memstack-deployment-netlify-deploy

Use this skill when the user says 'deploy to Netlify', 'Netlify setup', 'netlify-deploy', or needs to deploy a static site or serverless functions to Netlify with build configuration and custom domains. Do NOT use for Railway, Vercel, or VPS deployments.

cwinvestments/memstack5 installsMITSynced Aug 26

Works with

Claude CodeCursorCodex CLIGitHub CopilotGemini CLI
---
name: memstack-deployment-netlify-deploy
description: Use this skill when the user says 'deploy to Netlify', 'Netlify setup', 'netlify-deploy', or needs to deploy a static site or serverless functions to Netlify with build configuration and custom domains. Do NOT use for Railway, Vercel, or VPS deployments.
license: MIT
---

# 🌐 Netlify Deploy β€” Pre-flight check and deploy to Netlify...
*Validates build config, redirects, environment variables, and deployment readiness for Netlify static/SPA hosting.*

## Activation

When this skill activates, output:

`🌐 Netlify Deploy β€” Running pre-flight checks...`

Then execute the protocol below.

| Context | Status |
|---------|--------|
| User says "deploy to netlify" or "netlify deploy" | ACTIVE |
| User says "deploy frontend" or "deploy static site" | ACTIVE |
| Preparing a React/Vue/Svelte/Next.js static export for hosting | ACTIVE |
| Deploying a backend service or API server | DORMANT β€” use railway-deploy |
| Discussing Netlify pricing or features generally | DORMANT |

### Anti-patterns

| Trap | Reality Check |
|------|---------------|
| "I'll configure it in the Netlify UI" | `netlify.toml` is version-controlled and portable. UI settings get lost across teams. |
| "Redirects work fine without _redirects" | SPA routing breaks on refresh without `/* /index.html 200`. Every SPA needs this. |
| "Environment vars are the same everywhere" | Build-time vars (baked into JS bundle) vs runtime vars (Netlify Functions) are different. `NEXT_PUBLIC_` prefix exposes to client. |
| "The API proxy just works" | `/api/*` redirects must point to your actual backend URL. Forgetting to update after backend redeploy breaks the frontend. |
| "I'll check the deploy after pushing" | `netlify deploy --build` locally catches build failures before they hit production. Always build locally first. |

## Protocol

### Step 1: Check Build Configuration

Look for Netlify config and verify build settings:

```bash
# Check for Netlify configuration
ls netlify.toml _redirects _headers 2>/dev/null

# Check package.json for build script
cat package.json | grep -A2 '"scripts"' | grep '"build"'
```

If `netlify.toml` exists, verify it:

```toml
# Expected structure
[build]
  command = "npm run build"    # or "yarn build", "pnpm build"
  publish = "dist"             # or "build", "out", ".next" (varies by framework)

[build.environment]
  NODE_VERSION = "20"          # Pin Node version for reproducible builds
```

| Framework | Build Command | Publish Directory |
|-----------|--------------|-------------------|
| React (CRA) | `npm run build` | `build` |
| React (Vite) | `npm run build` | `dist` |
| Next.js (static) | `next build && next export` | `out` |
| Vue | `npm run build` | `dist` |
| Svelte/SvelteKit | `npm run build` | `build` |
| Astro | `npm run build` | `dist` |
| Plain HTML | β€” | `.` or `public` |

**Flag if:** `netlify.toml` missing or publish directory doesn't match framework default.

### Step 2: Verify Redirects and API Proxy

```bash
# Check redirect files
cat netlify.toml 2>/dev/null | grep -A5 '\[\[redirects\]\]'
cat _redirects 2>/dev/null
```

Check for the API proxy pattern (frontend β†’ backend):

```toml
# netlify.toml β€” API proxy to Railway/external backend
[[redirects]]
  from = "/api/*"
  to = "https://your-backend.up.railway.app/api/:splat"
  status = 200
  force = true
```

Or in `_redirects`:
```
/api/*  https://your-backend.up.railway.app/api/:splat  200
```

**Verify:**
- βœ… Backend URL is the production URL (not localhost)
- βœ… `status = 200` (proxy, not redirect β€” preserves the URL for the client)
- βœ… `force = true` if the proxy should override static files at the same path
- ❌ Backend URL still points to `localhost:3000` β€” update to production

**Flag if:** Code references `/api/` paths but no proxy redirect is configured.

### Step 3: Verify SPA Routing

Single-page apps need a catch-all redirect so deep links and page refreshes work:

```bash
# Check for SPA redirect
grep -r "\/\*.*\/index\.html\|\/\*.*200" netlify.toml _redirects 2>/dev/null
```

Required for SPAs (React Router, Vue Router, etc.):

```
# In _redirects (must be LAST rule β€” order matters)
/*  /index.html  200
```

Or in `netlify.toml`:
```toml
[[redirects]]
  from = "/*"
  to = "/index.html"
  status = 200
```

**Flag if:** Project uses client-side routing but no catch-all redirect exists. Symptoms: pages work when navigated to via links, but return 404 on direct URL access or refresh.

