Appearance
Deployment
What deploys what
| Change | Deployed by | When |
|---|---|---|
Frontend (src/) | Vercel Git integration, project qurtuba-portal-2 | Every push; main is production, other branches get preview URLs |
Migrations (supabase/migrations/) | GitHub Actions supabase-migrate.yml | Pull requests run a dry run against production; a merge to main applies them (behind the production environment) |
Edge functions (supabase/functions/) | The same workflow | After the migrations, for the functions that changed |
Edge router (infra/cloudflare/site-router) | Cloudflare dashboard, or npx wrangler deploy | By hand |
Docs (docs-site/) | Vercel, a separate project with docs-site as its root directory | Every push |
Order matters: migrations → edge functions → frontend, because the frontend calls functions and RPCs the migrations define.
Checks
sh
npm run verify # release hygiene, types drift, permission defs, lint, typecheck, tests, buildCI runs the same on every pull request.
Environment
| Where | Variable | Value |
|---|---|---|
| Vercel (app) | VITE_SUPABASE_URL, VITE_SUPABASE_PUBLISHABLE_KEY | The Supabase project |
| Vercel (app) | VITE_ROOT_DOMAIN | qurtuba.in |
| Vercel (app) | VITE_APP_HOST | app.qurtuba.in. Set it only once that host is live |
| Supabase secrets | ALLOWED_ORIGINS | One origin, or unset for * |
| Worker | ROOT_DOMAIN, APP_ORIGIN, SUPABASE_URL, SUPABASE_PUBLISHABLE_KEY (secret) | See infra/cloudflare/site-router/README.md |
The service-role key never goes to Vercel or the Worker.
The full runbook is docs/DEPLOYMENT.md in the repository.