Skip to main content

Deployment and release

RODENT has four separately deployed or distributed parts. A successful website deploy does not prove that the database, documentation or Python SDK is current.

PartDelivery targetPublic location or artefact
Research portal and Godot web exportVercelrodent-tau.vercel.app
Authentication, relational data and model filesSupabaseProject-managed hosted service; URL and publishable key are supplied through environment configuration.
DocumentationCloudflare Pagesvirtual-rodent-docs.pages.dev
Python SDK and simulation packPython wheel plus versioned packrodent-sdk; build records include a pack URL and SHA-256.

Website release​

The server reads SUPABASE_URL, SUPABASE_PUBLISHABLE_KEY and RODENT_PUBLIC_SITE_URL. Only the publishable key may reach browser code. The public site URL must be https://rodent-tau.vercel.app in production.

Supabase Authentication > URL Configuration must use the production site URL and allow https://rodent-tau.vercel.app/**. Confirmation and recovery templates should use Supabase's confirmation URL rather than a hard-coded localhost link.

After exporting Godot for the web, regenerate the compressed .js, .pck and .wasm files before deploying. The application falls back to uncompressed assets, but stale compressed files can serve an older simulator than the page code.

Database release​

Apply migrations in filename order and record the deployed migration list. The final workflow requires the migrations through:

  • 202610100001_rat_models.sql; and
  • 202610110001_live_rat_models.sql; and
  • 202610110002_account_deletion.sql.

The final migration adds the authenticated delete_my_account RPC used by Security. Applying the migration only installs the function. A later call must provide the exact confirmation DELETE. The function removes projects led by the departing account in explicit dependency order, reassigns required authorship inside projects that continue under another lead, anonymises remaining audit references, and removes memberships, profile, and Auth identity. This order supports the supplied live schema's historical NO ACTION foreign keys. Test the action only with a disposable account after taking a backup, and check private Storage for orphaned model files afterward.

After migration, verify tables, functions, Row Level Security policies and Storage policies with lead, editor, observer and non-member test accounts. Never infer security from hidden browser controls.

SDK release​

The SDK version in python/pyproject.toml and rodent_sdk.__version__ must match. CI builds the pack with Godot 4.7.1, installs the wheel outside the repository and runs an end-to-end experiment. A slim wheel downloads a versioned pack and refuses a SHA-256 mismatch.

A release should be tested in a fresh Colab session before publishing. Published packs and model versions must not be overwritten because old notebooks and saved provenance depend on their checksums.

Documentation release​

From the documentation repository:

npm ci
npm run build

Cloudflare Pages should publish only after the Docusaurus build passes with no broken links. The docs must identify the application commit or release they describe; otherwise a green docs build can still describe an older product.

Evidence to keep​

For each release, retain:

  • application and documentation commit IDs;
  • green Gitea Actions run links;
  • Vercel and Cloudflare deployment IDs and dates;
  • Supabase migration and policy verification output;
  • SDK version, wheel checksum and pack checksum;
  • browser, accessibility and performance test notes; and
  • known issues and scientific limitations.

AI Attribution: This deployment guide was prepared with OpenAI Codex assistance from the repository configuration and deployment history. Secrets and private deployment records must not be copied into the public site.