# Convex Deploy Guard > Clasifica y anuncia el deployment de Convex objetivo antes de cualquier comando que lo afecte; exige consentimiento explícito y fresco para prod; modo de sesión solo lectura. Fuente: https://skillsagentes.com/skills/get-convex/agent-skills/convex-deploy-guard Markdown: https://skillsagentes.com/skills/get-convex/agent-skills/convex-deploy-guard.md Repositorio: https://github.com/get-convex/agent-skills Autor: get-convex Licencia: Apache-2.0 Actualizado: el mes pasado Coste de contexto: 39 tok instalada, 891 tok al activarse, 891 tok con todos los archivos del bundle Bundle: 1 archivo, 3 KB Permisos que pide: ninguno declarado ## Instalación Un skill son archivos markdown: los mismos archivos valen para cualquier agente y lo único que cambia es el directorio de destino, es decir la bandera `--agent`. Añade `-g` para instalarlo en todos los proyectos de la máquina. ```bash # Claude Code npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent claude-code # Cursor npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent cursor # Codex npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent codex # Gemini CLI npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent gemini # Windsurf npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent windsurf # Cline npx -y skills add get-convex/agent-skills --skill convex-deploy-guard --agent cline ``` ## Qué hace - Identifica y clasifica el deployment de Convex objetivo (local-anonymous, dev, preview, prod) antes de cualquier comando que lo afecte - Anuncia el objetivo en una línea antes de ejecutar el comando - Exige un 'sí' explícito y fresco por sesión antes de acciones sobre prod - Separa los flags de riesgo del MCP: lectura de PII prod vs mutaciones prod - Activa un modo de sesión de solo lectura absoluto cuando el usuario lo pide ## Cuándo usarla - Antes de ejecutar cualquier comando que afecte un deployment de Convex (deploy, run --prod, env set, import/export) - Al iniciar el MCP oficial de Convex con acceso a prod - Cuando un deploy 'no cambió nada' y hay que diagnosticar el deployment real - Cuando el usuario dice 'read-only' o 'no cambies nada' ## Qué la activa - "Haz deploy a producción de Convex" - "Corre npx convex run --prod para esta función" - "Quiero revisar los logs de prod sin cambiar nada" - "Configura el MCP de Convex apuntando a producción" ## Antes de instalar - Requiere revisar CONVEX_DEPLOYMENT en .env.local, convex.json o CONVEX_DEPLOY_KEY, o usar la herramienta status del MCP oficial de Convex. ## Archivos - SKILL.md — 3 KB ## SKILL.md Reproducido tal cual desde get-convex/agent-skills bajo Apache-2.0. Esta sección es el documento original y está en inglés. # Deployment target guard Deployments are not interchangeable, and most incidents start with a command aimed at the wrong one. Every Convex project has several (personal dev, preview, prod — often across multiple projects on one machine). This guard is the standing discipline: identify, announce, then act — and treat prod as consent-gated, per action, per session. ## Workflow 1. IDENTIFY before you act: read `CONVEX_DEPLOYMENT` in .env.local, `convex.json`, and whether `CONVEX_DEPLOY_KEY` is set; or call the official Convex MCP `status` tool. Classify the target: local-anonymous | dev | preview | prod. If two sources disagree, resolve before proceeding. 2. ANNOUNCE in one line before any deployment-affecting command: `target: dev (joyful-capybara-123, personal dev)`. Never run the command in the same breath as discovering the target — announce first. 3. PROD needs a FRESH explicit yes: before `npx convex deploy` (when it resolves to prod), `npx convex run --prod`, `env set` on prod, snapshot `import`/`export` on prod, or starting the MCP with prod access — state exactly what will change on which deployment and get an explicit yes in THIS session. A yes given earlier, or for a different target, does not carry. 4. MCP safety defaults: start the official MCP scoped non-prod (`--deployment dev`). The two prod flags are DIFFERENT risk levels — keep them split: a read-only prod audit (advisor/insights reading data/logs/insights) passes ONLY `--cautiously-allow-production-pii` (read tools); `--dangerously-enable-production-deployments` (which enables MUTATING prod tools) stays OFF unless the user explicitly asked to CHANGE prod this session. Never pair them by default — 'look at prod' must not silently grant 'mutate prod'. 5. READ-ONLY session mode: when the user says 'read-only' / 'don't change anything', honor it absolutely for the rest of the session — no deploy, no env set/remove, no mutations via `run`, no imports; start the MCP with `--disable-tools run,envSet,envRemove`. 6. Wrong-deployment diagnosis: when a deploy 'didn't change anything', do NOT re-deploy harder. Re-run step 1 — the deploy almost certainly landed on a different deployment than the one being observed. 7. Ambiguity = stop: if you cannot determine which deployment a command will hit, find out (status tool; compare `npx convex env list` fingerprints) — never guess. ## Rules - Classify and announce the target BEFORE every deployment-affecting command — identification and action are two separate steps. - Prod consent is per-action, per-target, per-session: state what changes where, get a fresh explicit yes. - Keep the two prod MCP flags split by risk: --cautiously-allow-production-pii (read-only) for an audit; --dangerously-enable-production-deployments (mutating) only when the user explicitly asks to change prod. Both are user-spoken-only; default every MCP start to a non-prod deployment selector. - Read-only mode, once requested, is absolute for the session — including 'harmless' mutations. - A deploy that seemed to do nothing means the WRONG deployment changed — diagnose the target, don't re-run. - This guard composes: ship, env, migrate, and seed run it as their step 0; it is not itself a deploy tool. ## Dónde encaja - Categoría: [DevOps e infraestructura](https://skillsagentes.com/categorias/devops-infraestructura.md) — Despliegues, contenedores, IaC y flujos de gestión de incidentes. - Creador: [get-convex](https://skillsagentes.com/creators/get-convex.md) — 33 skills en el directorio - [Todas las skills](https://skillsagentes.com/skills.md) - [Ranking de instalaciones](https://skillsagentes.com/ranking.md) ## Otras skills del mismo repositorio - [Convex Quickstart](https://skillsagentes.com/skills/get-convex/agent-skills/convex-quickstart.md): Levanta un template Next.js + Convex barebones a partir de una idea en una frase. - [Convex Design](https://skillsagentes.com/skills/get-convex/agent-skills/convex-design.md): Diseña y construye backends reactivos y type-safe de nivel producción en Convex: schema, queries/mutations/actions, índices, auth, storage, scheduling, multiplayer en tiempo real y workflows LLM/agentes. - [Convex Authz](https://skillsagentes.com/skills/get-convex/agent-skills/convex-authz.md): Audita y refuerza la autorización de una app Convex: impersonación por identity-from-arg, checks de ownership por documento faltantes, queries públicas que filtran datos por un id del cliente y escrituras en un contenedor ajeno. - [Convex Expert](https://skillsagentes.com/skills/get-convex/agent-skills/convex-expert.md): Especialista en el backend de Convex: código dentro de convex/ (funciones, schemas, índices, queries, mutations, actions, endpoints HTTP, cron jobs, storage, auth y componentes). - [Convex Agent](https://skillsagentes.com/skills/get-convex/agent-skills/convex-agent.md): Añade un backend de agente de IA / RAG (@convex-dev/agent) a la app Convex. --- Skills Agentes · [Índice de páginas en markdown](https://skillsagentes.com/sitemap.md) · [Inicio](https://skillsagentes.com/index.md)