Deploying Programs
Deploy compiled sBPF programs with solana program deploy, manage buffer accounts, and control upgrade authority from the CLI.
Search across all documentation pages
Deploy compiled sBPF programs with solana program deploy, manage buffer accounts, and control upgrade authority from the CLI.
Quick-reference recipe card - copy-paste ready.
cargo build-sbf
solana program deploy target/deploy/my_program.so
solana program show <PROGRAM_ID>
solana program set-upgrade-authority <PROGRAM_ID> --new-upgrade-authority <AUTH>When to reach for this:
.so artifact.Anchor.toml / declare_id! after keygen.cd my_anchor_program
anchor build
# Artifact: target/deploy/my_anchor_program.so
solana config set --url devnet
solana airdrop 2
# Deploy with explicit program keypair (first deploy)
solana program deploy \
target/deploy/my_anchor_program.so \
--program-id target/deploy/my_anchor_program-keypair.json
PROGRAM_ID=$(solana-keygen pubkey target/deploy/my_anchor_program-keypair.json)
solana program show "$PROGRAM_ID"What this demonstrates:
cargo build-sbf / anchor build produces the .so consumed by deploy.program show confirms loader, programdata account, and authority.none (immutable)..so size.| Command | Purpose |
|---|---|
program deploy | Upload and activate (or upgrade) bytecode |
program write-buffer | Upload to buffer only |
program deploy --buffer | Finalize from existing buffer |
program close | Reclaim lamports from buffer (authority required) |
program set-upgrade-authority | Transfer or revoke upgrade rights |
# Show deploy cost estimate
solana program deploy my_program.so --dry-run 2>&1 | grep -i cost
# Immutable program: revoke upgrade authority
solana program set-upgrade-authority <PROGRAM_ID> --finaldeclare_id! does not match deployed keypair. Fix: align Anchor.toml and lib.rs with solana-keygen pubkey of deploy keypair..so wastes CU and rent. Fix: cargo build-sbf --release / anchor build.solana config get before every deploy.| Alternative | Use When | Don't Use When |
|---|---|---|
anchor deploy | Anchor workspace with scripted IDs | Raw native programs without Anchor |
solana program write-buffer + separate finalize | CI split upload and activation | Simple local dev loops |
solana-verify pipeline | Reproducible verified deploys | Quick throwaway devnet tests |
| Surfpool / local validator | Pre-mainnet simulation | Production release |
target/deploy/<crate_name>.so plus matching -keypair.json for the program ID.
Rent for programdata scales with bytecode size plus transaction fees. Run deploy on devnet and read the charged lamports in solana confirm -v.
Yes - submit a new .so to the same program ID while you hold upgrade authority.
Removes upgrade authority permanently - the program becomes immutable.
Temporary account holding uploaded ELF chunks before activation into programdata.
Possible with compatible signers, but most teams use a hot deploy key on devnet and multisig authority on mainnet.
Often a partial buffer or concurrent deploy. Close stale buffers or wait for in-flight transactions to clear.
solana program dump <ID> out.so and compare SHA256 with your build artifact, or use solana-verify for reproducible builds.
Yes - start solana-test-validator and deploy to http://127.0.0.1:8899.
The fee payer on the deploy transaction - usually your configured CLI keypair.
Stack versions: This page was written for Agave 4.1.1, Solana CLI 3.0.10, Anchor 0.32.1, anchor-lang 0.32.1, Rust 1.91.1, @solana/kit 7.0.0, Surfpool 0.12.0, and LiteSVM 0.6.x.
Reviewed by Chris St. John·Last updated Jul 16, 2026