Deployment

CI/CD

Build Commands

Builds run through Turborepo: pnpm turbo build --filter=admin.

Environment Variables

VariableRequiredDescription
PUBLIC_CONVEX_URLYesConvex deployment URL
CONVEX_DEPLOY_KEYBuild onlyConvex deploy key
BETTER_AUTH_SECRETYesSecret for session signing
BETTER_AUTH_URLYesPublic URL of admin app
S3_BUCKETIf using S3S3 bucket for uploads
S3_REGIONIf using S3AWS region

Do not commit .env files. Use your provider's environment variable settings.

Vercel

{ "buildCommand": "pnpm turbo build --filter=admin", "outputDirectory": "apps/admin/dist" }

Netlify

[build]
  command = "pnpm turbo build --filter=admin"
  publish = "apps/admin/dist"
[build.environment]
  NODE_VERSION = "20"

Build Steps

  1. pnpm install --frozen-lockfile
  2. npx vextro-migrate --check -- detect schema drift
  3. npx convex deploy -- push schema and functions
  4. pnpm turbo build --filter=admin
  5. Deploy dist/ to hosting provider

GitHub Actions

name: Deploy Admin
on: { push: { branches: [main] } }
jobs:
  deploy:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - uses: pnpm/action-setup@v4
      - uses: actions/setup-node@v4
        with: { node-version: 20, cache: pnpm }
      - run: pnpm install --frozen-lockfile
      - run: npx convex deploy
        env: { CONVEX_DEPLOY_KEY: "${{ secrets.CONVEX_DEPLOY_KEY }}" }
      - run: pnpm turbo build --filter=admin
        env: { PUBLIC_CONVEX_URL: "${{ secrets.PUBLIC_CONVEX_URL }}" }

Point preview deployments at a staging Convex deployment to avoid production writes.

CI Runtime Controls

The main ci workflow uses two safety-preserving runtime controls:

  • Concurrency cancellation: in-progress runs on the same PR/branch are automatically canceled when a newer commit is pushed.
  • Change-aware heavy jobs: expensive suites (e2e, e2e-verify-writes, e2e-browser, e2e-clerk, benchmarks) run when relevant paths change. Integration-to-staging PRs and pushes to staging or main run the full browser backend matrix.
  • Stable aggregate status: the aggregate job reports only after every applicable CI job passes or is intentionally skipped, giving branch protection one dependable required check.

This keeps required safety checks active while reducing unnecessary CI minutes on docs-only or unrelated PRs.

Metadata Depth Ops Workflows

Vextro includes dedicated metadata-depth workflows:

  • metadata-depth-gate -- always reports on PRs and protected-branch pushes; runs the depth contract suites when relevant inputs change and otherwise records a successful no-op.
  • metadata-depth-nightly -- nightly D4 stress run; opens or updates a tracked issue on failure.
  • metadata-depth-evidence-prune -- weekly pruning PR for evidence folders older than 90 days.

Operational references:

  • contract: docs/superpowers/reference/metadata-depth-contract.md
  • deployment runbook: docs/superpowers/reference/metadata-depth-validation-runbook.md
  • evidence archive: docs/superpowers/evidence/metadata-depth/

If branch protection is unavailable on your GitHub plan, treat failed metadata-depth-gate runs as a manual merge blocker.

Previous
CLI & Migrations