Skip to content

Production checklist

Go through this list before you point real traffic at a project.

Builds

  • Your build works from a clean checkout. Hiraiship installs from your lockfile on a fresh machine, without your local node_modules or .env files. Commit the lockfile.
  • The build doesn't need a private registry or an outside service. Build machines only reach the npm and Yarn registries, GitHub and nodejs.org. See Build environment.
  • The build finishes well within your plan's timeout. See Limits.

Configuration

  • Every variable your app reads is set in production. Variables are per environment, and a change only applies from the next deployment. See Environment variables.
  • API keys, tokens and passwords are secrets, not plain configuration.
  • Nothing secret is bundled into frontend code. Anything a browser downloads is public.

Domains

  • Your custom domain is Active in the project's Domains tab, with its certificate issued. See Verification & SSL.
  • The other hostnames redirect to the one you want indexed, example.com to www.example.com for instance. See Redirects.

Your app at runtime

  • Backends export a Worker handler. A Node.js server started with listen() doesn't run on Hiraiship. See Hono and Futon.
  • Heavy requests fit your plan's CPU budget per request. A request over it fails. See Limits.
  • A multi-page static site ships a 404.html. Without one, unknown paths serve your home page, which suits single-page apps only. See Static sites.

Your plan

  • Your plan's limits fit the traffic you expect. On Free, reaching the monthly request limit takes your sites offline until the next month. See Suspensions.
  • On a paid plan, your spend limit is where you want it. It's what stops overage, and reaching it suspends your sites. See Spend limit.
  • You know how to roll back. Open the project's deployments, pick the last good one, and roll back. See Rollback.