Skip to content

Debelu service keys and deployment setup ​

Never put server secrets in variables beginning with VITE_ or NEXT_PUBLIC_. Those values are included in the browser build. No key values are stored in this guide.

GitHub Actions: storefront and admin ​

Production builds use Settings → Environments → Production. Add environment secrets:

  • VITE_SUPABASE_ANON_KEY: current Supabase publishable/anon key, from Supabase Project Settings → API Keys. The local frontend keys tested on 2026-10-04 were rejected; replace them with the current key for the same project URL.
  • VITE_PAYSTACK_PUBLIC_KEY: Paystack Settings → API Keys & Webhooks, live public key beginning pk_live_.
  • CLOUDFLARE_API_TOKEN: https://dash.cloudflare.com/profile/api-tokens → Create Token → Create Custom Token. Permission Account → Cloudflare Pages → Edit; Account Resources → Include → Specific account → the account hosting the two Debelu Pages projects. Copy the token when created.
  • CLOUDFLARE_ACCOUNT_ID: in the matching Cloudflare account press Ctrl+K and choose Copy account ID, or Workers & Pages → Account Details → Account ID.

Environment variables:

  • VITE_SUPABASE_URL: the matching Supabase project URL.
  • VITE_API_BASE_URL: https://api.debelu.com/api
  • VITE_R2_PRODUCT_IMAGES: true only after configuring and verifying R2 product image uploads; otherwise false.
  • VITE_VAPID_PUBLIC_KEY: the public half of your web push key pair, matching the Supabase notification function.
  • VITE_STOREFRONT_SENTRY_DSN and VITE_ADMIN_SENTRY_DSN: optional frontend monitoring project DSNs.

Preview uses repository Settings → Secrets and variables → Actions, rather than the Production environment. Use the same setting names, but VITE_PAYSTACK_PUBLIC_KEY must start pk_test_. Preview payments also require a test-mode backend; a test public key alone does not isolate production data or payments. The preview workflow currently shares the repository VITE_API_BASE_URL, so point it at a test backend before running checkout tests.

After saving settings, use Actions → Cloudflare Pages release → Run workflow with production selected, or push changes to main. Updating Cloudflare Pages environment variables alone does not change these GitHub-built assets. GITHUB_TOKEN is automatically supplied by GitHub; do not create it manually.

Railway backend variables ​

Set these on the backend service's Variables page, and redeploy:

  • SUPABASE_URL, SUPABASE_SERVICE_ROLE_KEY, SUPABASE_ANON_KEY: matching Supabase project URL, server service-role key and public key. Keep the service-role key server-side.
  • PAYSTACK_SECRET_KEY: Paystack secret key matching the public key's live/test mode. Register https://api.debelu.com/api/payments/webhook in Paystack's webhook settings.
  • GEMINI_API_KEY: Google AI Studio API Keys; GEMINI_MODEL is optional and defaults to gemini-2.5-flash. Check that the key's Google project allows that model.
  • REDIS_URL: Railway Redis connection URL/reference reachable by the backend.
  • R2_ACCOUNT_ID, R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, R2_PUBLIC_BUCKET, R2_PUBLIC_URL: Cloudflare R2 bucket and S3 credentials with access to that bucket; R2_PUBLIC_URL must be its HTTPS public image URL. The Pages deployment token is not the R2 S3 secret.
  • META_APP_SECRET, WHATSAPP_WEBHOOK_VERIFY_TOKEN: Meta app secret and your chosen webhook verification token. Meta webhook: https://api.debelu.com/api/whatsapp/webhook.
  • SENTRY_DSN: optional backend monitoring.

Vercel marketing project ​

Project Settings → Environment Variables: NEXT_PUBLIC_SUPABASE_URL, NEXT_PUBLIC_SUPABASE_ANON_KEY, NEXT_PUBLIC_API_BASE_URL (https://api.debelu.com/api), NEXT_PUBLIC_PAYSTACK_PUBLIC_KEY if its payment flow is used. Use the same Supabase project and correct live/test public key. Redeploy after changing build variables. Update corresponding local .env files separately.

Supabase notifications and authentication email ​

Edge Functions → Secrets, for deliver-notification:

  • PUSH_WEBHOOK_SECRET: match the database webhook's x-push-secret header.
  • APP_URL and ADMIN_URL: https://app.debelu.com and https://admin.debelu.com.
  • SES_REGION, SES_ACCESS_KEY_ID, SES_SECRET_ACCESS_KEY, EMAIL_FROM; optionally EMAIL_REPLY_TO and SES_CONFIGURATION_SET: AWS SES sending configuration and AWS credentials permitted to send from the verified identity.
  • WHATSAPP_ACCESS_TOKEN and WHATSAPP_PHONE_ID: Meta WhatsApp app/API Setup; configure approved notification templates and an appropriate WHATSAPP_GRAPH_API_VERSION.
  • VAPID_PUBLIC_KEY, VAPID_PRIVATE_KEY, VAPID_SUBJECT: generated web push key pair and contact URI; use the same public key in the frontend.
  • FCM_SERVICE_ACCOUNT: Firebase Project Settings → Service accounts → Generate new private key, stored as JSON in the function secret, for Android notifications.
  • APNS_KEY_ID, APNS_TEAM_ID, APNS_PRIVATE_KEY, APNS_BUNDLE_ID, APNS_ENVIRONMENT: Apple Developer APNs signing key (.p8), IDs, app bundle and production/sandbox environment, for iOS notifications.

Supabase supplies reserved SUPABASE_* secrets to functions automatically. If the legacy paystack-webhook Edge Function is still an active webhook destination, it also needs the matching PAYSTACK_SECRET_KEY. Confirm which payment webhook destination is active before configuring an additional one.

Authentication → Email/SMTP: configure your email provider's SMTP host, port, username and password, plus sender address. AWS SES SMTP credentials differ from the AWS API access keys above. For SES eu-west-2, the host is email-smtp.eu-west-2.amazonaws.com; use the provider's supported TLS port such as 587. Verify the sender identity and SES sending restrictions in your AWS account.

Code fixes and rollout ​

Apply supabase/migrations/20261010_001_api_integration_contract_fixes.sql before deploying the modified backend. It requires the existing ledger_post function, wallet_adjustments table and audit_logs table. It restricts execution to service_role and requires an active admin actor, locks the canonical wallet, and commits balance, ledger, adjustment and audit together. This migration has not been applied to production by this audit.

The backend now reads actual profile/order/content flag fields, reads wallets from user_private_info, and checks Paystack/Gemini/R2/Redis connections rather than claiming success from key presence. Gateway coverage includes member wallets and pending withdrawals. This is a liquidity coverage check, not a full bank settlement or fee reconciliation. Notification delivery remains explicitly unverified by backend health checks because delivery occurs in Edge Functions.

After rollout: verify /health and /api/status, staff dependency checks, a test-mode checkout and webhook, image upload, and one notification for each enabled channel. Do not infer successful email, WhatsApp or push delivery from a database row or a key merely being present.

References: https://developers.cloudflare.com/pages/configuration/api/ ; https://developers.cloudflare.com/fundamentals/account/find-account-and-zone-ids/ ; https://supabase.com/docs/guides/functions/secrets ; https://supabase.com/docs/guides/auth/auth-smtp ; https://vercel.com/docs/environment-variables

Released under Proprietary Enterprise License.