Deployment
put your site online.
Two ways: the operator server (one Node process behind TLS, with the console) or a static host (just the built files). Use your own domain and your own hosting account for either.
01Choose a mode
| Mode | What runs | Use when |
|---|---|---|
| Operator server (recommended) | npm run server: the built dApp, the console at /admin and /api/public-config, in one Node process | You want to change the fee, brand, moderation and other settings without rebuilding |
| Static only | dist/ on any static host | A demo, or a site you rarely change. Settings come from build-time VITE_* values. |
Either way the browser talks directly to the RPC and to the trader's wallet. Nothing is signed, relayed or submitted by a server.
02Operator server
You need a machine or container that keeps a Node process running, a persistent disk, and a domain. The server uses a local SQLite file, so a serverless host that does not keep files between requests is not supported as shipped.
- Copy the project and install
Set yournpm ci npm run buildVITE_*values (at leastVITE_RPC_URL) in.env.localbeforenpm run build. - Set the environment
ADMIN_SECRET_KEY(required; generate once withopenssl rand -hex 32and keep the same value for good), and optionallyPORT,HOST,PARACHUTE_DATA_DIR,PARACHUTE_RPC_URL(all variables). - Start it under a process managerSo it restarts after a crash or reboot: systemd, PM2, Docker or your host's equivalent. The command is
npm run serverin the project folder. - Put a TLS reverse proxy in frontSee below.
- Create the ownerRead the one-time setup code from the process log, open
https://<your-domain>/adminand create the owner. Turn on two-factor.
The server listens on 127.0.0.1:8787 by default, which is right when the proxy runs on the same machine. In a container, set HOST=0.0.0.0 and publish the port only to the proxy.
03Example: systemd
An example unit, not shipped with the item and not tested for this release (unverified). Adjust the user and paths.
[Unit]
Description=PARACHUTE operator server
After=network.target
[Service]
User=parachute
WorkingDirectory=/opt/parachute
Environment=NODE_ENV=production
EnvironmentFile=/etc/parachute.env # ADMIN_SECRET_KEY=… (chmod 600)
ExecStart=/usr/bin/npm run server
Restart=on-failure
[Install]
WantedBy=multi-user.target
04TLS reverse proxy
Any proxy works. Examples, not tested for this release (unverified):
# Caddy (Caddyfile): gets and renews the certificate itself
<your-domain> {
reverse_proxy 127.0.0.1:8787
}
# nginx: inside a server block that already has TLS
location / {
proxy_pass http://127.0.0.1:8787;
proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto $scheme;
}
The dApp, /admin and /api must stay on the same origin: the dApp reads /api/public-config from where it is served.
05Backups
server/data/(or yourPARACHUTE_DATA_DIR):admin.sqliteholds settings, accounts, history and the audit log;fee-ledger.jsonholds the revenue read from the chain (it can be rebuilt from the chain).ADMIN_SECRET_KEY, stored separately (password manager). Without it the encrypted secrets in the database cannot be read.- Optionally a Console → Export / Import JSON file (settings without secrets).
06Static only
- Build without an operator server
WithVITE_PUBLIC_CONFIG_URL=off npm run buildoffthe app makes no config request and runs on the build-time values:VITE_FEE_BPSandVITE_FEE_RECIPIENT(both needed, capped at 100 bps) andVITE_STOCKS_ENABLED. You can also putVITE_PUBLIC_CONFIG_URL=offin.env.local. - Upload
dist/To your static host. - Send unknown paths to
index.htmlLinks such as/token/0x…are app routes, not files.- Vercel: copy
deploy/vercel.jsoninto the folder you deploy asvercel.json. It has the rewrite and security headers (X-Content-Type-Options,Referrer-Policy,X-Frame-Options: DENY, long caching for/assets/). - Netlify: a
_redirectsfile with/* /index.html 200. - nginx:
try_files $uri /index.html;
- Vercel: copy
A static site has no console: referrals, sponsored slots, moderation, the read-only switch, brand settings and the revenue view need the operator server. To change the fee or the stock flag, rebuild and upload again.
07Go-live checklist
- Your own
VITE_RPC_URL, with the public RPC as the last fallback. - HTTPS on your domain.
- Owner created, two-factor on,
ADMIN_SECRET_KEYandserver/data/backed up. - Console → Legal: your terms, privacy policy and disclaimer.
- Fee: off, or set with a wallet you control (Earnings).
- Stock module: off unless you have legal advice (Stock module).
- Console → Status: all blocker checks pass.
/settingsin the dApp shows no problems.