Lesson 6 of 6
Deploy, verify live, and submit redacted evidence
Deploy the tracker to a public https URL, keep secrets off the client (zero secrets for this app), re-run acceptance criteria live, and submit self-reported proof pending review.
Pre-deploy checklist, then deploy the public folder
Before deploy: every FEATURE.md criterion passes locally; console is clean; keyboard pass works; no key in public/; .gitignore includes .dev.vars* and .env*; npx wrangler whoami shows your account.
Workers (default for a new project), from the folder that contains wrangler.jsonc and public/:
npx wrangler deploy
Wrangler uploads assets.directory and prints https://<name>.<subdomain>.workers.dev.
Pages, if that is your Lesson 5 target:
npx wrangler pages deploy ./public --project-name task-tracker-yourname
That prints a https://<project>.pages.dev URL. Dashboard alternative: Workers & Pages → Create → Pages → Upload assets — upload public/, not the repo root. Redeploy with the same command and project name; the URL stays. Open the printed https URL, not localhost.
Server secrets: this app needs none
The tracker stores tasks in the visitor's browser. It makes no network calls and holds no secret. Do not invent a fake token to "finish" this step. Any provider credential you used in Lesson 1 stays in OpenCode's authentication store on your machine. It must never appear in the live page, the Network panel, a query string, or a screenshot.
If a later feature calls a third party, the token lives on the server. The browser talks only to your endpoint. Workers:
npx wrangler secret put QUOTE_TOKEN
Read env.QUOTE_TOKEN in a Worker fetch handler; fall through with env.ASSETS.fetch(request) for HTML. You then need "main", assets.binding, and "run_worker_first": ["/api/*"]. Locally, put the value in .dev.vars next to wrangler.jsonc — choose .dev.vars or .env, not both; never commit them.
Pages: Settings → Variables and Secrets → Add → Encrypt → Save, or npx wrangler pages secret put. Read context.env.QUOTE_TOKEN in a Function.
Wrong places: public/app.js, localStorage, VITE_* / PUBLIC_*, query strings, vars in Wrangler config, committed .env, screenshots. If a real secret leaks: revoke first, then update the stored secret, then redeploy.
Verify the live URL the way a stranger would
Localhost passing is not proof.
- Open the live https URL. Hard-refresh.
- Re-run FEATURE.md on this URL. Record pass/fail per criterion.
- Console: no errors. Network: no call to OpenRouter, xAI, or any model API. Those requests belong only to your agent tool using its supported provider connection, not to the published tracker.
- Application → Local Storage:
task-tracker.tasks.v1is under the public origin, a different store from localhost. Local tasks will not be there. - Open the URL on a phone on mobile data (Wi-Fi off).
- Tab through; zoom to 200%. Confirm the padlock and
https://.
If a criterion fails live but passed locally, it is a deploy problem: wrong folder, stale project name, or cached copy. Redeploy the current public/ and re-copy the printed URL. Never paste API keys into the live page, a query string, or a screenshot.
Submit proof, then expect a different toolchain in Module 2
The app stores three fields: public https URL, explanation, and checks (what you tried and what you saw). Fill them with facts. Do not paste keys, .dev.vars, account email, or billing.
Include this sentence: Tasks are stored in this browser's localStorage for this origin. They are not synced. Clearing site data deletes them. A reviewer starts with an empty list.
Saving a submission stores self-reported evidence. It is pending review. The platform does not fetch your URL, certify the app, issue a credential, or grant instructor time.
Bridge to Module 2 (safe-autonomy): the next module starts from this behaviour, not these files. public/index.html, styles.css, and app.js are replaced by Vite + TypeScript sources and a build output folder. python3 -m http.server / npx serve become npm run dev, npm run build, and npm run preview. Cloudflare assets.directory points at that build output, not public/. Keep this live URL. Module 2 adds local checks and CI verification; it does not deploy. A future deployment would use the build output for the same kind of target.