DEV Community

Mubarak Yakubu
Mubarak Yakubu

Posted on

My Solana Program Launch Checklist

Just shipped my first Solana program to mainnet. Took notes the whole way.

But I know how this goes. Three weeks from now, I'll stare at a terminal and forget half of it.

Here's the checklist I wish I had.

Phase 1: Pre-flight, on devnet

Catch problems while they're cheap.

  • Every test passes against your final build.
  • You've run the program end-to-end on devnet exactly as it will run on mainnet.
  • You produced a verifiable build with anchor build --verifiable.
  • Your deploy wallet holds enough SOL for the rent-exempt minimum plus fees.

Watch out: Once you have a verifiable build, don't overwrite it with a plain anchor build or cargo build-sbf. Those produce a different hash and break verification later.

Phase 2: The deploy itself

This is the irreversible phase. Slow down here.

  • Switch your CLI to mainnet-beta with solana config set --url mainnet-beta.
  • Confirm with solana config get that you're pointing at the right cluster.
  • Run your deploy command.
  • If the last attempt struggled to land, add a priority fee with --with-compute-unit-price and route through a reliable RPC with --use-rpc.

Watch out: A deploy is not atomic. If it's interrupted, you may be left with a buffer account holding your SOL. Check for stranded buffers and recover:

solana program show --buffers     # list stranded buffers
solana program deploy <SO_PATH> --buffer <BUFFER_KEYPAIR> #resume a stalled deploy
solana program close <BUFFER_ADDRESS  #close and reclaim the rent

Enter fullscreen mode Exit fullscreen mode

Phase 3: Authority and verification

Right after deploy. Confirm what landed and decide who controls it.

  • Run solana program show <PROGRAM_ID> and read back the upgrade authority. Is it what you intended?
  • Decide who holds the upgrade authority: a single keypair you control, a Squads multisig, or --final for permanent immutability. Write down which one and why.
  • Publish your IDL on-chain with anchor idl init.
  • Regenerate your Codama client from the published IDL.

Watch out: Skipping the IDL publish causes build verification to fail. Do it in the same session as the deploy.

Phase 4: Frontend and going live

The last mile. Make sure a real human can use it.

  • Point your React frontend at the mainnet program ID.
  • Confirm the Wallet Standard connection surfaces real wallets against mainnet.
  • Confirm every error your frontend can throw still produces a calm, legible message now that the stakes are real: rejected approval, insufficient funds, expired blockhash.
  • Announce the launch.
  • Write down where users report problems.

What surprised me

One thing surprised me most. The deploy itself was the easy part. The hard part was deciding who holds the upgrade authority and what to do with it.

A single key on your laptop can replace your program. That's the biggest risk in the whole launch.

A multisig distributes the key. But the real protection is a timelock plus a verifiable build. The timelock gives users time to see an upgrade coming and exit if they don't like it. The verifiable build lets anyone confirm the on-chain bytecode matches your source.

Signer count is secondary. Transparency and delay are what actually protect users.

Resources

Top comments (0)