Production
Hardening, backups, monitoring, and upgrades for a self-hosted instance
Before real traffic reaches the instance, work through the two go-live pages below, then keep the rest as runbooks. These pages assume a working Compose install from Installation.
Warning
The default stack is not safe to expose. It boots with development secrets that work out of the box, no TLS, and compose-managed data stores. Nothing fails or warns you if you leave it that way.
Before you go live
Checklist
The go-live pass: secrets, prod runtime flags, and managed data stores
Security & TLS
Terminate TLS in front of the stack and lock down secrets
Operating it
Was this page helpful?
Questions & Discussion