DeployLint
CI/CD guides

Monorepo CI/CD: separate install roots from application roots

A monorepo can contain a website, an API and shared packages. Running every command from the same directory can produce missing dependencies, incorrect builds or deployment to the wrong project.

Map the two kinds of directory

The install root owns the lockfile and dependency workspace. The application root owns a deployable application’s scripts and configuration. In a pnpm workspace, dependencies may install at the repository root while a website’s checks run in apps/web. Two independent applications may instead each own a lockfile and need separate installs.

repository/
  package.json
  pnpm-lock.yaml
  pnpm-workspace.yaml
  apps/
    web/package.json
    api/package.json

For this example, confirm that the workspace manifest includes both applications. A directory name alone does not establish workspace membership.

Use the correct package-manager mode

npm, Bun, pnpm and Yarn have different install commands. Yarn Classic and modern Yarn also use different immutable-install flags. Keep the exact manager version in the manifest where supported, commit the matching lockfile and run checks from the intended application directory.

Consult the pnpm workspace documentation and Yarn workspace documentation for the model used by your repository.

Choose a destination per application

A website and API need not share a host. Confirm the working directory and host configuration for each application, and scope credentials to the corresponding deployment job. Leave libraries and applications without a supported deployment configuration in checks-only mode.

Do not skip shared dependency changes

Path filtering can reduce CI cost, but a change to a root lockfile or shared package may affect several applications. Start with complete checks. Introduce selective execution only when you have a verified dependency graph and a clear fallback for changes you cannot classify.

How DeployLint helps

DeployLint separates application and install roots, previews per-application checks, and lets you confirm supported hosts. Generation currently bounds the inventory to 20 applications and rejects ambiguous or incomplete evidence. It does not assume every detected provider can produce a deployable workflow.

Preview your monorepo pipeline

Start with the GitHub Actions safety checklist before connecting production credentials.