exoDocs

The stack

07 · Deploy

exo-deploy ships every surface. Web apps and services run on Railway, and iOS and Android apps ship with Expo.

Dimension
07 · Deploy
Platform
Railway + Expo · via exo-deploy
Railway
Bounded application hosting observed by EXO through explicit health and release evidence. Core standard · authority: EXO
Expo
Open-source mobile framework for iOS, Android, and web releases, with swappable build and submit services. Core standard · authority: EXO
Status
Web live on Railway. Mobile toolkit accepted (ADR 0007, 2026-09-27) and planned; Universe already ships on Expo.

What it is

The deploy dimension answers: how does each surface reach users, and what is running now? exo-deploy owns the release path for every surface:

SurfacePlatformPath
Web apps and servicesRailwaystaging auto-deploys; a release PR to main promotes production
Mobile apps (iOS, Android)ExpoTestFlight, then the App Store and Google Play
Pages and embedded app surfacesConstruct on RailwaySame path as web

Every surface follows the same Staging → Release Candidate → Production path, described in How work ships. The service design is on the exo-deploy page. In-app purchases live under Payments, not here.

Platform

  • Railway runs Next.js hosting for the Exo web app, cron workers that reach external systems (Entire trail sync, provider health sweeps, revenue snapshot pulls), and Valkey for rate limits and short-lived caches (infrastructure). The Exo web image is a standard Dockerfile (node:22-bookworm-slim, pnpm 11.15, pnpm build, port 3000, output: 'standalone'). The self-hosted Arch-Router assessor is a second Railway service built from services/arch-router/.
  • Expo, an MIT-licensed framework on React Native, is the standard mobile framework for Exo apps. EAS is optional and swappable for build, submit, and OTA updates (ADR 0007).

Boundary and replaceability

  • Web: the contract is an OCI image: a standard Dockerfile, an HTTP port, and environment variables. Railway and Coolify are the initial adapters, and the contract requires neither (architecture, cross-platform delivery).
  • Railway holds runtime secrets. Exo stores only the names of environment variables.
  • Leaving the managed runtime includes a documented handoff of the container contract, health checks, variable names, volumes, scheduled jobs, domains, and rollback (portability).
  • A provider-generated hostname is deployment evidence, never the review URL (staging topology).
  • Mobile: EAS is a service choice, not a dependency. The exo-deploy mobile template keeps a local-build path (eas build --local or fastlane). The repository contract keeps a PWA-required-for-mobile gate, and each app registers its native redirect scheme with Exo Key during onboarding.

Cost notes

Web:

  • One recorded unit cost: ~$0.007 per 5-minute run on a 2 vCPU / 2 GB Railway worker (ADR 0005, used to price exo-verify).
  • The Arch-Router service is CPU-only and runs comfortably in ~1 GB RAM, with no per-call cost (arch-router).
  • Monthly Railway spend for Exo and the portfolio: TBD. Every deployment must first pass the projects.dev credential and spend gate.

Mobile (ADR 0007, 2026-09-27):

StageFixed costMarginal cost
Apple Developer Program$99/year (required)—
EAS Free$0Capped at 15 iOS + 15 Android builds/month, OTA to 1K MAU
EAS Starter$19/monthUsage beyond the $45 build credit
Own Mac builderHardware or hosted Mac~$0 per build; pays off only at high volume

At current volume the mobile toolkit costs about $8/month (Apple fee amortized).

Status

  • Live: Exo web on Railway, with staging at staging.exo.now and production at exo.now.
  • Planned: the exo-deploy mobile template (roadmap: mobile-delivery-pipeline). Template location: TBD.
  • Reference: Universe already ships on Expo, registered with Exo Key using the native redirect universe://auth/callback.
  • Evidence rule: a push proves only that Git received the commit, and a provider success proves only that a deployment job finished. Staging is current only after the deployed commit, /api/health, access boundary, and browser behavior are verified (build and deploy).

Source: content/docs/stack/deploy.mdx

On this page