deployment
poorvith-mp/skills-developer/skills/deployment/SKILL.md
Ship it: platform config for Vercel, Netlify, Fly, Railway, AWS, env secrets, checklists, and rollback. Use when deploying applications to cloud environments.
Skill0 starsChanged 46 days ago
- Reads credentials
What's in it
- Deployment
- 1. Platform Configuration Archetypes
- A. Vercel (vercel.json)
- B. Netlify (netlify.toml)
- C. Fly.io (fly.toml)
- D. Railway (railway.json / Nixpacks)
- E. Cloudflare Pages & Workers (wrangler.toml)
- F. AWS (App Runner / ECS Fargate / CDK)
- 2. Zero-Downtime Migration & Rollback Discipline
- Critical Rules
- Verification Checklist
- Anti-Patterns
---
name: deployment
last_reviewed: 2026-09-06
group: Ship and run
description: >-
Ship it: platform config for Vercel, Netlify, Fly, Railway, AWS, env secrets, checklists, and
rollback. Use when deploying applications to cloud environments.
---
# Deployment
Deployments fail on environment drift, schema mismatches, and unverified secrets. A reliable deployment pipeline specifies target platform configurations explicitly, manages environment secrets strictly through platform vaults, verifies database migration forward-compatibility, and guarantees automated rollback in under 60 seconds.
## 1. Platform Configuration Archetypes
### A. Vercel (`vercel.json`)
Used for Next.js, SvelteKit, and frontend/serverless architectures:
```json
{
"buildCommand": "npm run build",
"outputDirectory": ".next",
"framework": "nextjs",
"regions": ["iad1"],
"cleanUrls": true,
"headers": [
{
"source": "/(.*)",
"headers": [
{ "key": "X-Content-Type-Options", "value": "nosniff" },
{ "key": "X-Frame-Options", "value": "DENY" }
]
}
]
}
```
- **CLI Commands**: `vercel deploy` (preview), `vercel deploy --prod` (production promote).
- **Environment Scope**: Segregate variables between Development, Preview, and Production.
### B. Netlify (`netlify.toml`)
Used for static sites, Jamstack, and Netlify Edge functions:
```toml
[build]
command = "npm run build"
publish = "dist"
[[redirects]]
from = "/*"
to = "/index.html"
status = 200
[[headers]]
for = "/*"
[headers.values]
Strict-Transport-Security = "max-age=31536000; includeSubDomains; preload"
```
- **CLI Commands**: `netlify deploy`, `netlify deploy --prod`.
### C. Fly.io (`fly.toml`)
Used for full-stack Node.js, Go, Python, and containerized long-running services:
```toml
app = "production-app"
primary_region = "iad"
[build]
dockerfile = "Dockerfile"
[http_service]
internal_port = 3000
force_https = true
auto_stop_machines = "stop"
auto_start_machines = true
min_machines_running = 1
[[http_service.checks]]
grace_period = "10s"
interval = "15s"
method = "GET"
timeout = "5s"
path = "/healthz"
```
- **CLI Commands**: `fly launch`, `fly secrets set KEY=VALUE`, `fly deploy`, `fly releases rollback`.
### D. Railway (`railway.json` / Nixpacks)
Used for microservices, Redis, PostgreSQL, and background worker queues:
```json
{
"$schema": "https://railway.com/railway.schema.json",
"build": {
"builder": "NIXPACKS",
"buildCommand": "npm run build"
},
"deploy": {
"startCommand": "node dist/index.js",
"healthcheckPath": "/healthz",
"healthcheckTimeout": 100,
"restartPolicyType": "ON_FAILURE",
"restartPolicyMaxRetries": 10
}
}
```
- **CLI Commands**: `railway up`, `railway variables set KEY=VALUE`.
### E. Cloudflare Pages & Workers (`wrangler.toml`)
Used for edge compute, global APIs, and static assets with serverless bindings:
```toml
name = "edge-api"
main = "src/index.ts"
compatibility_date = "2026-01-01"
[vars]
ENVIRONMENT = "production"
[[kv_namespaces]]
binding = "CACHE"
id = "xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"
```
- **CLI Commands**: `wrangler secret put KEY`, `wrangler deploy`.
### F. AWS (App Runner / ECS Fargate / CDK)
Used for enterprise multi-tenant architectures and private VPC deployments:
- Inject secrets via AWS Secrets Manager or SSM Parameter Store using IAM task roles (`arn:aws:iam::...`). Never bake `.env` into container layers.
- App Runner: define `apprunner.yaml` with build and run stages, health checks, and auto-scaling rules (min 1, max 10 instances).
- ECS Fargate: configure Blue/Green deployments using AWS CodeDeploy with automatic rollback triggered on CloudWatch 5xx alarm breaches.
## 2. Zero-Downtime Migration & Rollback Discipline
- **Expand/Contract Database Pattern**:
1. *Phase 1 (Expand)*: Add nullable column or new table. Deploy migration.
2. *Phase 2 (Dual Write)*: Deploy application code writing to both old and new schemas.
3. *Phase 3 (Backfill)*: Asynchronously backfill historical data.
4. *Phase 4 (Contract)*: Deploy code reading exclusively from new schema; drop old column in a subsequent release.
- **Rollback Runbook**:
- Keep previous deployment artifact/image digest tagged (`:v3.0.0-previous`).
