Skip to content
← Back

Lesson 6 of 6

Deploy, verify live, and submit redacted evidence

Deploy the tracker to a public https URL, keep secrets off the client (zero secrets for this app), re-run acceptance criteria live, and submit self-reported proof pending review.

Pre-deploy checklist, then deploy the public folder

Before deploy: every FEATURE.md criterion passes locally; console is clean; keyboard pass works; no key in public/; .gitignore includes .dev.vars* and .env*; npx wrangler whoami shows your account.

Workers (default for a new project), from the folder that contains wrangler.jsonc and public/:

npx wrangler deploy

Wrangler uploads assets.directory and prints https://<name>.<subdomain>.workers.dev.

Pages, if that is your Lesson 5 target:

npx wrangler pages deploy ./public --project-name task-tracker-yourname

That prints a https://<project>.pages.dev URL. Dashboard alternative: Workers & Pages → Create → Pages → Upload assets — upload public/, not the repo root. Redeploy with the same command and project name; the URL stays. Open the printed https URL, not localhost.

Server secrets: this app needs none

The tracker stores tasks in the visitor's browser. It makes no network calls and holds no secret. Do not invent a fake token to "finish" this step. Any provider credential you used in Lesson 1 stays in OpenCode's authentication store on your machine. It must never appear in the live page, the Network panel, a query string, or a screenshot.

If a later feature calls a third party, the token lives on the server. The browser talks only to your endpoint. Workers:

npx wrangler secret put QUOTE_TOKEN

Read env.QUOTE_TOKEN in a Worker fetch handler; fall through with env.ASSETS.fetch(request) for HTML. You then need "main", assets.binding, and "run_worker_first": ["/api/*"]. Locally, put the value in .dev.vars next to wrangler.jsonc — choose .dev.vars or .env, not both; never commit them.

Pages: Settings → Variables and Secrets → Add → Encrypt → Save, or npx wrangler pages secret put. Read context.env.QUOTE_TOKEN in a Function.

Wrong places: public/app.js, localStorage, VITE_* / PUBLIC_*, query strings, vars in Wrangler config, committed .env, screenshots. If a real secret leaks: revoke first, then update the stored secret, then redeploy.

Verify the live URL the way a stranger would

Localhost passing is not proof.

  1. Open the live https URL. Hard-refresh.
  2. Re-run FEATURE.md on this URL. Record pass/fail per criterion.
  3. Console: no errors. Network: no call to OpenRouter, xAI, or any model API. Those requests belong only to your agent tool using its supported provider connection, not to the published tracker.
  4. Application → Local Storage: task-tracker.tasks.v1 is under the public origin, a different store from localhost. Local tasks will not be there.
  5. Open the URL on a phone on mobile data (Wi-Fi off).
  6. Tab through; zoom to 200%. Confirm the padlock and https://.

If a criterion fails live but passed locally, it is a deploy problem: wrong folder, stale project name, or cached copy. Redeploy the current public/ and re-copy the printed URL. Never paste API keys into the live page, a query string, or a screenshot.

Submit proof, then expect a different toolchain in Module 2

The app stores three fields: public https URL, explanation, and checks (what you tried and what you saw). Fill them with facts. Do not paste keys, .dev.vars, account email, or billing.

Include this sentence: Tasks are stored in this browser's localStorage for this origin. They are not synced. Clearing site data deletes them. A reviewer starts with an empty list.

Saving a submission stores self-reported evidence. It is pending review. The platform does not fetch your URL, certify the app, issue a credential, or grant instructor time.

Bridge to Module 2 (safe-autonomy): the next module starts from this behaviour, not these files. public/index.html, styles.css, and app.js are replaced by Vite + TypeScript sources and a build output folder. python3 -m http.server / npx serve become npm run dev, npm run build, and npm run preview. Cloudflare assets.directory points at that build output, not public/. Keep this live URL. Module 2 adds local checks and CI verification; it does not deploy. A future deployment would use the build output for the same kind of target.

Sources

How did this lesson go? Give feedback →