DomainRuntimedocs
Environments
PlannedWhat works todayReviewed 2026-09-23

Production

Release your domain to a production environment, change it safely, and roll back.

Releases run in production today as immutable builds of your domain source, created through the platform. druntime push releases your folder's domain; building straight from a Git commit and rollback from the CLI are planned.

A production environment runs a release: your domain and action code, built once, immutable. A development session never touches production; a release is an explicit druntime push to the production environment.

Create the environment

druntime env create main --project orders --mode prod --client-org acme

Its handle is prod-acme-main and its URL https://prod-acme-main.domainruntime.cloud. Set the project's repository, branch and root directory when you create the project (druntime project create orders --repository … --branch main) or in the console.

Release

druntime push --env prod-acme-main
  1. The CLI uploads your domain's source from your folder (see Releasing to production).
  2. The platform builds your domain and action code. A failed build shows the compiler's messages at your files' paths.
  3. It applies your schema, checked against the stored data first. A change the data does not allow, or an unconfirmed removal, stops the release and nothing is applied. See Changing the schema.
  4. It activates the release. New calls run the new code; calls already in flight finish on the old one.

The release records the digest of the built code, the schema it applied, and who pushed it and made it live.

Who can release: an owner or admin of the organization, signed in as themselves, or the organization's service key from CI. The first release also sets up the environment's runner with a credential valid for that environment only; nobody handles it, and the organization's key never leaves the platform.

Making safe changes

When a release activates, browsers that loaded your app before it are still open, and workflows started before it are still running. Change things so both keep working.

ChangeSafeUnsafe
Action inputadd an optional fieldadd a required field, narrow a type, rename a field
Action outputadd a fieldremove or rename a field an old client reads
Actionsadd a new actionrename or remove one that old clients call
Schemaadd an entity, attribute or linkchange or remove an attribute (refused on release)
Workflowschange code; running runs stay on their release—

To make an unsafe change, do it in steps: add the new shape, release, move clients to it, then remove the old one in a later release.

Roll back

druntime release rollback --env prod-acme-main

Rollback re-activates the previous release's code. It does not revert data or schema — one more reason to only ever add to the schema in a release.

Delete an environment

druntime env delete prod-acme-main    # type the handle to confirm

It stops serving at once and its data is kept for 2 days: druntime env restore prod-acme-main brings the environment back with its data and its last release. While custom domains still point at it, it is not deleted without --force. See Deleting an environment.

Before you ship

  • Every entity has explicit rules and the default is deny: $default: { allow: { $default: "false" } }. See Permissions.
  • Every action checks its caller at the top of execute. See Actions.
  • Your backend mints user tokens. See Users.
  • Actions that create things take a caller-chosen id or write through a .unique() attribute. See Guarantees.

On this page