# Deploy a ROM application

Choose the exact source revision and support profile before deployment.
The 0.1.0 checkout is a source candidate. It does not establish production readiness.

## Verify the selected source

Use the checkout's declared toolchain and lockfiles. Run the local verifier.

```sh
./scripts/check
```

Run both maintained adapter workflows when your application depends on their common contract.

```sh
./demo/run smoke
./demo/run smoke redb
```

Read [release support](release-support.md) before choosing an artifact.
Do not mix native alpha packages with a different source package set.

## Start the local reference host

The maintained workshop serves a persistent SQLite database on numeric loopback.

```sh
./demo/run serve sqlite ./demo.db 8080
```

The host binds to `127.0.0.1`. Its demonstration identity is a local fixture.
It is not a production authentication system.
Read the [workshop](../demo/README.md) for identity and CLI instructions.

## Choose identity and transport

Use the explicit [provider deployment profile](provider-deployment.md) for its service-identity workflow.
This profile does not establish universal OAuth compatibility or human login.

Build its reference host and CLI.

```sh
cargo build --locked -p rom-demo -p rom-cli --features rom-demo/provider-profile
```

Provision with an approved private configuration file.

```sh
rom-demo provider-provision sqlite DATABASE CONFIG_FILE
rom-demo provider-serve sqlite DATABASE CONFIG_FILE 0
```

Keep backend credentials in the host. Use approved secret references.
Configure your reverse proxy for TLS. Verify issuer, audience and current authority with your actual provider.
A reverse proxy does not grant Resource permissions.

## Preserve durable data

Mount the database and external Blob bytes on persistent storage.
Keep a verified backup before offline maintenance.
Stop the active owner before maintenance or migration.
Use the declared upgrade procedure for historical formats.

Test restart recovery with your selected database and application.
An acknowledged commit and a client acknowledgement are separate facts.
Preserve the operation identity when an outcome remains unknown.
Read [operator recovery](operator-recovery.md) before retrying uncertain work.

## Select optional integrations

Read the [Extras catalog](/extras/) before choosing a database executor or external service.
SQL executor tests are not full ROM Storage acceptance.
Confirm TLS, delivery guarantees, provider limits and required attribution for the exact profile.
Use [Extras support status](extras-support.md) for evidence and remaining gates.

## Operate within the verified boundary

Keep one declared database owner. Do not infer multiwriter support from a local test.
Record source, lockfile, binary, database format and configuration identities with deployment evidence.
Keep private values and credentials out of logs and defect reports.
Verify login, denied operations, restart, observation and unknown-outcome recovery in the assembled application.
Automated fixtures do not establish human usability or production TLS acceptance.