**Note:** Next.js static export handles this differently β€” each page is pre-rendered as its own HTML file. SPA redirect is NOT needed for static Next.js.

### Step 4: Verify Environment Variables

```bash
# Find env vars used in frontend code
grep -rn "process\.env\.\|import\.meta\.env\.\|VITE_\|NEXT_PUBLIC_\|REACT_APP_" --include="*.ts" --include="*.tsx" --include="*.js" --include="*.jsx" . | grep -v node_modules
```

**Build-time vs runtime separation:**

| Prefix | Framework | When Available | Exposed to Client? |
|--------|-----------|---------------|-------------------|
| `REACT_APP_` | CRA | Build time | ⚠️ YES β€” baked into JS bundle |
| `NEXT_PUBLIC_` | Next.js | Build time | ⚠️ YES β€” baked into JS bundle |
| `VITE_` | Vite | Build time | ⚠️ YES β€” baked into JS bundle |
| No prefix | Any | Build time only | ❌ No β€” server-side/build scripts only |

**Critical security check:**
```bash
# Search for secrets that might be exposed to client
grep -rn "NEXT_PUBLIC_.*SECRET\|NEXT_PUBLIC_.*KEY\|VITE_.*SECRET\|REACT_APP_.*SECRET" --include="*.ts" --include="*.tsx" --include="*.js" --include="*.env*" . | grep -v node_modules
```

**Flag if:** Any secret (API keys with write access, database URLs, auth secrets) uses a client-exposed prefix. These are baked into the JavaScript bundle and visible to anyone who opens DevTools.

**Output:** List each variable with where to set it:
- Netlify UI: Site Settings β†’ Environment Variables (for secrets)
- `netlify.toml` `[build.environment]` (for non-sensitive build config like `NODE_VERSION`)

### Step 5: Check Custom Domain and SSL

```bash
# Check for domain configuration
cat netlify.toml 2>/dev/null | grep -A5 '\[context\]'
```

Verify in Netlify dashboard:
- βœ… Custom domain added (Domain Management β†’ Add domain)
- βœ… DNS points to Netlify (CNAME to `*.netlify.app` or A record to Netlify load balancer)
- βœ… SSL certificate provisioned (automatic via Let's Encrypt β€” check HTTPS section)
- βœ… Force HTTPS enabled (redirects http β†’ https)
- βœ… www redirect configured (www β†’ apex or apex β†’ www β€” pick one, be consistent)

**Flag if:** Domain is added but DNS hasn't propagated or SSL shows "Waiting for DNS verification."

### Step 6: Check for Netlify Functions

```bash
# Check for serverless functions
ls netlify/functions/ functions/ 2>/dev/null
cat netlify.toml 2>/dev/null | grep 'functions'
```

If functions exist, verify:
- Function directory is specified in `netlify.toml`: `[functions] directory = "netlify/functions"`
- Functions have correct export pattern: `export const handler = async (event, context) => { ... }`
- Environment variables needed by functions are set in Netlify dashboard (these are runtime, not build-time)
- Functions are not importing large dependencies that exceed Netlify's 50MB bundle limit

### Step 7: Check Headers Configuration

```bash
# Check for security headers
cat netlify.toml 2>/dev/null | grep -A10 '\[\[headers\]\]'
cat _headers 2>/dev/null
```

Recommended security headers:

```toml
# netlify.toml
[[headers]]
  for = "/*"
  [headers.values]
    X-Frame-Options = "DENY"
    X-Content-Type-Options = "nosniff"
    Referrer-Policy = "strict-origin-when-cross-origin"
    Permissions-Policy = "camera=(), microphone=(), geolocation=()"
```

