A preview environment is a test surface with its own deployment identity and configuration. It may read unpublished content for editorial review, but that access must not turn draft data into a public production route. Separate API credentials, CMS endpoints, and cache namespaces where possible. A preview hostname should not be used as the production smoke target, and a production build should reject preview-only flags. Check which branch or commit triggered the deployment and which configuration values were injected at build time; changing an environment variable after a static build may require another build. Treat preview URLs as potentially shareable unless access controls are actually enforced.
Preview and production publishing: keep content and configuration separate
Operational decision
A candidate branch renders a draft lesson for an editor. The preview build uses a restricted draft-reading credential and a preview cache namespace; the production build uses only public published content. Before promotion, a release check compares the branch, deployment ID, CMS mode, and output directory against an expected production manifest. It also probes a draft slug through the public hostname and requires a non-success response. A preview rendering that looks correct is useful evidence for layout and editorial review, but it does not establish that the production deployment received the same content snapshot or that the live route is reachable. Record both observations separately.
Environment gate
Preview: candidate branch, draft-reading credential, isolated cache
Production: approved branch, published-only collection
Production build assertion: preview flag absent
Public draft probe: no successful response
Release receipt: deployment ID and CMS snapshot revisionCost and verification
Duplicating builds and cache namespaces increases storage and execution cost, but it prevents a preview-only revision from contaminating production. A credential with draft access expands the blast radius of a leaked preview; scope it to the minimum records and revoke it when the review ends. Checking E environment fields is O(E) local work. The expensive part is proving the resulting public behavior, so include production-route probes and an explicit draft-leak test in the release gate.
Common Mistakes
- Do not infer production state from a preview deployment.
- Do not ship a draft-reading token in the browser bundle.
- Do not assume a private preview merely because its URL is hard to guess.
Connected lessons
- DevOps: delivery, infrastructure, and reliable operations
- Headless CMS publishing: define which records become public routes
- Web publishing evidence: prove the build, deployment, and live route separately
- Secrets and configuration across the delivery path
