Health checks
The API’s/healthz is a public liveness check. /readyz requires Bearer authentication and verifies database/schema readiness. The web app has its own /healthz. A healthy process is not proof that DNS, TLS, OAuth callbacks or an MCP client connection are working.
Check the Compose service state with docker compose ps, then test the public UI and API through your ingress. Keep request/response bodies, Authorization headers, health observations and root credentials out of proxy logs and tracing.
Upgrades and migrations
Take a tested database backup before upgrading. Deploy the API and web app from the same reviewed revision. The API startup entrypoint applies checked-in Drizzle migrations and serializes concurrent migration attempts with a PostgreSQL advisory lock. For an operator-run migration, usenpm run db:migrate with the intended DATABASE_URL. Keep applied migration files immutable and add forward migrations. Do not use drizzle-kit push for production upgrades.
Back up PostgreSQL
A PostgreSQL backup retains records, immutable revisions, goals, API-key digests, OAuth client registrations and idempotency metadata. Store dumps encrypted with restricted access, and test restoring them into an isolated database before relying on them.Credential boundaries
- The environment
AUTH_KEYcan read/write the ledger and administer all authentication records. - Generated
vlk_API keys enforce the selected permission ceiling and expiry (30 days, 90 days, 1 year or Never). Administrative keys can also inspect readiness and OpenAPI; root/primary authority still protects credential management. - OAuth
vlo_tokens authorize their requested MCP health scopes for 30 days. - Dashboard
vls_sessions can read health records only. - Root-verified
vlm_sessions can manage generated keys and MCP connections for 30 minutes.
File storage
Back up attachment objects alongside PostgreSQL; database backups and JSONL exports contain only metadata and links.operator:attachments:prune clears expired staging uploads without removing ready files. Stop the API before permanent erasure; the erasure command removes ledger objects before database metadata and preserves unrelated prefixes. See attachment operations.