Skip to main content
This chapter is the operator’s map. Each step has a check; do not go on until it passes. The complete runbook, with every command and every failure, is Production deployment; every variable is in the Environment variable reference.

What runs

One Node.js process: the API, the policy engine and the gateway together. The same code runs as a container (Dockerfile, docker/entrypoint.sh) or as a Vercel function (api/index.ts, vercel.json). It needs a Postgres database (Supabase works). Production refuses to start without a real database, signing keys and caller authentication, and never falls back to something weaker.

The procedure

At startup the log line runtime_engine_constructed must show policyExecutionVerifierConfigured, signingReadinessConfigured and executionIntentsConfigured all true. In production they are on and cannot be switched off.

Keys and who holds them

A caller key grants its allowedCapabilities and acts for its allowedPrincipalIds (the caller id when none are named). Never grant "*" to an agent.

Upgrades

  1. Migrations first. npm run db:migrate -- apply against production before deploying the version that needs them. A version that finds a table missing refuses requests (for example 503 EXECUTION_INTENT_UNAVAILABLE) rather than run without it.
  2. New policy versions are not deploys. They take effect when approved (Chapter 4).
  3. A changed environment variable needs a new deployment on Vercel before it takes effect.
  4. Restarts are safe. On SIGTERM in flight requests finish (up to SHUTDOWN_TIMEOUT_MS, default 10000), and the replay and audit stores are in the database, not in memory.

Monitoring

Rotation

A key that was ever shown in a chat, a ticket or a log is exposed: rotate it.

Self hosted

To run Parmana on your own infrastructure with one command, with the database included, use the self hosted deployment. The checks above still apply.