Skip to content

Sprint: TCOIN production launch readiness #78

Description

@KazanderDad

Why

TCOIN is close enough to launch that the remaining risk is no longer ordinary code completeness; it is release alignment across GitHub, Vercel, remote Supabase, hosted smoke paths, Buy TCOIN configuration, OTP/signed-in flows, pay-link behaviour, and worker scheduling that CI cannot fully prove yet.

Coordination Objective

Coordinate a Preview-first, Production-second launch-readiness sprint for TCOIN. The sprint should prove the intended hosted environments, keep Buy TCOIN sandboxed before live approval, collect evidence inside each Goal, and leave Production merge/go-live decisions human-owned.

Scaffold Notes

  • Scaffolded early from: GreenPill-TO/Genero, GreenPill Project, issue Goal: Align hosted release environments and remote Supabase readiness #74, and production-readiness interview on 2026-07-16.
  • Still to finalize: exact secret values, Supabase linked-write approvals at time of action, Preview faucet funding details, Production seeded wallet availability, and Supabase-side scheduler implementation choice.

In Scope

  • Configure/confirm GitHub Environment secrets and variables for Preview – tcoin and Production – tcoin where agent permissions allow.
  • Confirm Vercel environment variables and retired aliases for Preview and Production.
  • Align remote Supabase schema/API exposure and release-alignment workflow evidence, with no linked database write unless explicitly approved at the moment of action.
  • Smoke Preview first, including signed-in OTP via hubert.cormac@gmail.com, faucet-funded pay-link create/resolve, and Buy TCOIN sandbox.
  • Configure and prove Supabase-side indexer/onramp worker scheduling.
  • Smoke Production after main merge, including a fresh post-merge Production pass.
  • Keep NEXT_PUBLIC_ENABLE_BUY_TCOIN_CHECKOUT=false unless Buy TCOIN is fully configured and smoke-tested for the target environment.

Out Of Scope And Follow-On Candidates

  • Full Dependabot/security backlog triage unless a vulnerability blocks launch smoke.
  • CI automation for OTP and authenticated browser sessions; this sprint uses manual or agent-assisted Gmail OTP retrieval for speed.
  • Live Buy TCOIN enablement before sandbox evidence and explicit human approval on the main path.
  • Direct linked Supabase database writes without separate just-in-time human approval.

Brainstorm Summary

  • Selected current-scope idea: four-Goal production-readiness sprint with Preview first, then Production.
  • Strong follow-on candidates: seeded auth fixture for repeatable e2e, dependency/security triage sprint, automated hosted authenticated e2e, and mainnet seeded-wallet operational playbook.
  • Rejected or out-of-bounds ideas: merging Buy TCOIN live and sandbox into one Goal, treating Preview smoke as sufficient for Production, and hiding evidence in a separate packet rather than each Goal.
  • Evidence still useful: workflow run URLs, Vercel deployment URLs, Supabase schema/API checks, OTP screenshots/notes, pay-link token lifecycle notes, Buy TCOIN sandbox receipts, worker queue/cron health, and final Production smoke notes.

Sequencing

Codebase Findings

Guardrails

  • GitHub Environment secrets/vars may be configured directly where permissions allow.
  • Vercel env confirmation may be performed directly where permissions allow.
  • Linked Supabase writes require separate explicit approval at the moment of action.
  • Production must receive its own post-merge smoke pass before this Sprint closes.
  • Evidence belongs in each Goal, not in a separate evidence-packet Task.
  • If Buy TCOIN is not fully green, proceed with NEXT_PUBLIC_ENABLE_BUY_TCOIN_CHECKOUT=false.

Recommended Approach

Keep this as a lean four-Goal Sprint. Each Goal should be independently executable by Codex or a human operator, with evidence captured on the Goal and exact blockers recorded rather than silently bypassed.

Alternatives Considered

Option Pros Cons Decision
Four Goals Clear sequence, manageable issue count, evidence per lane Requires careful dependency tracking Chosen
Three Goals Fewer issues Worker scheduler risk gets buried Rejected
Five Goals More precise Buy TCOIN split More overhead before launch Deferred unless vetting recommends it

Evaluation Criteria

  • Preview target release-alignment workflow completes green.
  • Preview hosted smoke proves signed-in OTP, faucet-funded pay-link create/resolve, and Buy TCOIN sandbox.
  • Supabase-side worker scheduling is configured and queue drain evidence is captured.
  • Production target has its own post-merge smoke evidence.
  • Buy TCOIN remains disabled unless the target environment is fully configured and smoke-tested.

Validation Plan

  • GitHub release-alignment workflow for Preview and Production.
  • Vercel deployment checks for TCOIN Preview and Production.
  • Wallet preflight and TorontoCoin ops checks from the correct environment profile.
  • Manual/agent-assisted Gmail OTP smoke using hubert.cormac@gmail.com.
  • Faucet-funded pay-link create/resolve on Preview.
  • Production read/resolve-only pay-link smoke until a seeded mainnet wallet is provided.
  • Worker queue and scheduler health checks.

Project Metadata

  • Project: GreenPill Project
  • Priority: High
  • Initial status: Scoped
  • Labels: none
  • Assignees: none

Goals And Tasks

Risks And Mitigations

  • External env permissions may block direct configuration: record exact blocker and operator action.
  • Linked Supabase writes may be required: stop for explicit approval before any write.
  • Buy TCOIN may not be launch-ready: keep checkout disabled and launch without it if other paths are green.
  • OTP delivery may be flaky: use Gmail browser for fastest retrieval and record timing/evidence.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions