Browse the library
Product guide

Operating MachinArc

The deployment, persistence, recovery, and verification model behind the workspace.

Application and database

MachinArc uses Next.js with server-side PostgreSQL access through Drizzle. Application sessions identify operators, and server actions scope workspace operations. The browser does not use the Supabase Data API to read application tables.

Apply the registered Drizzle migrations in sequence. Use a dedicated server database role, enable row-level security, revoke public client-role access, and verify the server role's grants and policies. Supply the trusted database root certificate through DATABASE_SSL_CA so certificate verification remains enabled.

Workers and function budgets

Hosted web processes run with MARC_WORKER=off. A trusted scheduler sends an authenticated POST to /api/internal/worker once per minute. The endpoint advances schedules, recovers eligible orphaned work, and drains a bounded batch of jobs. Its credential and any deployment-protection access must match the deployment.

Hosted function execution is limited to 300 seconds. Keep task runtime and delegation inside that total budget. Use npm run worker for longer execution on infrastructure that supports a continuous process, and disable in-process workers on the accompanying web processes.

Maintenance and recovery

Workers reclaim expired job leases and resume eligible persisted runs. Recovery respects unanswered tool calls, durable results, and an interrupted action whose outcome cannot safely be inferred.

Maintenance prunes expired shared rate-limit buckets and eligible visitor demos in bounded batches. Login and demo provisioning limits are shared across processes through PostgreSQL. Runtime and tool limits remain process-local, so they are not a fleet-wide quota mechanism.

Verification and secrets

Use Node.js 22 or newer and install the locked dependencies. Keep database credentials, integration encryption keys, and scheduler secrets in ignored local configuration or deployment secret variables. A build needs database configuration; disable worker startup during it.

Database integration tests require TEST_DATABASE_URL to explicitly select a separate disposable database. Apply migrations there first, then verify the task and recovery paths without using live data. Static checks, a successful build, and a reachable health endpoint answer different questions from a completed provider-backed task.

Example
npm ci
npm run typecheck
npm run lint
npm test
npm run test:integration
Living documentation · October 2026Product status & limits ↗