# Release, cache, and rollback contract Each deployment is an immutable `releases//` artifact set. The provider adapter must upload assets, release manifest, runtime config, and verify asset reachability before atomically switching the active HTML pointer. The post-switch boot, route, API, telemetry, and reload-loop smoke checks close the deployment. Rollback selects a prior release tuple, confirms its assets and runtime/API compatibility, atomically switches the complete set, performs the provider cache action, and repeats the smoke checks. Rebuilding an old commit, replacing HTML alone, or declaring recovery from cache-purge completion is prohibited. Recovery is established by old/new reachability probes. The provider-independent cache defaults are: - hashed assets: `public, max-age=31536000, immutable` - HTML: `no-cache` - runtime config and release manifest: `no-store` - public source maps: disabled - service worker/offline cache: disabled HTML, JSON config/manifest, and hashed JavaScript MIME types are also compared to the declared allowlist; a cache-correct response with a mismatched `Content-Type` still fails the hosting gate. `corepack pnpm verify:hosting-headers` uses a deterministic fixture locally. Set `HOSTING_BASE_URL` to probe deployed responses; production promotion requires the artifact to report `mode: "live"`. The live target must be its canonical, non-loopback HTTPS root URL. Each required surface must return HTTP 200 without leaving that origin before its cache, content-type, and security headers can count as deployment evidence.