Production Checklist
Work through this before real users or real data reach a deployment. One line per item, each
linked to the page that explains it. With APP_ENV unset or production, the engine checks the
items marked "refused" itself and will not start until they pass.
Secrets
Section titled “Secrets”-
JWT_SECRETis a random value of at least 16 characters (refused). Configuration -
ENCRYPTION_KEYis a different random value of at least 32 characters, stored durably (refused). Configuration -
LYEVE_AUDIT_HMAC_KEYis exactly 64 hex characters (refused). Configuration -
ADMIN_CONSOLE_KEYholds the same value on the engine and the admin console. Configuration -
LYEVE_SETUP_TOKENis set when more than one replica can answer first-run setup. Configuration - Secrets live in a secret store or an uncommitted
.envfile. Secure your instance
Tokens and cookies
Section titled “Tokens and cookies”- The signing key at
JWT_KEY_PATHis on a volume, or the same file on every replica. Kubernetes - The signing key file is readable by its owner only (refused). Configuration
-
JWT_EXPIRY_SECSis a deliberate choice of3600or less (refused above). Secure your instance -
SECURE_COOKIE=true, and the deployment is served over HTTPS end to end (refused). Docker images -
PASSWORD_HASH_ALGOand the password rules are chosen on purpose. Secure your instance
Network and proxies
Section titled “Network and proxies”-
LYEVE_CONSOLE_URLis the admin console's publichttpsURL. Configuration -
LYEVE_BASE_URLis the engine's public URL. Configuration -
CORE_INTERNAL_URLandCORE_API_INTERNAL_URLare set on the admin console. Docker images -
CORS_ORIGINSlists the exact origins of your browser apps (*refused). Secure your instance -
TRUSTED_PROXIESnames your proxy or load balancer CIDRs. Secure your instance -
RATE_LIMIT_RPSis set (refused unset). Secure your instance - Your proxy sets
X-Forwarded-Proto: https, on internal plain-HTTP hops too. Docker images - The Admin API (port 3001) has no public host unless a tool outside your network needs it. Docker images
-
super_adminis held by as few accounts as possible. Secure your instance
Database
Section titled “Database”- The database user is not
postgres,rootorsa(refused). Supported databases -
DATABASE_URLusessslmode=requireor stronger outside a private network. Configuration -
DATABASE_MAX_CONNECTIONStimes the replicas stays under the database's limit. Configuration - The database is backed up, and one restore has been tested. Backup and restore
- Media is backed up with the database, or stored in a bucket with its own retention. Object storage
More than one replica
Section titled “More than one replica”- Every replica uses the same signing key file. Kubernetes
-
CACHE_DRIVER=redisandREDIS_URLare set, and the boot log'srefresh token storeline says sessions are shared. Scaling -
RATE_LIMIT_BACKEND=redisis set. Rate limiting - Media goes to an S3-compatible bucket. Object storage
- Outbound email is configured if users rely on invitations, password resets or notifications. Email
Features and license
Section titled “Features and license”-
LYEVE_LICENSE_KEYis set if you use paid features. Licensing and tiers -
LYEVE_PLUGINSis empty or names exactly the features you run. Licensing and tiers - Plugins in the admin console, or
GET /api/admin/plugins/status, shows the features you expect. Licensing and tiers
Monitoring
Section titled “Monitoring”- Readiness probes and uptime checks use
/readyz, liveness probes/healthz. Health endpoints - Metrics are scraped from
GET /api/admin/metricswithMETRICS_TOKEN. Configuration - Logs go somewhere durable, not only to container output. Logs
Free hosting
Section titled “Free hosting”- If any part runs on a free plan, its limits are acceptable. Free-tier stack