Cross-LifeTime Promotion is an OutSystems 11 LifeTime plugin that promotes an application from an environment managed by one LifeTime (source) to an environment managed by another LifeTime (target), with 4-eyes approval and a full audit log.
It solves a gap in standard LifeTime: a deployment plan can only move apps between environments registered in the same LifeTime. Teams that run separate LifeTimes (for example Dev + UAT in one, Production in another) otherwise have to download and upload packages by hand.
Key features
Both LifeTimes must run LifeTime 11.22.0 or later, the first version with cross-infrastructure deployment through the LifeTime API.
Service account tokens are shown only once by LifeTime. On LifeTime versions before 11.29 a newly generated token revokes the previous one immediately.
Install the plugin in the target LifeTime environment's own Service Center; LifeTime cannot deploy to itself.
https://<target-lifetime-host>/ServiceCenter
RegisterPluginOnPublish
If the menu link opens with "Registered role required" (common on OutSystems Cloud), the timer registered the server's internal host name. Open the plugin through the public LifeTime address, go to Setup check > Register plugin in LifeTime menu, then set the site property RegisterOnPublish to False so later publishes keep that link.
RegisterOnPublish
The module uses the ServiceCenter user provider, so anyone signed in to LifeTime is signed in to the plugin. Only the LifeTime SDK modules that LifeTime already has are referenced; do not publish a solution pack that contains LifeTime's own modules.
All settings are site properties of module CrossLifeTimePromotion (Service Center > Factory > Modules > CrossLifeTimePromotion > Site Properties).
https://source-lifetime.company.com/lifetimeapi/rest/v2
https://prod-lifetime.company.com/lifetimeapi/rest/v2
Timer schedule. Give the ProcessPromotions timer a schedule (for example every 5 minutes) in Service Center > Factory > Modules > CrossLifeTimePromotion > Timers. Without a schedule, approved requests only move when someone clicks Run Now.
ProcessPromotions
Setup check screen. Open Setup check from the Promotions screen (LifeTime infrastructure permission required). It shows whether each setting is set (tokens are never shown), offers Test source connection and Test target connection, and the Register plugin in LifeTime menu button.
Logging. Keep the LifeTimeAPI integration's Logging Level at Default. Full logging records request headers, which include the service account token.
LifeTimeAPI
A promotion needs two people: one requests it, another approves it; the plugin then deploys it in the background.
Request a promotion
Approve or reject
Open the request and click Approve or Reject. The buttons appear only for a user who is not the requester and has Change & Deploy on the target environment.
Track progress
The detail screen shows the Source → Target header, a progress tracker (Requested, Approved, Package, Upload, Deploy, Completed), the current message and the deployment log. While a deployment runs, the page refreshes every 30 seconds and checks the target LifeTime itself; Check status now forces an immediate check.
Needs intervention
If the target reports conflicts or asks for user intervention, review the plan in the target LifeTime, then click Continue deployment or Abort deployment.
A request moves through fixed statuses; the ProcessPromotions timer does the work, and people only request, approve, continue or abort.
Packaging, upload and the start of the deployment happen in one timer run; each later run (or an open detail page) checks the target until it reports a final result.
GET /environments/
GET /environments/{env}/applications/
GET /environments/{env}/applications/{app}/?IncludeEnvStatus=true
GET /applications/{app}/versions/{version}/content/
GET
POST /environments/{env}/deployment
GET /deployments/{key}/
POST /deployments/{key}/{command}/
GET /deployments/{key}/status/
Every call goes through OnBeforeRequest, which picks the source or target address and adds that side's service account token.
OnBeforeRequest
Every action is checked on the server against the signed-in LifeTime user; the screens only hide buttons that the server would refuse anyway.
Security_CheckEnvironmentPermission
Security_CheckInfrastructurePermission
Credentials. Tokens live in secret site properties, are added to calls in OnBeforeRequest as a Bearer header and are never shown on screen. Download links are marked sensitive in the integration logs.
Output encoding. All data shown in the HTML parts of the screens goes through EncodeHtml(). Service Studio still shows its generic reminder on those widgets; it is expected.
EncodeHtml()
Menu web service. PluginConfiguration.ShouldDisplayMenuItemToUser is internal-access only and returns True for every user; the checks above decide what each user can do.
PluginConfiguration.ShouldDisplayMenuItemToUser
Audit. Every request records requester, approver, dates, the version promoted, the target deployment key and a timestamped log.
Start with the request's Deployment log and the Setup check screen; most failures name the setting or step involved.
https://<host>/lifetimeapi/rest/v2
Raw API calls are listed in Service Center > Monitoring > Integrations, filtered on module CrossLifeTimePromotion.