- Automated platform rollback: `fly releases rollback`, `vercel rollback [deployment-url]`, or AWS ECS task definition reversion.
## Critical Rules
1. Never run destructive database migrations (`DROP COLUMN`, `ALTER TABLE ... RENAME`) in the same deployment as application code changes.
2. Production builds must run from committed git SHAs, never uncommitted local dirty states.
3. Every production service must expose an unauthenticated, lightweight `/healthz` endpoint verifying process vitality and database connectivity.
## Verification Checklist
- [ ] Target platform configuration file (`vercel.json`, `fly.toml`, `netlify.toml`, `railway.json`, `wrangler.toml`) committed and validated.
- [ ] Environment secrets populated in platform vault; no secrets committed to git or exposed in client bundles.
- [ ] Health check endpoint (`/healthz`) verified returning HTTP 200 before cutover.
- [ ] Database migrations tested in staging for forward-compatibility.
- [ ] Instant rollback mechanism (CLI command or container rollback) verified and tested.
## Anti-Patterns
- NEVER run database migrations inside the container startup script (`CMD`); execute migrations as a separate pre-deploy step or release phase.
- NEVER deploy to production with `latest` Docker tags; pin immutable content digests (`sha256:...`).
- NEVER store production encryption keys or credentials in repository `.env.production` files.
More agent context in poorvith-mp/skills-developer
134 other files this repository gives its agents, the first 60 shown.
Skill
- accessibility-engineerskills/accessibility-engineer/SKILL.md
- accessibility-fixskills/accessibility-fix/SKILL.md
- ai-data-remediation-engineerskills/ai-data-remediation-engineer/SKILL.md
- ai-engineerskills/ai-engineer/SKILL.md
- ai-eval-suite-builderskills/ai-eval-suite-builder/SKILL.md
- android-developerskills/android-developer/SKILL.md
- api-designskills/api-design/SKILL.md
- api-lifecycle-engineerskills/api-lifecycle-engineer/SKILL.md
- appsec-architectskills/appsec-architect/SKILL.md
- audit-readinessskills/audit-readiness/SKILL.md
- authenticationskills/authentication/SKILL.md
- autonomous-optimization-architectskills/autonomous-optimization-architect/SKILL.md
- backend-architectskills/backend-architect/SKILL.md
- backend-buildskills/backend-build/SKILL.md
- blockchain-security-auditorskills/blockchain-security-auditor/SKILL.md
- branching-strategyskills/branching-strategy/SKILL.md
- bug-explainerskills/bug-explainer/SKILL.md
- changelog-writerskills/changelog-writer/SKILL.md
- change-notesskills/change-notes/SKILL.md
- ci-cd-pipeline-builderskills/ci-cd-pipeline-builder/SKILL.md
- ci-pipelinesskills/ci-pipelines/SKILL.md
- cloud-costskills/cloud-cost/SKILL.md
- cloud-security-architectskills/cloud-security-architect/SKILL.md
- cloud-securityskills/cloud-security/SKILL.md
- codebase-mapskills/codebase-map/SKILL.md
- codebase-onboarding-engineerskills/codebase-onboarding-engineer/SKILL.md
- code-comment-writerskills/code-comment-writer/SKILL.md
- code-reviewerskills/code-reviewer/SKILL.md
- code-reviewskills/code-review/SKILL.md
- code-translatorskills/code-translator/SKILL.md
- commerce-platformskills/commerce-platform/SKILL.md
- compliance-auditorskills/compliance-auditor/SKILL.md
- composioskills/composio/SKILL.md
- cron-job-plannerskills/cron-job-planner/SKILL.md
- database-optimizerskills/database-optimizer/SKILL.md
- database-schema-designerskills/database-schema-designer/SKILL.md
- databaseskills/database/SKILL.md
- data-engineerskills/data-engineer/SKILL.md
- data-pipeline-architectskills/data-pipeline-architect/SKILL.md
- data-pipelinesskills/data-pipelines/SKILL.md
- debuggingskills/debugging/SKILL.md
- debugging-strategistskills/debugging-strategist/SKILL.md
- dependency-auditskills/dependency-audit/SKILL.md
- dependency-upgrade-auditorskills/dependency-upgrade-auditor/SKILL.md
- deployment-checklistskills/deployment-checklist/SKILL.md
- developer-platformskills/developer-platform/SKILL.md
- devops-automatorskills/devops-automator/SKILL.md
- ecommerce-cms-architectskills/ecommerce-cms-architect/SKILL.md
- email-intelligence-engineerskills/email-intelligence-engineer/SKILL.md
- embedded-firmware-engineerskills/embedded-firmware-engineer/SKILL.md
- environment-setup-guideskills/environment-setup-guide/SKILL.md
- error-boundary-designerskills/error-boundary-designer/SKILL.md
- error-handlingskills/error-handling/SKILL.md
- evidence-collectorskills/evidence-collector/SKILL.md
- filament-optimizerskills/filament-optimizer/SKILL.md
- finops-engineerskills/finops-engineer/SKILL.md
- firmwareskills/firmware/SKILL.md
- frontend-buildskills/frontend-build/SKILL.md
- frontend-developerskills/frontend-developer/SKILL.md
- git-commit-writerskills/git-commit-writer/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

