credentials stay in their connection stores, outside the application manifest.
Evidence is shown explicitly. Pick any strategy to override the recommendation.
Unsupported build/runtime combinations are rejected before provider mutation.
Container target uses the full-stack ECS/Fargate service path, including image/build, health, networking, and scaling settings.
Drafts store secret names only. Secret values must already exist in the environment secrets boundary.
Validation happens before a resource or DNS record is created.
This exact manifest is shared with CLI and API automation.