Deployment
Build an application image, run the compose stack, and ship to production.
Build and run
The compose stack builds the app from the workspace Dockerfile and exposes a /health liveness probe on port 8000.
Infrastructure services
Production configuration
Two rules to internalize before shipping:
- Environment variables always win over TOML files. The config loader merges
config/*.tomlfirst, then applies the process environment last — so secrets belong in the environment, not in files. - Destructive migrations are gated.
migrate:freshis refused in production unless--forceis passed explicitly.
Run migrations as a release step, then bring the app up:
Background workers
Queue workers and the scheduler are separate processes in production:
For recurring dispatch, drive schedule:run from an external timer or a long-running supervisor, and use the pause/resume commands during deploys to avoid double dispatch:
Release checklist
cargo xtask cipasses (fmt, clippy, deps, lines, DAG cycles)cargo test --workspacepassescargo deny checkandcargo auditare cleanAPP_KEYand all secrets come from the environment- Migrations run with
--forceand are reversible - Health probe on
/healthmatches the orchestrator configuration
Last updated Sep 22, 2026