Neon Law
  • Services
  • Book Consultation opens in a new tab
  • Sign in

← Operating Neon Law Navigator

Environment Matrix

Chapter 4 of 7 · Section 19 of 45

Sections

1. Intro

  • 1. Deploy your own
  • 2. Agenda

2. Prepare Google Cloud

  • 3. Bring your own project
  • 4. Dry-run first
  • 5. Private assets and domain restricted sharing
  • 6. The Navigator deployment matrix
  • 7. The `/app` mount and HTTP route ownership
  • 8. `neon` — the whole brand seam
  • 9. Live rollout checkpoint
  • 10. Set one site to one version

3. Provision the Infrastructure

  • 11. The APIs that light up
  • 12. Network and storage buckets
  • 13. How a Project portal reaches a client
  • 14. A document's bytes and authorization are separate
  • 15. A private image registry
  • 16. The cluster comes up
  • 17. What setup owns — and what follows it

4. Environment Matrix

  • 18. Three operating modes, two deployment profiles
  • 19. The deployment that says its matters are sample
  • 20. Configuration precedence: the first source wins
  • 21. Local dev controls: inputs read by `navigator dev`
  • 22. Local runtime: what `.devx/env` generates
  • 23. The store: SurrealDB
  • 24. Where SurrealDB authorization lives
  • 25. Deployed runtime: core web and worker wiring
  • 26. Deployed runtime: identity and access
  • 27. Deployed runtime: email, signatures, and billing
  • 28. Deployed runtime: repositories, content, AI, and scheduled work
  • 29. Provision and ship: variables read by the operator CLI
  • 30. Ancillary operations and opt-in test controls
  • 31. When sample data appears

5. Configure the Trust Boundaries

  • 32. Secrets: the invariants that gate the boot
  • 33. Sign-in: bring an OIDC provider; passwords live there, not here
  • 34. Role rings: who can do what
  • 35. Provider signup and parity across the deployments
  • 36. The external surface — every third party, in one place
  • 37. The two service deployments
  • 38. Security architecture

6. Ship the Instance

  • 39. Ship and verify
  • 40. Post the verified handoff in `#navigator`
  • 41. Point your domain at the instance (optional)
  • 42. Drive it from the CLI
  • 43. Make it yours — white-label under your own brand
  • 44. This is how we set up our production deployment

7. Wrap Up

  • 45. Canonical references

The deployment that says its matters are sample

NAVIGATOR_SIMULATED_MATTERS is the second selector, and it answers a different question from the first. The profile above decides which runtime wiring a boot gets; this decides whether the matters in front of a visitor are invented.

Left unset or empty it follows the profile: a dev boot carries sample matters because that is all a dev boot has, and a production boot does not, because production is where the real files are. Exactly true or false overrides that in both directions, and every other value — TRUE, 1, yes, a case or whitespace variant — is rejected rather than resolved to the permissive answer. That exactness is the point: a typo that quietly read as true would seed invented clients into a database of real ones.

The override that matters is true under a production profile, which is exactly what neon-law-stg is. Both of its selectors are production on purpose, so nothing in the running process can tell it apart from the row holding real client files. It therefore says so itself, in deployments/neon-law-stg/config.toml:


NAVIGATOR_SIMULATED_MATTERS = "true"

Two things follow from that value. store::seed applies the sample-matter fixture, so the row carries sample-litigation, sample-transactional, and sample-estate rather than an empty portfolio. And every page publishes a site-wide banner saying the matters are sample — which is why staging.neonlaw.com is a link worth handing to somebody, because a demo matter cannot be mistaken for a client's file.

It is a coordinate, not a credential, so it lives in config.toml beside the buckets and hostnames rather than in that deployment's secrets.enc.yaml. Adding it needs no SOPS re-encryption on either row.

neon-law-prod states "false" for documentation rather than for behaviour. The code already reads a missing value as false under a production profile, and ops ship renders false into the web env when a deployment's config omits the key, so the substitution is deliberately optional: a config that never mentions it still renders and still ships. A key that could halt a production rollout by being deleted would be a worse failure than the one it guards against.

Presenter notes

Two selectors, two questions. Ask the room which one decides whether a visitor sees invented clients — the answer is not the one whose name contains "environment". Then point out that staging's runtime profile is production, and let the implication land: nothing in the process can tell staging from production, so staging has to say so itself. That is why there is a second selector at all rather than a third value on the first one.

The banner is the part worth dwelling on. It is not a developer convenience — it is what makes staging.neonlaw.com a link you can hand to somebody without them mistaking a demo for a client's file.

View all slidesOpen display
← PreviousNext →
Neon Law
  • X opens in a new tab
  • LinkedIn opens in a new tab
  • YouTube opens in a new tab
  • API opens in a new tab
  • Blog opens in a new tab
  • Contact
  • Glossary opens in a new tab
  • Navigator opens in a new tab
  • Notations opens in a new tab
  • Presentations opens in a new tab
  • Privacy opens in a new tab
  • Team opens in a new tab
  • Terms opens in a new tab
  • Testimonials
  • UX opens in a new tab
  • contact@neonlaw.com
  • +1 510 800 2080
  • Nevada
    5150 Mae Anne AveSte 405-9002Reno, NV 89523
  • New York
    12 E 49th St18th FloorNew York, NY 10017
  • Justice Technology AssociationMission-Aligned Partner opens in a new tab

Attorney advertisement. Nothing here is legal advice without a signed retainer for an active project. Past results do not guarantee future outcomes.

© 2026 Shook Law PLLC

NEON LAW® is a registered trademark of Shook Law PLLC, U.S. Reg. No. 6,325,650 opens in a new tab

Powered by Neon Law Navigator 26.10.4

Everyone deserves to be seen. Made with ❤️ in 🗽.