# TechHeck Admin — deployment

Production hosting is Namecheap shared hosting. The admin app is a **separate** cPanel Node.js application from the marketing site (`techheck`) and the Ask bot (`techheck-bot`).

This repo deploys on its own when `main` is updated (same pattern as the site).

## Branches

| Branch | What happens |
| --- | --- |
| `feature/*` | Work + local verify at http://127.0.0.1:3002/Admin |
| `main` | GitHub **Deploy production** → FTP upload + health check |

Never push product work straight to `main`. Merge only after local OK and an explicit deploy request.

## GitHub secrets (`production` environment)

| Secret | Value |
| --- | --- |
| `FTP_SERVER` | Namecheap FTP hostname (same as site if same account) |
| `FTP_USERNAME` | FTP user that can write the admin app folder |
| `FTP_PASSWORD` | FTP password |
| `PRODUCTION_ADMIN_ROOT` | FTP path to the Node app root, e.g. `techheck-admin/` |
| `PRODUCTION_ADMIN_HEALTH_URL` | HTTPS health URL, e.g. `https://admin.techheck.co/health` |

Do **not** put DB passwords, `SESSION_SECRET`, or mailbox secrets in GitHub. Those stay in cPanel → Setup Node.js App → Environment variables.

## First-time Namecheap setup

Follow `docs/namecheap.md` once: create the Node app, set env vars, Run NPM Install, Restart. Then add the secrets above and push/merge to `main` (or run **workflow_dispatch**).

After each FTP deploy, if health still shows the old process, **Restart** the Node app in cPanel.

## Marketing site link

On the next **site** production build, set:

```env
NEXT_PUBLIC_ADMIN_API_URL=https://admin.techheck.co/Admin
```

(or your live admin origin + `BASE_PATH`) so the footer can load public settings.

## Rollback

1. Note a good commit SHA from a successful **Deploy production** run / artifact.
2. Revert or reset `main` to that commit with a normal push (no force-push).
3. Approve the new production run and confirm health + `deploy-sha.txt` on the server if uploaded.
