Skip to content

Production Checklist

Work through this before real users or real data reach a deployment. One line per item, each linked to the page that explains it. With APP_ENV unset or production, the engine checks the items marked "refused" itself and will not start until they pass.

  • JWT_SECRET is a random value of at least 16 characters (refused). Configuration
  • ENCRYPTION_KEY is a different random value of at least 32 characters, stored durably (refused). Configuration
  • LYEVE_AUDIT_HMAC_KEY is exactly 64 hex characters (refused). Configuration
  • ADMIN_CONSOLE_KEY holds the same value on the engine and the admin console. Configuration
  • LYEVE_SETUP_TOKEN is set when more than one replica can answer first-run setup. Configuration
  • Secrets live in a secret store or an uncommitted .env file. Secure your instance
  • The signing key at JWT_KEY_PATH is on a volume, or the same file on every replica. Kubernetes
  • The signing key file is readable by its owner only (refused). Configuration
  • JWT_EXPIRY_SECS is a deliberate choice of 3600 or less (refused above). Secure your instance
  • SECURE_COOKIE=true, and the deployment is served over HTTPS end to end (refused). Docker images
  • PASSWORD_HASH_ALGO and the password rules are chosen on purpose. Secure your instance
  • The database user is not postgres, root or sa (refused). Supported databases
  • DATABASE_URL uses sslmode=require or stronger outside a private network. Configuration
  • DATABASE_MAX_CONNECTIONS times the replicas stays under the database's limit. Configuration
  • The database is backed up, and one restore has been tested. Backup and restore
  • Media is backed up with the database, or stored in a bucket with its own retention. Object storage
  • Every replica uses the same signing key file. Kubernetes
  • CACHE_DRIVER=redis and REDIS_URL are set, and the boot log's refresh token store line says sessions are shared. Scaling
  • RATE_LIMIT_BACKEND=redis is set. Rate limiting
  • Media goes to an S3-compatible bucket. Object storage
  • Outbound email is configured if users rely on invitations, password resets or notifications. Email
  • Readiness probes and uptime checks use /readyz, liveness probes /healthz. Health endpoints
  • Metrics are scraped from GET /api/admin/metrics with METRICS_TOKEN. Configuration
  • Logs go somewhere durable, not only to container output. Logs
  • If any part runs on a free plan, its limits are acceptable. Free-tier stack