kestrel-one

Operate Kestrel One in production

Operate Vercel natively and release every Fly, RunPod-worker, and tenant runtime target manually.

Kestrel OneadvancedCurrent releases
Verified 2026-08-16View sourceReport a docs issue

Use the production delivery runbook before enabling an organization and after a change to application code, data, workers, images, model access, Apps/MCP, or managed deployment infrastructure.

Establish a healthy baseline

Record the operator, intended targets, and chosen image tag. Confirm the Vercel application, PostgreSQL, Redis, object storage, queue services, runner access, approved gateways/models, workers, Fly image roles, and email services are healthy.

Preflight migrations

Inspect the actual production migration history, identify only pending migrations, take an owned backup, and verify application and worker compatibility. Stop when rollback compatibility is unknown.

Let Vercel deploy Web and Docs

Advance the protected production branch through the normal repository process. Vercel natively deploys one and docs; the one build runs the ordinary production migration. Record each real Vercel result.

Publish and deploy one image at a time

Choose a readable tag. Publish only the selected role, then update only the selected Fly Machine. Review the provider record before the change and verify the exact Machine afterward. Managed RunPod worker changes use the same manual Fly path; managed RunPod profile changes remain separate.

Update Router and Workspace Runtime deliberately

Publish Router and Workspace Runtime explicitly with the intended tag. Prove the pair on disposable Fly resources, update one canary Environment, run the live Workspace and Preview canaries, and activate using that exact completed operation. Update every other Environment separately.

Verify the user path

  1. Accept an invitation with a non-administrator account.
  2. Open the intended organization and Project.
  3. Confirm Environment, model, and required App readiness.
  4. Create a Thread and complete one run.
  5. Upload or retrieve permitted Knowledge and inspect an artifact.
  6. Exercise one waiting/operator-control path.
  7. Test an administrative action separately with an administrator.

Run canaries

Verify application health, queue/worker delivery, workspace provisioning, model access, one terminal result, artifact persistence, operator control, and selected image tags before changing another target.

Prove recovery after a change

Preserve application, database, queue, runner, deployment, model, trace, and image evidence. Restore the prior provider deployment or operator tag only when migrations remain compatible; otherwise stop and fix forward.

Incident handoff

Include the operator, chosen tag, intended targets, Vercel deployments, migration before/after state, Fly Machine before/after records, organization/Environment/Project/Thread/run identifiers, trace correlation, timestamps, observed symptom, and last safe action.

Escalate when equivalent actors receive different authority results, data disappears, a credential reaches browser state, an unqualified deployment becomes selectable, or the selected production target cannot be verified.