Skip to content

Deployment ​

What deploys what ​

ChangeDeployed byWhen
Frontend (src/)Vercel Git integration, project qurtuba-portal-2Every push; main is production, other branches get preview URLs
Migrations (supabase/migrations/)GitHub Actions supabase-migrate.ymlPull requests run a dry run against production; a merge to main applies them (behind the production environment)
Edge functions (supabase/functions/)The same workflowAfter the migrations, for the functions that changed
Edge router (infra/cloudflare/site-router)Cloudflare dashboard, or npx wrangler deployBy hand
Docs (docs-site/)Vercel, a separate project with docs-site as its root directoryEvery push

Order matters: migrations → edge functions → frontend, because the frontend calls functions and RPCs the migrations define.

Checks ​

sh
npm run verify   # release hygiene, types drift, permission defs, lint, typecheck, tests, build

CI runs the same on every pull request.

Environment ​

WhereVariableValue
Vercel (app)VITE_SUPABASE_URL, VITE_SUPABASE_PUBLISHABLE_KEYThe Supabase project
Vercel (app)VITE_ROOT_DOMAINqurtuba.in
Vercel (app)VITE_APP_HOSTapp.qurtuba.in. Set it only once that host is live
Supabase secretsALLOWED_ORIGINSOne origin, or unset for *
WorkerROOT_DOMAIN, APP_ORIGIN, SUPABASE_URL, SUPABASE_PUBLISHABLE_KEY (secret)See infra/cloudflare/site-router/README.md

The service-role key never goes to Vercel or the Worker.

The full runbook is docs/DEPLOYMENT.md in the repository.

Qurtuba Foundation · Sign in at app.qurtuba.in