Resource Tags

Resource Tags let you label service instances, My Apps, and My Pages with free-text tags, then group everything that shares a tag into a project view — a single page listing every resource tagged with it, with a one-click cleanup action to delete the whole group at once.

A "project" is not a separate object — it's just a tag. Any resource can carry multiple tags and belong to multiple projects at the same time.

Status: Resource Tags shipped 2026-09-26 and is currently available on the dev environment only. It has not yet been deployed to production.

What You Can Do

  • Add or remove tags on a service instance, My App, or My Page from its existing card/row menu
  • Filter your instance list, My Apps list, or My Pages list by tag
  • Click any tag chip to open a project view listing every resource (across all three resource types) that shares that tag
  • Delete every resource in a project at once, with a confirmation dialog that lists what will be deleted and flags resources that also belong to other projects
  • Manage tags programmatically via the deploy-manager API or the list-resource-tags / set-resource-tags MCP tools

Using the Web Console

Tags appear as small chips alongside existing status chips (e.g. Lock/Private) on:

  • Instance cards — a Manage tags item in the card's overflow dropdown opens the tag editor
  • My Apps list (Dashboard → My Apps) — a filter bar above the list, and Manage tags in the row's actions
  • My Pages list (Dashboard → My Pages) — same pattern: filter bar plus Manage tags in the row's actions
  • My Running Services list (Dashboard → Home, redesigned dashboard only) — each service row shows the union of tags carried by your running instances of that service, capped at 2 chips plus a "+N more" chip; rows with no tagged instances show no chip

Click any tag chip to open its project view at /dashboard/tags/<tag>. This page is only reachable by clicking a chip — there is no sidebar entry for it. It lists every instance, My App, and My Page carrying that tag (showing each resource's other tags too), and has a Delete everything in this project action. The confirmation dialog lists every resource that will be deleted and warns if a resource also belongs to a different project, before anything is removed.

Deleting a service instance or My App through the normal delete flow automatically removes its tag entries — you don't need to untag before deleting.

MCP Tools

Two MCP tools are available for AI agents and MCP clients:

  • list-resource-tags — lists tagged resources, optionally filtered by tag and/or resourceType (instance, myapp, mypage). Called with no filters, it also returns the distinct list of tags with per-tag resource counts (the "project list").
  • set-resource-tags — adds and/or removes tags on a resource in one call ({ add: [...], remove: [...] }).

API Reference

All endpoints require a PAT passed as Authorization: Bearer <pat> in the x-pat-jwt header. The tenant is always derived from the token — never from the path, query, or body.

Base URL (dev): https://deploy.svc.dev.osaas.io

type ResourceType = 'instance' | 'myapp' | 'mypage';

interface ResourceTagEntry {
  resourceType: ResourceType;
  serviceId?: string; // only present for 'instance'
  resourceId: string;
  tags: string[];
  updatedAt: string;
}

List tagged resources

curl -s -H "x-pat-jwt: Bearer $PAT" \
  "https://deploy.svc.dev.osaas.io/resourcetags?tag=myproject&resourceType=instance"

Both query parameters are optional. Response: { "resources": ResourceTagEntry[] }

List distinct tags (project list)

curl -s -H "x-pat-jwt: Bearer $PAT" \
  https://deploy.svc.dev.osaas.io/resourcetags/tags

Response: { "tags": [{ "tag": "myproject", "count": 3 }, ...] }

Add/remove tags on a resource

curl -s -X PATCH \
  -H "x-pat-jwt: Bearer $PAT" \
  -H "Content-Type: application/json" \
  -d '{"add": ["myproject"], "remove": ["old-tag"]}' \
  https://deploy.svc.dev.osaas.io/resourcetags/instance/eyevinn-web-runner/myinstance

PUT replaces the tag set entirely; PATCH applies add/remove deltas. Both return the resulting ResourceTagEntry (200). Available resource paths:

Resource type Path
Service instance /resourcetags/instance/:serviceId/:instanceName
My App /resourcetags/myapp/:appId
My Page /resourcetags/mypage/:pageId

PUT/PATCH on a My App or My Page path returns 404 if the resource doesn't exist. A service instance path is not existence-checked.

Remove all tags from a resource

curl -s -X DELETE \
  -H "x-pat-jwt: Bearer $PAT" \
  https://deploy.svc.dev.osaas.io/resourcetags/myapp/myapp-id

DELETE is idempotent and always returns 204, whether or not the resource had any tags. Note: send this request without a Content-Type header — Fastify rejects a DELETE with Content-Type: application/json and no body.

Validation Rules

Rule Limit Error
Tag length 1–64 characters (after trim), no control characters 400 invalid_tag
Tags per resource Max 20 400 too_many_tags
Registry size Max 512 KiB per tenant (all tags combined) 409 tag_registry_full
Concurrent writes Retried automatically up to 5 times 409 conflict_retries_exhausted

Tags are deduplicated case-insensitively, keeping the casing of the first tag added.

Resources