### Step 8: Pre-Deploy Checklist

Build locally to catch errors before Netlify builds:

```bash
# Local build test
npm run build

# Check output directory exists and has content
ls -la dist/  # or build/, out/, etc.

# Check for common issues
grep -rn "http://localhost\|http://127\.0\.0\.1" dist/ 2>/dev/null
```

| Check | Command | Pass Criteria |
|-------|---------|--------------|
| Build passes | `npm run build` | Exit code 0, no errors |
| Output directory exists | `ls dist/` | Has index.html and assets |
| No localhost in build | grep dist/ for localhost | Zero matches |
| _redirects in output | `ls dist/_redirects` | Exists if using _redirects approach |
| Env vars documented | Check .env.example | All client vars listed |
| No secrets in client code | grep for exposed secrets | Zero matches |
| Git clean | `git status` | All changes committed |

**Output pre-deploy summary:**

```
🌐 Netlify Deploy β€” Pre-flight Complete

Project: [name] ([framework])
Build: βœ… passes β†’ [publish directory]
Redirects: βœ… SPA routing + API proxy configured
Env vars: βœ… 8 build-time vars, no secrets exposed
Domain: βœ… [domain] with SSL
Functions: βœ… 2 functions in netlify/functions/
Headers: βœ… security headers configured

Ready to deploy.
  Preview:    netlify deploy --build
  Production: netlify deploy --build --prod
```

### Step 9: Post-Deploy Verification

After deployment completes:

1. **Preview deploy:** Netlify generates a unique URL for every deploy β€” test there first
2. **Check build log:** Netlify dashboard β†’ Deploys β†’ click deploy β†’ Build Log
3. **Test SPA routing:** Navigate directly to a deep route (e.g., `/dashboard/settings`) β€” should load, not 404
4. **Test API proxy:** Open DevTools Network tab, trigger an API call, verify it reaches backend
5. **Check SSL:** Visit `https://[domain]` β€” padlock should appear, no mixed content warnings
6. **Test redirects:** Visit `http://[domain]` β€” should redirect to `https://`

**Rollback plan:**
- Netlify keeps every deploy as an immutable snapshot
- Dashboard β†’ Deploys β†’ click any previous deploy β†’ "Publish deploy"
- Instant rollback, no rebuild required

## Level History

- **Lv.1** β€” Base: Build config validation, redirect/proxy verification, SPA routing, env var security audit, domain/SSL checks, Netlify Functions, security headers, pre/post-deploy checklists. Based on AdminStack marketing site, GreenAcres frontend, and other Netlify deployments. (Origin: MemStack Pro v3.2, Mar 2026)

More Deployment & CI/CD skills

azure-enterprise-infra-planner

microsoft/azure-skills

Architect and provision enterprise Azure infrastructure from workload descriptions. For cloud architects and platform engineers planning networking, identity, security, compliance, and multi-resource topologies with WAF alignment. Generates Bicep or Terraform directly (no azd). WHEN: 'plan Azure infrastructure', 'architect Azure landing zone', 'design hub-spoke network', 'plan multi-region DR topology', 'set up VNets firewalls and private endpoints', 'subscription-scope Bicep deployment', 'Azure Backup for VM workloads'. PREFER azure-prepare FOR app-centric workflows.

387.5k

azure-kubernetes-app-deploy

microsoft/azure-skills

Use when deploying an existing web application or API to an already-running Azure Kubernetes Service cluster. Detects the framework, generates a Dockerfile and Kubernetes manifests, validates against AKS Deployment Safeguards, and deploys with verification. WHEN: deploy app to AKS, deploy to existing AKS cluster, containerize app for Kubernetes, generate K8s manifests for Azure, set up CI/CD for AKS, my AKS deployment is failing safeguard checks, I have a Django/Express/Spring Boot app to run on AKS. DO NOT USE FOR: creating or provisioning an AKS cluster (use azure-kubernetes), assessing migration to AKS Automatic (use azure-kubernetes-automatic-readiness), or deploying to non-AKS targets like Web Apps, Container Apps, or Functions.

380.4k

finetuning

microsoft/azure-skills

Fine-tune models on Microsoft Foundry using SFT (supervised), DPO (preference), or RFT (reinforcement with graders). Covers dataset preparation, training job submission, deployment, and evaluation. USE FOR: fine-tune, SFT, DPO, RFT, training data, grader, distillation, fine-tuned model, training job, large file upload, calibrate grader, deploy fine-tuned model, evaluate fine-tuned model. DO NOT USE FOR: general model deployment without fine-tuning (use deploy-model), agent creation (use agents), prompt optimization without training (use prompt-optimizer).

323.2k

← All Deployment & CI/CD skills

Check your AI visibility

One URL in, a 0–100 score and the exact fixes out.

RUN THE CHECK

Browse all the tools

15 tools across six categories
13 of them never send your data anywhere

Free Β· No signup Β· No trial clock

SEE THE DIRECTORY