Production checklist
What to verify before going live.
Verify these items before pointing production traffic at Caedral.
Infrastructure
- Docker Compose stack healthy: site :5000, api-gateway :5001, Postgres, Redis, model-inference
- Single root .env with DATABASE_URL, Stripe LIVE keys, and required gateway secrets
- Reverse proxy: caedral.com → :5000, api.caedral.com → :5001
- Database migrations applied (docker compose exec site npx drizzle-kit migrate)
Security & keys
- API keys stored in secrets manager or env vars — never client-side
- Separate keys for staging and production
- BETTER_AUTH_SECRET and Stripe webhook secret configured
- OAuth redirect URLs set to production domains
Billing
- Stripe live keys configured (subscription Checkout and Customer Portal)
- Webhook endpoint https://caedral.com/api/webhooks/stripe verified in Stripe Dashboard
- Test subscription checkout in Stripe test mode before switching live
Observability
- Handle 402 insufficient_balance and 429 rate_limit_exceeded in client retry logic
- Monitor /v1/usage or dashboard billing for low pool quota (HTTP 402)
- Run integration test suite (see TEST_REPORT.md)