Audit the Vercel deployment configuration for this Vite + Express SPA project. Check for correctness, security, and optimization opportunities.
Target: $ARGUMENTS (default: full audit)
Pre-flight
- Read
vercel.json,package.json,api/index.ts, and.env.local(if exists). - Read
server/index.tsto understand the Express handler shape. - Glob for any additional
api/**/*.tsserverless entry points.
Audit Checklist
1. SCHEMA & STRUCTURE
-
$schemaproperty present ("https://openapi.vercel.sh/vercel.json") for IDE autocomplete - No deprecated properties (
routes→ userewrites/redirects/headersinstead) - No conflicting properties (e.g.,
routesmixed withrewrites) -
frameworkset to"vite"(matches actual build tool) -
buildCommandmatchespackage.jsonbuild script or is omitted to use default -
outputDirectorymatches Vitebuild.outDir(default:"dist")
2. SERVERLESS FUNCTIONS
-
functionsconfig exists for eachapi/*.tsentry point -
includeFilespatterns are correct and complete — all runtime dependencies included -
includeFilesuses glob patterns (e.g.,"server/**") not comma-separated strings unless properly formatted -
memoryconfigured appropriately (default 1024 MB; increase to 3008 for heavy AI/LLM work) -
maxDurationset if functions do long-running work (AI calls, DB queries); Pro plan max: 300s - No unnecessary files in
includeFiles(bloats cold start) -
runtimespecified if non-default Node.js version needed - Functions entry point (
api/index.ts) exports a proper handler (req, res) or Web API Response
3. REWRITES & ROUTING
- SPA fallback rewrite exists: all non-API routes →
/index.html - API rewrite routes to correct serverless function:
/api/(.*)→/api/index.ts - SPA rewrite uses negative lookahead to exclude
/api/paths:/((?!api/).*) - Rewrite order is correct (specific routes before catch-all)
- No rewrite loops or conflicts between rules
- If
cleanUrls: true, rewrites don't include.htmlextensions
4. HEADERS (Security & Caching)
- Security headers configured (recommended):
X-Content-Type-Options: nosniffX-Frame-Options: DENYorSAMEORIGINX-XSS-Protection: 1; mode=blockReferrer-Policy: strict-origin-when-cross-originPermissions-Policyrestricting unused APIs
- Static asset caching:
Cache-Control: public, max-age=31536000, immutablefor hashed assets (/assets/*) - HTML caching:
Cache-Control: no-cacheforindex.html(prevents stale SPA shells) - API caching: appropriate
Cache-Controlors-maxagefor cacheable endpoints - CORS headers if API is consumed cross-origin
5. ENVIRONMENT VARIABLES
- No secrets in
NEXT_PUBLIC_*orVITE_*prefixed variables (these are client-exposed) -
NEXT_PUBLIC_OPENAI_API_KEYis a security risk — OpenAI keys must NEVER be client-exposed - Database URLs (
DATABASE_URL,DIRECT_DATABASE_URL) are server-only (noVITE_/NEXT_PUBLIC_prefix) - Service role keys (
SUPABASE_SERVICE_ROLE_KEY) are server-only - Stripe secret keys (
STRIPE_SECRET_KEY) are server-only -
SENTRY_AUTH_TOKENis server-only (build-time only, not runtime) - All required env vars for serverless functions are available in Vercel project settings
- No placeholder/dummy values for webhook secrets (e.g.,
whsec_12345)
6. REGIONS & PERFORMANCE
-
regionsconfigured to match data source location (Supabaseus-west-2→pdx1orsfo1) - Or using Fluid compute (
"fluid": true) for automatic scaling (default for new projects since April 2025) -
functionFailoverRegionsset for high-availability if needed - Consider
trailingSlash: falsefor clean URLs
7. BUILD OPTIMIZATION
-
buildCommandruns type checking before build if desired (e.g.,npm run build:check && npm run build) -
installCommandnot set unless specific package manager behavior needed -
ignoreCommandconsidered for skipping unnecessary builds (e.g., docs-only changes) - Source maps configured for error tracking (Sentry) but not publicly exposed
8. IMAGES (if applicable)
-
imagesconfig set if using Vercel Image Optimization - Allowed domains listed for remote images
- Format preferences set (
avif,webp)
Output Format
## Vercel Audit Report
### Score: X/8 dimensions passing
### Critical Issues
1. [DIMENSION] — [severity: CRITICAL/HIGH/MEDIUM/LOW] — description
Current: `current value`
Fix: specific fix with code
### Warnings
1. [DIMENSION] — description
Recommendation: what to change
### Optimizations
1. [DIMENSION] — description
Benefit: expected improvement
### Passing
- [DIMENSION] — what's configured correctly
### Recommended vercel.json
(Only if changes needed — show the complete corrected file)