Production checklist

HTTPS, production compose overlay, env secrets, CORS, backups, and health checks before you point production SDKs at Epure.

Use this after a successful Quickstart on localhost. Production means a public HTTPS URL, the deploy/ compose overlay, and secrets that are not the documented laptop defaults.

Laptop compose is not the same file you publish. Installation separates local vs production paths.

Before you cut over traffic

CheckWhy
EPURE_PUBLIC_URL is https://…DSN and OAuth redirects must match the browser
EPURE_SESSION_SECURE=1Session cookie uses __Host-epure.sid behind TLS
Production env from deploy/env.production.example or ./configure --prodExample DB passwords are refused off localhost
Reverse proxy terminates TLSEpure listens HTTP inside the container
EPURE_CORS_ORIGINS lists your SPA originsBrowser SDK POSTs fail closed otherwise
Pin EPURE_IMAGE to a tagAvoid surprise latest pulls on restart
Postgres dump scheduleUpgrades assume you can restore
Per-project ingest cap and retentionProtect disk on shared VPS: Projects
DSN keys rotated after any leakPublic keys in frontend bundles are expected; rotate if scraped

Do not publish laptop compose

The root docker-compose.yml is for local proof. Production uses the overlay under deploy/ with stricter boot checks. See Configuration.

Health and smoke tests

curl -sS "https://your-host.example/health"

Expect {"status":"ok"}. Then:

  1. Login at /login (cookie must stick — no redirect loop).
  2. Copy production DSN → one captureException from staging.
  3. Confirm 202 and issue row with correct environment filter.
  4. Optional: webhook test fire → Webhooks.

Symptom table: Troubleshooting.

Backup and upgrade rhythm

CadenceAction
Before every image bumppg_dump off-box — steps in Upgrades
After deploy/health, login, one test event
MonthlyReview retention, caps, and webhook URLs

Operator env highlights

Full tables: Configuration.

VariableProduction note
DATABASE_URL / ingest / app URLsAll three required; migrations exit on missing migrate URL
EPURE_CORS_ORIGINSComma-separated origins, not * in prod
GOOGLE_CLIENT_IDOptional; set callback {EPURE_PUBLIC_URL}/api/v1/auth/google/callback
EPURE_WEBHOOK_ALLOW_PRIVATELeave off — hooks must be public HTTPS
Why does the app refuse to start with example passwords?

When EPURE_PUBLIC_URL is not localhost, boot rejects documented placeholder DB credentials. Switch to production env templates before pointing DNS.

Can I run Postgres on a managed service?

Yes, if all three connection URLs reach the same logical database with the expected roles. You still run the Epure binary container (or image) yourself. Connection strings: Configuration.

What about multi-region?

Epure Phase 1 is single-region Postgres. Run one instance per region if you need data residency; do not expect cross-region replication in the OSS binary.