Deployment Guide
How Danvas is deployed to production
Danvas uses six independent Vercel projects plus protected Dagster and database
workflows. The repository registry in scripts/app-targets.ts is the source of
truth for expected application targets.
Applications
| App | Vercel project | Directory | Build filter |
|---|---|---|---|
| Main app | canvas-forge-app | apps/app | app |
| API | canvas-forge-api | apps/api | api |
| Docs | canvas-forge-docs | apps/docs | docs |
| Guest | canvas-forge-guest | apps/guest | guest |
| Slack bot | canvas-forge-slack-bot | apps/slack-bot | slack-bot |
| Analytics MCP | canvas-forge-analytics-mcp | apps/analytics-mcp | analytics-mcp |
Vercel's native Git integration deploys previews and production commits. Each
project runs bash ../../scripts/should-build.sh as its Ignored Build Step so
unaffected projects skip their build.
Dagster and database production changes
Production database mutation and Dagster cutover are distinct, approval-gated workflows:
- Dispatch
dagster-deploy.ymlfor an exact current-main SHA and approved rehearsal reference. Its managed-CI job builds and attests the candidate images, then the protected deployment waits for approval. - Copy the user image digest from the build summary and dispatch
production-migrate.ymlwith the same SHA and rehearsal reference. - Approve and complete the migration.
- Only after migration evidence succeeds, approve the waiting Dagster cutover.
The protected cutover verifies image attestations, migration evidence, activation identity, rollback admission, Podman acceptance, and Dagster GraphQL health.
Do not run production migration or Dagster deployment scripts directly. Do not approve Dagster cutover before the matching migration workflow succeeds.
Preview deployment
Package commands remain preview-only:
bun run vercel:deploy
bun run vercel:deploy --all
cd apps/app
bun run deployNever link the monorepo root or run a bare vercel deploy --prod from
apps/<app>.
Local build contract
bun install --frozen-lockfile
bun run build:ci
bun run check
bun run testBuild-time public values (NEXT_PUBLIC_APP_URL, NEXT_PUBLIC_WEB_URL, and other
NEXT_PUBLIC_* keys) are classified in the
environment-variables.md. Never copy CI
placeholder values or production secrets into a local file.
See DEPLOYMENT_GUIDE.md and
docs/agents/workflows/vercel-deploy.md
for operator details.