Deployment Overview
This section is the source of truth for shipping every TrickBook application. Feature work reaches production through a reviewed promotion from staging; merging a feature branch is not itself a production deployment.
Platform map
| Application | Production branch | Runtime/distribution | Deployment |
|---|---|---|---|
| Backend API | master | AWS EC2 + PM2 | Manual EC2 fast-forward today; GitHub OIDC + SSM planned |
| Web app | main | AWS Amplify Web Compute | Automatic after the production promotion merges |
| iOS app | Mobile release branch | EAS Build, TestFlight, App Store Connect | EAS build/submit plus App Store review |
| Android app | Mobile release branch | EAS Build, Google Play | EAS build/submit plus Play Console promotion |
| Documentation | main | GitHub Pages | Automatic GitHub Actions deployment |
Choose a runbook
- Backend API deployment: EC2 checkout, PM2 process, validation, rollback, and planned OIDC/SSM automation.
- Web app deployment: staging and production Amplify branches, promotion, build monitoring, and smoke tests.
- App Store deployment: iOS preflight, TestFlight, App Store Connect, review, and release monitoring.
- Google Play deployment: Android App Bundle builds, submission, testing tracks, and Play Console release.
- Staging and production promotion: shared branch policy and QA gates.
- Infrastructure overview: hosts, processes, DNS, storage, and external services.
- CI/CD pipeline: current checks and deployment automation status.
Standard production release order
When a web feature depends on an API change:
- Merge feature PRs into each repository's
stagingbranch only after CI passes. - Validate the paired staging revisions.
- Open
staging→ production promotion PRs (masterfor the API,mainfor the web app). - Merge and deploy the backend first.
- Smoke-test the production API.
- Merge the web promotion and wait for the Amplify production job to succeed.
- Smoke-test the live page, its API calls, and any sitemap or metadata changes.
Mobile releases may consume the same API. Confirm backward compatibility with the current App Store and Play Store builds before deploying breaking backend changes.
Release evidence
Record these items in the promotion PR or release notes:
- production commit SHA;
- successful CI and hosting/build job;
- deployment target and timestamp;
- smoke-test results;
- migrations or index changes;
- rollback revision;
- App Store or Play review state when applicable.
Never place signing keys, SSH keys, store credentials, JWT secrets, database URIs, or provider tokens in documentation, source control, workflow output, or PR descriptions.