Architecture practice / deployment boundaries
Choose the lifetime.
Then choose the cloud.
A request, a job, an entity and a batch run have different failure modes. Make that decision before combining frameworks or opening a production tenant.
Vercel
A bounded front door
Source template; tenant deployment must be verified
Choose this sidecar when a portal needs a bounded API to admit work and return job status from a separate worker.
Portal → authenticated API → worker job → status
Keep durable jobs out of the request. Limit input, execution time, model spend and tool authority.
Evidence before production
Denied caller, oversized input, upstream timeout, failed model call, rollback and cost per successful request.
Railway
Work that outlives a request
Source template; durability requires an implementation
Choose a container worker when an agent needs its own process, dependencies and restart policy.
Portal → admitted job → worker → result; workflow and traces stay separate
The starter is an in-memory teaching fixture. Add a durable queue and store before promising recovery.
Evidence before production
Restart recovery, duplicate delivery, cancellation, terminal model failure, tenant isolation and trace redaction.
Cloudflare
One durable identity
Reference design; no Academy deployment receipt
Choose an entity boundary when a session or workspace needs coordinated state and connections.
Worker → named Durable Object → state and alarms
Map identity to a tenant-scoped entity. Keep retrieval authorization and irreversible tools outside model control.
Evidence before production
Cross-tenant lookup, reconnect, concurrent writes, alarm replay, storage recovery and revocation.
Google Cloud
A finite evaluation run
Reference design; no Academy deployment receipt
Choose a Cloud Run job for bounded container work that completes and exits; use a service for HTTP.
Approved run → Cloud Run job → evidence store → independent review
One service account per authority class. Bound retries, execution time, concurrency and data access.
Evidence before production
Partial task failure, retry safety, identity isolation, immutable fixture inputs and a failing exit code.
Compose after proving the boundary
A runtime is one part of the system.
Hermes or OpenClaw can be the agent runtime. n8n can orchestrate admitted workflows. Langfuse can record model traces and evaluation results. Keep credentials, job state, customer data and release authority explicit; adding a tool does not make the starter durable or multi-tenant.
A customer-owned deployment needs a version pin, an operating owner, a tested recovery path and a support boundary. These are source templates and reference designs, with no claim of a verified customer deployment.