PARACHUTE docs
v1.0.0
Live demo Get help
● Ship · Go live

Deployment
put your site online.

Two ways: the operator server (one Node process behind TLS, with the console) or a static host (just the built files). Use your own domain and your own hosting account for either.

01Choose a mode

ModeWhat runsUse when
Operator server (recommended)npm run server: the built dApp, the console at /admin and /api/public-config, in one Node processYou want to change the fee, brand, moderation and other settings without rebuilding
Static onlydist/ on any static hostA demo, or a site you rarely change. Settings come from build-time VITE_* values.

Either way the browser talks directly to the RPC and to the trader's wallet. Nothing is signed, relayed or submitted by a server.

02Operator server

You need a machine or container that keeps a Node process running, a persistent disk, and a domain. The server uses a local SQLite file, so a serverless host that does not keep files between requests is not supported as shipped.

  1. Copy the project and install
    npm ci
    npm run build
    Set your VITE_* values (at least VITE_RPC_URL) in .env.local before npm run build.
  2. Set the environmentADMIN_SECRET_KEY (required; generate once with openssl rand -hex 32 and keep the same value for good), and optionally PORT, HOST, PARACHUTE_DATA_DIR, PARACHUTE_RPC_URL (all variables).
  3. Start it under a process managerSo it restarts after a crash or reboot: systemd, PM2, Docker or your host's equivalent. The command is npm run server in the project folder.
  4. Put a TLS reverse proxy in frontSee below.
  5. Create the ownerRead the one-time setup code from the process log, open https://<your-domain>/admin and create the owner. Turn on two-factor.
Listening address

The server listens on 127.0.0.1:8787 by default, which is right when the proxy runs on the same machine. In a container, set HOST=0.0.0.0 and publish the port only to the proxy.

03Example: systemd

An example unit, not shipped with the item and not tested for this release (unverified). Adjust the user and paths.

[Unit]
Description=PARACHUTE operator server
After=network.target

[Service]
User=parachute
WorkingDirectory=/opt/parachute
Environment=NODE_ENV=production
EnvironmentFile=/etc/parachute.env   # ADMIN_SECRET_KEY=… (chmod 600)
ExecStart=/usr/bin/npm run server
Restart=on-failure

[Install]
WantedBy=multi-user.target

04TLS reverse proxy

Any proxy works. Examples, not tested for this release (unverified):

# Caddy (Caddyfile): gets and renews the certificate itself
<your-domain> {
  reverse_proxy 127.0.0.1:8787
}
# nginx: inside a server block that already has TLS
location / {
  proxy_pass http://127.0.0.1:8787;
  proxy_set_header Host $host;
  proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
  proxy_set_header X-Forwarded-Proto $scheme;
}

The dApp, /admin and /api must stay on the same origin: the dApp reads /api/public-config from where it is served.

05Backups

  • server/data/ (or your PARACHUTE_DATA_DIR): admin.sqlite holds settings, accounts, history and the audit log; fee-ledger.json holds the revenue read from the chain (it can be rebuilt from the chain).
  • ADMIN_SECRET_KEY, stored separately (password manager). Without it the encrypted secrets in the database cannot be read.
  • Optionally a Console → Export / Import JSON file (settings without secrets).

06Static only

  1. Build without an operator server
    VITE_PUBLIC_CONFIG_URL=off npm run build
    With off the app makes no config request and runs on the build-time values: VITE_FEE_BPS and VITE_FEE_RECIPIENT (both needed, capped at 100 bps) and VITE_STOCKS_ENABLED. You can also put VITE_PUBLIC_CONFIG_URL=off in .env.local.
  2. Upload dist/To your static host.
  3. Send unknown paths to index.htmlLinks such as /token/0x… are app routes, not files.
    • Vercel: copy deploy/vercel.json into the folder you deploy as vercel.json. It has the rewrite and security headers (X-Content-Type-Options, Referrer-Policy, X-Frame-Options: DENY, long caching for /assets/).
    • Netlify: a _redirects file with /* /index.html 200.
    • nginx: try_files $uri /index.html;

A static site has no console: referrals, sponsored slots, moderation, the read-only switch, brand settings and the revenue view need the operator server. To change the fee or the stock flag, rebuild and upload again.

07Go-live checklist

  • Your own VITE_RPC_URL, with the public RPC as the last fallback.
  • HTTPS on your domain.
  • Owner created, two-factor on, ADMIN_SECRET_KEY and server/data/ backed up.
  • Console → Legal: your terms, privacy policy and disclaimer.
  • Fee: off, or set with a wallet you control (Earnings).
  • Stock module: off unless you have legal advice (Stock module).
  • Console → Status: all blocker checks pass.
  • /settings in the dApp shows no problems.