Why
The orchestrator decided (2026-09-24) to host the showcase on Vercel with Supabase instead of Neon (ADR-0001 D11 named Vercel + Neon + R2). This issue prepares the repository so the showcase can be deployed once the orchestrator has created the accounts and entered the secrets. No accounts, secrets, cloud resources or deploys are created here.
Scope
- ADR-0001 D11 amendment: Supabase Postgres (EU, Frankfurt) replaces Neon; Supabase Storage via its S3-compatible API replaces R2 (one vendor less). Record consequences: Supavisor transaction pooler for the runtime role, session pooler/direct for migrations,
app/identity schemas must not be exposed through the Supabase Data API, Supabase reserves the schema auth (→ separate issue: rename our Better Auth schema to identity).
- Jobs without a long-running worker: the showcase has no worker process. A protected route runs one bounded drain of processing and export jobs (existing
drain / drainExports with a time budget); triggered right after upload and approval via after(), by Vercel Cron, and by the existing retry action. Guarded by a shared secret (CRON_SECRET), constant-time comparison, no request body logged. Docker Compose keeps the worker unchanged.
vercel.json: framework, function max duration for the drain route, cron entry (Hobby allows daily crons only – documented; after() covers normal flow).
- Demo mode:
DEMO_MODE=true shows a banner „Demo – nur synthetische Daten“ on every page.
- Runbook
docs/technical/deployment-vercel.md: what the orchestrator creates (Vercel project, Supabase project in eu-central-1, private bucket, S3 access keys, AI service host, Vertex eu credentials), the one-time SQL bootstrap for the roles app_owner/app_rw (script in the repo, passwords supplied by the operator), env variables per environment, first migration via pnpm setup:deploy, smoke check.
.env.example: new variables documented with safe local defaults.
Acceptance criteria
- Local
docker compose up and pnpm verify behave as before.
- The drain route refuses requests without the correct secret (401) and never logs it; a test proves it drains queued processing and export jobs within the budget and is idempotent with the worker (exactly-once export unchanged: idempotency key + unique export row + row lock).
- Upload and approval trigger a drain via
after() only when JOB_DRAIN_INLINE=true.
- Demo banner visible when
DEMO_MODE=true, absent otherwise.
- Runbook lets the orchestrator deploy without reading code.
Not in scope
Creating accounts, secrets, projects or deploying; the AI-service hosting spike (Cloud Run vs. Vercel Python Function) – documented as an open decision with a recommendation.
Why
The orchestrator decided (2026-09-24) to host the showcase on Vercel with Supabase instead of Neon (ADR-0001 D11 named Vercel + Neon + R2). This issue prepares the repository so the showcase can be deployed once the orchestrator has created the accounts and entered the secrets. No accounts, secrets, cloud resources or deploys are created here.
Scope
app/identityschemas must not be exposed through the Supabase Data API, Supabase reserves the schemaauth(→ separate issue: rename our Better Auth schema toidentity).drain/drainExportswith a time budget); triggered right after upload and approval viaafter(), by Vercel Cron, and by the existing retry action. Guarded by a shared secret (CRON_SECRET), constant-time comparison, no request body logged. Docker Compose keeps the worker unchanged.vercel.json: framework, function max duration for the drain route, cron entry (Hobby allows daily crons only – documented;after()covers normal flow).DEMO_MODE=trueshows a banner „Demo – nur synthetische Daten“ on every page.docs/technical/deployment-vercel.md: what the orchestrator creates (Vercel project, Supabase project ineu-central-1, private bucket, S3 access keys, AI service host, Vertexeucredentials), the one-time SQL bootstrap for the rolesapp_owner/app_rw(script in the repo, passwords supplied by the operator), env variables per environment, first migration viapnpm setup:deploy, smoke check..env.example: new variables documented with safe local defaults.Acceptance criteria
docker compose upandpnpm verifybehave as before.after()only whenJOB_DRAIN_INLINE=true.DEMO_MODE=true, absent otherwise.Not in scope
Creating accounts, secrets, projects or deploying; the AI-service hosting spike (Cloud Run vs. Vercel Python Function) – documented as an open decision with a recommendation.