- Create production env values from
.env.example. - Set
ENVIRONMENT=production. - Set
POSTGRES_*for your production database. - Set
AUTH_TOKENas a SHA-256 hex digest (64 lowercase chars) of your bearer token. - Set
ALLOWED_IPSto kaapi-backend's source IP(s), comma-separated. Required in production — the service will not start without it. - Optionally set
GUARDRAILS_HUB_API_KEYandSENTRY_DSN.
Generate AUTH token hash:
echo -n "your-plain-text-token" | shasum -a 256Only kaapi-backend may call this service. Requests must carry Authorization: Bearer <token> plus
X-ORGANIZATION-ID / X-PROJECT-ID, and must originate from an IP in ALLOWED_IPS.
Confirm ALLOWED_IPS matches the IP guardrails actually sees. If NAT or a different network
interface is in play, the observed source will differ from what you expect and every request will be
rejected with 403. Only the health check is exempt.
Note: the check reads the real connection source and ignores X-Forwarded-For. If a reverse proxy
or load balancer is ever placed in front of this service, all traffic will appear to come from the
proxy and this must be revisited.
Build and start backend:
docker compose build backend
docker compose up -d backendRun migrations and initial setup (recommended before or during first rollout):
docker compose --profile prestart up prestartDefault host endpoint:
- API/Docs host:
http://<host>:8001 - Health check:
http://<host>:8001/api/v1/utils/health-check/
CI workflow is defined in .github/workflows/continuous_integration.yml.
It runs dependency install, Guardrails validator installation, migrations, pre-commit checks, and tests.