The runtime pass we actually run
Clone the Repl, then sign a process you control
Harden when the Repl’s screens and navigation still match the product operators will pay for. Rewrite only the seams glued to Replit — .replit/Nix, Secrets, Auth, Database, Object Storage, and Deployments.
01
Prove a clean boot from a checkout that is not the Repl
Another engineer starts the process on your infrastructure. If the only runnable surface is Replit Deployments or Always-on, you still have a demo.
02
Put identity and secrets off the Replit workspace
Sessions live on your IdP or a hardened provider you control. Replit Auth is not that identity. Secrets never ship only in the Repl pane.
03
Give data and deploys an owner outside Replit Database
Migrations, backups, and a named data owner. CI deploys the checkout with environment injection and a rollback that does not reopen Always-on.
04
Carry public URLs through the Repl hostname cutover
Canonical tags, redirects, and sitemap continuity survive leaving replit.app. “It stays up on Always-on” is not that continuity.