Deployment
CI/CD
Build Commands
Builds run through Turborepo: pnpm turbo build --filter=admin.
Environment Variables
| Variable | Required | Description |
|---|---|---|
PUBLIC_CONVEX_URL | Yes | Convex deployment URL |
CONVEX_DEPLOY_KEY | Build only | Convex deploy key |
BETTER_AUTH_SECRET | Yes | Secret for session signing |
BETTER_AUTH_URL | Yes | Public URL of admin app |
S3_BUCKET | If using S3 | S3 bucket for uploads |
S3_REGION | If using S3 | AWS region |
Do not commit .env files. Use your provider's environment variable settings.
Vercel
{ "buildCommand": "pnpm turbo build --filter=admin", "outputDirectory": "apps/admin/dist" } Netlify
[build]
command = "pnpm turbo build --filter=admin"
publish = "apps/admin/dist"
[build.environment]
NODE_VERSION = "20" Build Steps
pnpm install --frozen-lockfilenpx vextro-migrate --check-- detect schema driftnpx convex deploy-- push schema and functionspnpm turbo build --filter=admin- Deploy
dist/to hosting provider
GitHub Actions
name: Deploy Admin
on: { push: { branches: [main] } }
jobs:
deploy:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: pnpm/action-setup@v4
- uses: actions/setup-node@v4
with: { node-version: 20, cache: pnpm }
- run: pnpm install --frozen-lockfile
- run: npx convex deploy
env: { CONVEX_DEPLOY_KEY: "${{ secrets.CONVEX_DEPLOY_KEY }}" }
- run: pnpm turbo build --filter=admin
env: { PUBLIC_CONVEX_URL: "${{ secrets.PUBLIC_CONVEX_URL }}" } Point preview deployments at a staging Convex deployment to avoid production writes.
CI Runtime Controls
The main ci workflow uses two safety-preserving runtime controls:
- Concurrency cancellation: in-progress runs on the same PR/branch are automatically canceled when a newer commit is pushed.
- Change-aware heavy jobs: expensive suites (
e2e,e2e-verify-writes,e2e-browser,e2e-clerk,benchmarks) run when relevant paths change. Integration-to-stagingPRs and pushes tostagingormainrun the full browser backend matrix. - Stable aggregate status: the
aggregatejob reports only after every applicable CI job passes or is intentionally skipped, giving branch protection one dependable required check.
This keeps required safety checks active while reducing unnecessary CI minutes on docs-only or unrelated PRs.
Metadata Depth Ops Workflows
Vextro includes dedicated metadata-depth workflows:
metadata-depth-gate-- always reports on PRs and protected-branch pushes; runs the depth contract suites when relevant inputs change and otherwise records a successful no-op.metadata-depth-nightly-- nightly D4 stress run; opens or updates a tracked issue on failure.metadata-depth-evidence-prune-- weekly pruning PR for evidence folders older than 90 days.
Operational references:
- contract:
docs/superpowers/reference/metadata-depth-contract.md - deployment runbook:
docs/superpowers/reference/metadata-depth-validation-runbook.md - evidence archive:
docs/superpowers/evidence/metadata-depth/
If branch protection is unavailable on your GitHub plan, treat failed metadata-depth-gate runs as a manual merge blocker.