Environments
tsdevstack supports multiple deployment environments. Each environment is completely isolated with its own cloud project/account.
Specifying the Environment
CLI Commands
All cloud commands accept the --env flag:
CI/CD Workflows
All workflows accept an environment input.
Environments are configured in .tsdevstack/ci.json:
Environment Isolation
Each environment must use a separate cloud project/account:
The framework validates credentials and rejects deployments if the same project/account is used for multiple environments.
Why Separate?
- Security - Production credentials cannot affect dev
- Billing - Clear cost attribution
- IAM - Separate permission boundaries
- Quotas - Environments don't compete for limits
- Certificates - SSL certificates are environment-specific
Adding a New Environment
-
Create the cloud project/account for the new environment
-
Add credentials:
- Update CI configuration:
- Regenerate workflows:
-
Add GitHub secrets for CI (environment name in uppercase):
GCP_WIF_STAGINGGCP_SA_STAGINGGCP_REGION_STAGING
NPM_TOKEN(if your project uses private npm packages) is the only generated-workflow secret that is not per-environment — add it once globally, no_STAGING/_PRODvariant. See Private npm packages. -
Push secrets:
- Deploy:
Local Development
Local development does not use environments. It uses:
.secrets.local.jsonfor secretsdocker-compose.ymlfor infrastructure- Services run natively via npm