# Namecheap shared hosting deployment preparation

Target URL: `https://dash.aiwebcommand.com`. WooCommerce and the Woo Bridge remain on `https://aiwebcommand.com`; the Site Agent belongs on customer WordPress sites.

## Hosting prerequisites

- Stellar Plus or Stellar Business with **Setup Node.js App**, **PostgreSQL Databases**, **Terminal/SSH**, and SSL available in cPanel. Use Node.js 22 or 24 (Next.js 16 requires Node.js 20.9+).
- Create the `dash` subdomain, point its DNS to this hosting account, and enable HTTPS before configuring the bridge.
- Create a PostgreSQL database and dedicated user in cPanel. Grant that user all permissions on the new database. Keep the database and the app under the same account unless a secure remote connection is deliberately configured.
- Record the actual cPanel database name/user; cPanel may prefix both. PostgreSQL 10 is listed by Namecheap for these plans. Plan an upgrade path because this is an old database version.

## App preparation

1. Use `.env.production.example` as a list of cPanel environment variables; never upload a populated `.env` or a local Docker database. Set `APP_URL=https://dash.aiwebcommand.com`. Generate independent, random `JWT_SECRET`, `CREDENTIAL_ENCRYPTION_KEY`, `WOO_SSO_SHARED_SECRET`, and `LICENSE_SYNC_SECRET`; do not copy development values. URL-encode special characters in the PostgreSQL password inside `DATABASE_URL`.
2. In cPanel's **Setup Node.js App**, choose Production mode, Node.js 22/24, the `dash` URL, and an application root outside `public_html`. The startup file for a standalone bundle is `server.js`.
3. Keep a private full-source checkout on the Linux host (outside `public_html`). From that checkout, run `npm ci`, `npm run prisma:generate`, and `npm run build`. Do not upload a Windows-built `.next/standalone` or Windows Prisma engine. If cPanel cannot complete the build within resource limits, build on a compatible Linux CI runner and upload the resulting bundle.
4. From the private checkout in cPanel Terminal, with the production `DATABASE_URL` available, run `npm run prisma:migrate` and `npm run seed:plans`. **Never run `seed:demo` in production.** The current catalog is Solo $15/$119, Growth $39/$299, Agency $89/$699 (monthly/annual); confirm these prices and the 7-day trial against the actual Woo products before seeding.
5. Copy `.next/standalone` contents to the cPanel application root; also copy `public` into that root and `.next/static` into `<app-root>/.next/static`. Keep the private source checkout, build tools, and database files outside the web-accessible document root.
6. Start/restart the Node.js app in cPanel. `https://dash.aiwebcommand.com/api/health` must return `{"status":"ok"}`. A 503 indicates database connectivity or migration failure. Then verify `/login` and a signed Woo sign-in using a test customer.
7. Confirm `/downloads/ai-web-command.zip` downloads the current plugin (0.14.19). Keep the ZIP in `public/downloads` for every deployment; the Sites screen links to it.
8. Schedule a cPanel cron job every 12 hours to POST `https://dash.aiwebcommand.com/api/internal/license-sync` with `Authorization: Bearer <LICENSE_SYNC_SECRET>`. Check the JSON `failed` and `sitesFailed` counts; investigate nonzero results. The plugin's entitlement expires after 48 hours without a successful sync.

## Woo Bridge settings

- Install Woo Bridge 0.1.2 on the **storefront only**. Set App URL to `https://dash.aiwebcommand.com` and use the exact same shared secret as `WOO_SSO_SHARED_SECRET`.
- Fill six distinct product/variation IDs: Solo monthly/annual, Growth monthly/annual, Agency monthly/annual. A mapped annual product must have a yearly Woo subscription period; monthly must have a monthly period.
- Set SaaS `WOO_SSO_START_URL=https://aiwebcommand.com/aiwebcommand-sign-in/`. Test both a monthly and an annual purchase, then check that the SaaS subscription interval and site limit match WooCommerce.

## Go-live gate

This is deployment preparation, **not production approval**. `PRE-LAUNCH-VALIDATION.md` still lists blocking work: live entitlement validation, hosted MCP, Woo retry/reconciliation, site lifecycle/revocation, SSRF protection, integration testing, and server-backed dashboard state. Do not invite paying customers based only on a successful deployment or health check.
