Guides

Preview deployments

Pull requests get their own URL and disposable data — never production secrets or DB — torn down on merge.

What you get

When preview deploys are enabled on a service and the GitHub App can reach the repo:

  • A dedicated preview Environment (kind=preview, slug pr-{n}) forked from your project's preview-base
  • NetworkPolicy isolation for that environment (same labels as persistent stages)
  • A unique preview URL per PR (for example https://{name}-pr-{n}-{shortId}.…)
  • Child services marked as previews (isPreview + parentServiceId) for CLI pairing
  • Overlay Variables from the base (non-secrets copied; secret values blank)
  • Automatic teardown of the environment + NetworkPolicy when the PR merges or closes

Previews are not attached to custom project domains (ADR-0005 — bind attempts return 400).

Preview-base

PR environments clone from the project's preview-base persistent environment:

  1. The environment with previewBase=true, or else
  2. The first non-production persistent environment (by position), or else
  3. Production — still without copying secret values or cloning databases

Prefer Staging (or Testing) as preview-base when you have extra environments. Enable preview deploy on the logical services in that base environment (the platform migrates the flag from production counterparts by logicalKey when needed).

Previews never clone databases. Operators can attach a disposable DB later if required.

Safety vs production

Treat preview data as disposable:

  • DATABASE_URL and other secrets on the preview env start blank (or point only at what you fill in) — they are not production values.
  • Fill blank secrets on the preview-base before expecting previews to boot cleanly.
  • Billing reap always deprovisions preview services before non-preview excess.

Enable

  1. Install the GitHub App on the repository.
  2. Set preview-base (Manage environments) when you have Staging/Testing.
  3. Turn on preview deploy on the logical web/static service in that base.
  4. Open or update a pull request — the webhook forks pr-{n} and deploys.

There is no separate /previews dashboard page; preview services appear on the Pipeline / overview with preview badges. CLI: bytstack preview.

Protecting previews

Treat preview URLs as semi-public. Prefer password protection or SSO when sharing with clients.

Differences from production

Previews may use smaller compute, ephemeral data, and different Variables. Never assume preview data is production-safe. Custom domain routes are rejected for preview environments and isPreview services.