Files
Reactive-Resume/docs/contributing/deployment-checks.mdx
T
Amruth Pillai 8c40313980 feat(deploy): support Vercel Hobby alongside Docker (#3541)
* feat(deploy): support Vercel Hobby alongside Docker

* fix(deploy): include PDFKit runtime font assets

* docs(deploy): document Vercel and Docker setup

* docs(deploy): record storage persistence checks

* refactor(deploy): drop scheduled staging cleanup

Staging uploads are deleted after finalization and expired ones are swept
on each new upload, so the Vercel cron job, its route, and CRON_SECRET are
no longer needed. The Deploy with Vercel wizard now asks for two secrets.

* docs(deploy): restructure Vercel guides

Split the Vercel page into a how-to with its environment reference, move the
large RPC staging protocol to an API reference page, and move CI deployment
checks to the contributing section. Point Deploy with Vercel buttons at main.

* chore: remove agent planning records and fix web app description

Delete superpowers plans/specs, ADRs, issue plans, execution briefs, domain
context maps, and Europass research. Describe apps/web as a TanStack Router
SPA served by apps/server.

* refactor(deploy): simplify Vercel support code

- Share one Redis client and key namespace through @reactive-resume/db/redis
  for API and auth instead of a second auth-only client.
- Drop the auth seeding retry; the provider already treats concurrent inserts
  as no-ops and deployment preparation seeds before runtime.
- Detect staging support from POST /api/storage/stage (404 on Docker) instead
  of a separate GET probe.
- Read staged bodies directly; the signed upload already caps their size.
- Close per-subscription Redis connections with disconnect() alone.
- Check Blob health with one list call instead of write/read/delete.
- Remove redundant tsdown onlyBundle list, dead namespace fallbacks, and the
  conditional spread in the health status.

* fix(deploy): heal stopped runs with dead owners and keep auth up without Redis

- Run owners refresh a Redis heartbeat until they release their claim. Stop
  requests reap the run immediately when the owner has stopped heartbeating,
  instead of leaving the thread blocked until the 15-minute TTL reaper.
- Auth and oRPC rate limiters fall back to per-instance memory limits when
  Redis errors, instead of rejecting every login or failing requests.

* ci: allow esbuild build for Vercel CLI and register deployment deps with knip

pnpm 12 fails dlx installs with ignored build scripts, so allow esbuild
explicitly. The server bundle keeps @vercel/blob, ioredis, and jose external,
and api/index.mjs is the Vercel Function entry.

* fix(web): send buffered RPC bodies instead of teed streams

Reading a request clone turned the original body into a stream, which
browsers send without inspectable request data and which needs duplex
mode. Send the already buffered Blob for direct requests.

* fix(web): send direct RPC bodies as bytes

Blob request bodies are sent as data pipes, so browser tooling cannot
inspect them. Buffer the original request as an ArrayBuffer and send those
bytes; this restores the e2e save assertions that match on request data.
2026-09-26 02:37:22 +02:00

53 lines
2.1 KiB
Plaintext

---
title: "Deployment checks"
description: "How CI verifies the Vercel build artifact, and how to run the deployment smoke test against Vercel or Docker."
---
The **Vercel compatibility** workflow (`.github/workflows/vercel.yml`) has two jobs.
## Artifact build
Runs on every pull request and every push to `main`. It needs no Vercel account and no secrets, so fork pull requests run it safely.
The job:
1. Starts an isolated PostgreSQL service.
2. Writes a local `.vercel/project.json` and runs `vercel build --prod` offline, with placeholder Blob credentials. This also applies migrations to the isolated database.
3. Checks the generated Function:
- runtime is `nodejs24.x` and `maxDuration` is `300`;
- PDFKit standard font files are included in the traced files;
- every emitted server chunk loads with `--no-experimental-require-module`, which matches the Vercel runtime;
- the Vercel entrypoint answers a request.
If a new server dependency fails the module-loading check, add it to `bundledInteropPackages` in `apps/server/tsdown.config.ts`.
## Live smoke test
Runs only when started manually (`workflow_dispatch`). It uses the `vercel-smoke` GitHub environment and runs `tooling/deployment/smoke.mjs` against `VERCEL_SMOKE_URL`.
<Warning>
Point the smoke test only at a dedicated test installation. It creates an account, a public resume, and files, then deletes them.
</Warning>
The script checks health, public pages, signup, resume CRUD, public PDF rendering, a 10 MiB upload and download, and one-time use of staged requests.
To also check a 25 MiB agent attachment, configure a deterministic OpenAI-compatible test provider that serves the model `smoke-model`:
| Name | Kind | Value |
| --- | --- | --- |
| `VERCEL_SMOKE_URL` | Variable | Test installation origin |
| `VERCEL_SMOKE_AI_BASE_URL` | Variable | Test provider base URL |
| `VERCEL_SMOKE_AI_API_KEY` | Secret | Test provider API key |
No paid AI model is needed.
## Run the smoke test locally
Against a local Docker installation:
```bash
SMOKE_URL=http://localhost:3000 node tooling/deployment/smoke.mjs
```
Add `SMOKE_AI_BASE_URL` and `SMOKE_AI_API_KEY` to include the attachment check.