Preview deployments
Pull requests get their own URL and disposable data — never production secrets or DB — torn down on merge.
What you get
When preview deploys are enabled on a service and the GitHub App can reach the repo:
- A dedicated preview Environment (
kind=preview, slugpr-{n}) forked from your project's preview-base - NetworkPolicy isolation for that environment (same labels as persistent stages)
- A unique preview URL per PR (for example
https://{name}-pr-{n}-{shortId}.…) - Child services marked as previews (
isPreview+parentServiceId) for CLI pairing - Overlay Variables from the base (non-secrets copied; secret values blank)
- Automatic teardown of the environment + NetworkPolicy when the PR merges or closes
Previews are not attached to custom project domains (ADR-0005 — bind attempts return 400).
Preview-base
PR environments clone from the project's preview-base persistent environment:
- The environment with
previewBase=true, or else - The first non-production persistent environment (by position), or else
- Production — still without copying secret values or cloning databases
Prefer Staging (or Testing) as preview-base when you have extra environments. Enable preview deploy on the logical services in that base environment (the platform migrates the flag from production counterparts by logicalKey when needed).
Previews never clone databases. Operators can attach a disposable DB later if required.
Safety vs production
Treat preview data as disposable:
DATABASE_URLand other secrets on the preview env start blank (or point only at what you fill in) — they are not production values.- Fill blank secrets on the preview-base before expecting previews to boot cleanly.
- Billing reap always deprovisions preview services before non-preview excess.
Enable
- Install the GitHub App on the repository.
- Set preview-base (Manage environments) when you have Staging/Testing.
- Turn on preview deploy on the logical web/static service in that base.
- Open or update a pull request — the webhook forks
pr-{n}and deploys.
There is no separate /previews dashboard page; preview services appear on the Pipeline / overview with preview badges. CLI: bytstack preview.
Protecting previews
Treat preview URLs as semi-public. Prefer password protection or SSO when sharing with clients.
Differences from production
Previews may use smaller compute, ephemeral data, and different Variables. Never assume preview data is production-safe. Custom domain routes are rejected for preview environments and isPreview services.