Just shipped my first Solana program to mainnet. Took notes the whole way.
But I know how this goes. Three weeks from now, I'll stare at a terminal and forget half of it.
Here's the checklist I wish I had.
Phase 1: Pre-flight, on devnet
Catch problems while they're cheap.
- Every test passes against your final build.
- You've run the program end-to-end on devnet exactly as it will run on mainnet.
- You produced a verifiable build with
anchor build --verifiable. - Your deploy wallet holds enough SOL for the rent-exempt minimum plus fees.
Watch out: Once you have a verifiable build, don't overwrite it with a plain anchor build or cargo build-sbf. Those produce a different hash and break verification later.
Phase 2: The deploy itself
This is the irreversible phase. Slow down here.
- Switch your CLI to mainnet-beta with
solana config set --url mainnet-beta. - Confirm with
solana config getthat you're pointing at the right cluster. - Run your deploy command.
- If the last attempt struggled to land, add a priority fee with
--with-compute-unit-priceand route through a reliable RPC with--use-rpc.
Watch out: A deploy is not atomic. If it's interrupted, you may be left with a buffer account holding your SOL. Check for stranded buffers and recover:
solana program show --buffers # list stranded buffers
solana program deploy <SO_PATH> --buffer <BUFFER_KEYPAIR> #resume a stalled deploy
solana program close <BUFFER_ADDRESS #close and reclaim the rent
Phase 3: Authority and verification
Right after deploy. Confirm what landed and decide who controls it.
- Run
solana program show <PROGRAM_ID>and read back the upgrade authority. Is it what you intended? - Decide who holds the upgrade authority: a single keypair you control, a Squads multisig, or
--finalfor permanent immutability. Write down which one and why. - Publish your IDL on-chain with
anchor idl init. - Regenerate your Codama client from the published IDL.
Watch out: Skipping the IDL publish causes build verification to fail. Do it in the same session as the deploy.
Phase 4: Frontend and going live
The last mile. Make sure a real human can use it.
- Point your React frontend at the mainnet program ID.
- Confirm the Wallet Standard connection surfaces real wallets against mainnet.
- Confirm every error your frontend can throw still produces a calm, legible message now that the stakes are real: rejected approval, insufficient funds, expired blockhash.
- Announce the launch.
- Write down where users report problems.
What surprised me
One thing surprised me most. The deploy itself was the easy part. The hard part was deciding who holds the upgrade authority and what to do with it.
A single key on your laptop can replace your program. That's the biggest risk in the whole launch.
A multisig distributes the key. But the real protection is a timelock plus a verifiable build. The timelock gives users time to see an upgrade coming and exit if they don't like it. The verifiable build lets anyone confirm the on-chain bytecode matches your source.
Signer count is secondary. Transparency and delay are what actually protect users.
Resources
- Deploying Programs — the official guide to deployment, buffer accounts, and recovery
- Anchor Verifiable Builds — how to produce a build whose on-chain bytecode matches your source
- Managing Program Upgrades with Multisig — Squads on why and how to secure upgrade authority
- Solana Production Readiness — RPC reliability and production considerations
Top comments (0)