Production checklist
HTTPS, production compose overlay, env secrets, CORS, backups, and health checks before you point production SDKs at Epure.
Use this after a successful Quickstart on localhost. Production means a public HTTPS URL, the deploy/ compose overlay, and secrets that are not the documented laptop defaults.
Laptop compose is not the same file you publish. Installation separates local vs production paths.
Before you cut over traffic
| Check | Why |
|---|---|
EPURE_PUBLIC_URL is https://… | DSN and OAuth redirects must match the browser |
EPURE_SESSION_SECURE=1 | Session cookie uses __Host-epure.sid behind TLS |
Production env from deploy/env.production.example or ./configure --prod | Example DB passwords are refused off localhost |
| Reverse proxy terminates TLS | Epure listens HTTP inside the container |
EPURE_CORS_ORIGINS lists your SPA origins | Browser SDK POSTs fail closed otherwise |
Pin EPURE_IMAGE to a tag | Avoid surprise latest pulls on restart |
| Postgres dump schedule | Upgrades assume you can restore |
| Per-project ingest cap and retention | Protect disk on shared VPS: Projects |
| DSN keys rotated after any leak | Public keys in frontend bundles are expected; rotate if scraped |
Do not publish laptop compose
The root docker-compose.yml is for local proof. Production uses the overlay under deploy/ with stricter boot checks. See Configuration.
Health and smoke tests
curl -sS "https://your-host.example/health"Expect {"status":"ok"}. Then:
- Login at
/login(cookie must stick — no redirect loop). - Copy production DSN → one
captureExceptionfrom staging. - Confirm 202 and issue row with correct environment filter.
- Optional: webhook test fire → Webhooks.
Symptom table: Troubleshooting.
Backup and upgrade rhythm
| Cadence | Action |
|---|---|
| Before every image bump | pg_dump off-box — steps in Upgrades |
| After deploy | /health, login, one test event |
| Monthly | Review retention, caps, and webhook URLs |
Operator env highlights
Full tables: Configuration.
| Variable | Production note |
|---|---|
DATABASE_URL / ingest / app URLs | All three required; migrations exit on missing migrate URL |
EPURE_CORS_ORIGINS | Comma-separated origins, not * in prod |
GOOGLE_CLIENT_ID | Optional; set callback {EPURE_PUBLIC_URL}/api/v1/auth/google/callback |
EPURE_WEBHOOK_ALLOW_PRIVATE | Leave off — hooks must be public HTTPS |
FAQ
Why does the app refuse to start with example passwords?
When EPURE_PUBLIC_URL is not localhost, boot rejects documented placeholder DB credentials. Switch to production env templates before pointing DNS.
Can I run Postgres on a managed service?
Yes, if all three connection URLs reach the same logical database with the expected roles. You still run the Epure binary container (or image) yourself. Connection strings: Configuration.
What about multi-region?
Epure Phase 1 is single-region Postgres. Run one instance per region if you need data residency; do not expect cross-region replication in the OSS binary.