all they would have to do is to update the published tarball every time they deploy a new version of code to production.
there is no need to do anything like a tar at the time of the request. for anything other than an interpreted language, a tar wouldn't guarantee that you got the right version anyway.