Secrets are repository secrets, kept in one place. The pause before production is the production environment under Settings, Environments, with dylan-sutton-chavez as its required reviewer, so a v tag waits on Ship until the run is approved.
A push to main promotes to dev and a v tag ships to production, and either one replaces the files the last build shipped.
- Dev rebuilds its database from the schema and the seed, and sweeps the packages published under
pkg/with it. - Production only runs the migrations its database has not recorded, and keeps every published package.
- A frozen release, the copy a tag from
v1.0.0keeps under its version, stays in both.
OWNER in site/src/lib/account/handle.ts names the account that publishes the standard library. It skips the per-minute publish limiter and gets five times the daily names, versions and room, and since the privilege follows the handle, that account keeps @dylan.
A schema change edits site/db/schema.sql and adds its step to site/db/migrations/ in the same commit, since production keeps its rows. The next v tag runs the step before the Worker ships, and after that release you delete the file by hand, which the Database job warns about until you do.
npm run schema in infra/ reads production and checks that it plus the pending migrations matches schema.sql. The Database job warns about a mismatch on main and enforces it on a tag.