Developer guide / Storage & readiness

Spaces is the only store

Perminister persists identities, password verifiers, sessions, grants, API-key verifiers, and audit events in the configured private DigitalOcean Spaces bucket. There is no database fallback.

Storage boundary

Only server code receives Spaces credentials. Browser clients and consumer applications never access the bucket directly.

PersistencePrivate DigitalOcean Space
RegionSFO3
Bucketperminister
Object IDsOpaque UUIDs
CredentialsServer-side only

Set PERMINISTER_SPACES_ACCESS_KEY and PERMINISTER_SPACES_SECRET_KEY securely. Keep both credential values blank in templates and out of public environment variables.

Recoverable mutations and write boundary

Each mutation appends a versioned event before replacing its record snapshot. A later read replays the newest full-record event if the snapshot is missing or stale.

01

Issue admin changes one at a time

The process-local queue is not a distributed lock. This low-volume operating assumption limits operator overlap, but multiple Vercel instances can still race against the same Spaces objects.

02

Enable recovery support

Enable Spaces object versioning and keep a separate backup before production writes. Spaces does not provide cross-object transactions.

03

Inspect partial multi-record actions

Account registration, password recovery, and key rotation can span several records. If a response is lost, inspect event history before retrying or manually repairing state.