Operations
Routine checks
Run from the server/ directory on the deployment host:
docker compose ps
docker stats --no-stream
curl -fsS https://<sync-domain>/health
curl -fsS https://<sync-domain>/readyz
All three containers (postgres, api, caddy) should be running and healthy.
Logs and restart
docker compose logs --tail=200 api
docker compose logs --tail=200 postgres
docker compose logs --tail=200 caddy
docker compose restart api
Prefer restarting only the affected component. Do not print .env or Authorization headers into logs or support conversations.
Deployment
cp .env.example .env
chmod 600 .env
# Fill secrets locally.
docker compose config
docker compose build api
docker compose up -d
curl -fsS https://<sync-domain>/readyz
Back up changed files before deployment and retain a documented rollback point.
Database backup and restore drill
set -a
. ./.env
set +a
./scripts/backup.sh
./scripts/restore-check.sh /path/to/memory_sync_TIMESTAMP.dump
Copy encrypted backups to a separate private storage account. A VM disk snapshot does not replace a PostgreSQL logical backup.
Network boundary
- Expose HTTPS only.
- Restrict SSH and any hosting control panel to trusted sources.
- Never publish PostgreSQL port 5432.
- The local dashboard must remain bound to
127.0.0.1and must not be reverse-proxied.
Release acceptance
- Tests and static checks pass from the actual source tree.
- No credentials or user memories are staged in Git.
- Health/readiness endpoints return 200.
- Website assets and client download return 200 and match the published SHA-256.
- A rollback point and backup location are recorded outside the repository.