Deployment and release
RODENT has four separately deployed or distributed parts. A successful website deploy does not prove that the database, documentation or Python SDK is current.
| Part | Delivery target | Public location or artefact |
|---|---|---|
| Research portal and Godot web export | Vercel | rodent-tau.vercel.app |
| Authentication, relational data and model files | Supabase | Project-managed hosted service; URL and publishable key are supplied through environment configuration. |
| Documentation | Cloudflare Pages | virtual-rodent-docs.pages.dev |
| Python SDK and simulation pack | Python wheel plus versioned pack | rodent-sdk; build records include a pack URL and SHA-256. |
Website release
The server reads SUPABASE_URL, SUPABASE_PUBLISHABLE_KEY and RODENT_PUBLIC_SITE_URL. Only the publishable key may reach browser code. The public site URL must be https://rodent-tau.vercel.app in production.
Supabase Authentication > URL Configuration must use the production site URL and allow https://rodent-tau.vercel.app/**. Confirmation and recovery templates should use Supabase's confirmation URL rather than a hard-coded localhost link.
After exporting Godot for the web, regenerate the compressed .js, .pck and .wasm files before deploying. The application falls back to uncompressed assets, but stale compressed files can serve an older simulator than the page code.
Database release
Apply migrations in filename order and record the deployed migration list. The final workflow requires the migrations through:
202610100001_rat_models.sql; and202610110001_live_rat_models.sql; and202610110002_account_deletion.sql.
The final migration adds the authenticated delete_my_account RPC used by Security. Applying the migration only installs the function. A later call must provide the exact confirmation DELETE. The function removes projects led by the departing account in explicit dependency order, reassigns required authorship inside projects that continue under another lead, anonymises remaining audit references, and removes memberships, profile, and Auth identity. This order supports the supplied live schema's historical NO ACTION foreign keys. Test the action only with a disposable account after taking a backup, and check private Storage for orphaned model files afterward.
After migration, verify tables, functions, Row Level Security policies and Storage policies with lead, editor, observer and non-member test accounts. Never infer security from hidden browser controls.
SDK release
The SDK version in python/pyproject.toml and rodent_sdk.__version__ must match. CI builds the pack with Godot 4.7.1, installs the wheel outside the repository and runs an end-to-end experiment. A slim wheel downloads a versioned pack and refuses a SHA-256 mismatch.
A release should be tested in a fresh Colab session before publishing. Published packs and model versions must not be overwritten because old notebooks and saved provenance depend on their checksums.
Documentation release
From the documentation repository:
npm ci
npm run build
Cloudflare Pages should publish only after the Docusaurus build passes with no broken links. The docs must identify the application commit or release they describe; otherwise a green docs build can still describe an older product.
Evidence to keep
For each release, retain:
- application and documentation commit IDs;
- green Gitea Actions run links;
- Vercel and Cloudflare deployment IDs and dates;
- Supabase migration and policy verification output;
- SDK version, wheel checksum and pack checksum;
- browser, accessibility and performance test notes; and
- known issues and scientific limitations.
AI Attribution: This deployment guide was prepared with OpenAI Codex assistance from the repository configuration and deployment history. Secrets and private deployment records must not be copied into the public site.