Build, runtime, and deployment operations
Build, runtime, and deployment operations
Runtime model
This repository is a Vite-built React frontend that can run in development, be built as static assets, and be packaged behind Nginx for deployment.
Scripts in package.json
package.json defines the primary operational commands:
npm run dev— Vite dev servernpm run build— production buildnpm run test/npm run test:run/npm run test:coverage— Vitest suitesnpm run lint— ESLint over the reponpm run preview— local production previewnpm run security:audit,security:lint,security:full— security-oriented checksnpm run prerenderandnpm run build:seo— static prerendering layernpm run quality:analyze/quality:fix— code-quality scripts
Environment handling
src/config.js is the important runtime config gate.
- It reads from
window._env_first when present. - It falls back to
import.meta.env. - It blocks access to forbidden frontend keys.
- It returns an empty API base URL in dev so the browser can use the Vite proxy rather than hitting the backend directly.
That means environment precedence is intentional, not incidental: runtime injection wins over build-time values when both exist.
Dev-server proxying and static assets
The API client assumes the frontend can talk to a backend through the Vite development proxy in local mode. The build/runtime docs and Vite config establish the reverse-proxy/static-asset behavior used for development and production parity.
Deployment shape
The root README and deployment files describe a containerized path:
- multi-stage Docker build,
- static asset output from Vite,
- Nginx serving the built app,
- runtime env injection via
env.shandwindow._env_.
Operational files worth checking together
Dockerfiledocker-compose.ymlnginx.confenv.shvite.config.jsplaywright.config.tsvitest.config.tsunified-deployment.yaml
What to validate after changes
- Build changes:
npm run build - Runtime config changes:
npm run devplus the relevant contract test(s) - Deployment wiring: container build/run and the affected route workflow
- Security changes:
npm run security:fullplus the focused unit/contract tests
Scope boundary
This page is about repository operations and frontend deployment behavior. It does not document backend deployment internals or cloud infrastructure beyond what is needed to understand this frontend’s runtime assumptions.