Production checklist
Go through this list before you point real traffic at a project.
Builds
- Your build works from a clean checkout. Hiraiship installs from your lockfile on a fresh machine, without your local
node_modulesor.envfiles. Commit the lockfile. - The build doesn't need a private registry or an outside service. Build machines only reach the npm and Yarn registries, GitHub and nodejs.org. See Build environment.
- The build finishes well within your plan's timeout. See Limits.
Configuration
- Every variable your app reads is set in
production. Variables are per environment, and a change only applies from the next deployment. See Environment variables. - API keys, tokens and passwords are secrets, not plain configuration.
- Nothing secret is bundled into frontend code. Anything a browser downloads is public.
Domains
- Your custom domain is Active in the project's Domains tab, with its certificate issued. See Verification & SSL.
- The other hostnames redirect to the one you want indexed,
example.comtowww.example.comfor instance. See Redirects.
Your app at runtime
- Backends export a Worker handler. A Node.js server started with
listen()doesn't run on Hiraiship. See Hono and Futon. - Heavy requests fit your plan's CPU budget per request. A request over it fails. See Limits.
- A multi-page static site ships a
404.html. Without one, unknown paths serve your home page, which suits single-page apps only. See Static sites.
Your plan
- Your plan's limits fit the traffic you expect. On Free, reaching the monthly request limit takes your sites offline until the next month. See Suspensions.
- On a paid plan, your spend limit is where you want it. It's what stops overage, and reaching it suspends your sites. See Spend limit.
- You know how to roll back. Open the project's deployments, pick the last good one, and roll back. See Rollback.