description: Build/deploy runtime for Time Machine — the multi-stage Docker image, docker-compose, push-to-nas/deploy scripts, Synology reverse proxy, and the 3099 port lane. No cloud CI.
---
# /devops — build & deploy
Own how **Time Machine** ships (see `CLAUDE.md` + `docs/SETUP.md`). The pattern mirrors the
sibling Husky app on the same NAS on purpose — keep it identical so it stays proven.
## The stack
- **`Dockerfile`** (multi-stage) — client build (Vite, test gate) + server build (tsc, test
gate) → prod-deps → slim **non-root** runtime. Build tooling never reaches the final image;
Keep the 3099 lane (husky 3080, utility 3040). `.env`**is synced** to the NAS by `npm run deploy`
(keep `NODE_ENV=production`; `.env.*` variants stay local; never baked into the image). Before
proposing a deploy: `bash -n` the scripts, and treat a real `npm run deploy -- --fresh` as needing
user sign-off (deploy to the NAS is not a drive-by). End with `## Next`.
## Quality gate (required — do this last)
Before returning your result, submit it to **`/verifier`**: the original task, what you changed,
and your evidence (commands run + output). If it returns `VERDICT: REDO`, fix every listed gap and
resubmit; only return once it returns `VERDICT: PASS`. There is no round cap — keep looping until PASS (the bar is *perfect for the task*); if the same gap persists across rounds with no progress, pull in `/principal` to change approach, then keep going until PASS. Never skip this (`/verifier` itself is exempt, to avoid recursion).