Appearance
Deploy and operate
Production integration has two surfaces: the product application and the isolated wallet runtime. Deploy each from reviewed artifacts, give each its own origin and security policy, and keep custody-role secrets out of the browser.
Use this section to prepare a release:
- Host the wallet integration.
- Review origin, iframe, CSP, and request-authentication boundaries.
- Assign environment values to their proper owner.
- Complete the production checklist.
- Configure observability and audit.
- Rehearse troubleshooting.
See tenant-root backups for the separate A/B recovery copies in R2, Google KMS key ownership, restore behavior, and operating costs.
Use the recovery CLI to verify downloaded backup kits, retain an offline-verifiable native binary, and restore both holder shares into an approved empty destination.
Read recovery and portability before choosing a backup strategy. It separates managed root recovery from tenant-controlled recovery and planned wallet/deployment migration, with availability tracked for each operating path.
Repository operators should also follow the private deployment runbook for the exact lane, environment, and release workflow. Public application developers do not need custody credentials or internal service topology.