Guide: Going to Production
Work through this list before your first deployment. Each item links to the page that explains it.
1. Configuration
Section titled “1. Configuration”-
APP_ENV=production,APP_DEBUG=false - A fresh
APP_KEYandJWT_SECRET(php naluz key:generate --jwt --show), stored as environment variables, not committed -
APP_URLset to the public HTTPS URL - A real database (MySQL, PostgreSQL or SQL Server) with a dedicated user. See Database drivers
-
CACHE_DRIVER,SESSION_DRIVERandQUEUE_CONNECTIONon Redis if you run more than one server
2. Security
Section titled “2. Security”- HTTPS everywhere (HSTS and
Securecookies then activate automatically) - Document root is
public/only;.envandstorage/are not web-accessible - CORS origins listed if browsers on other origins call your API (
config/security.php) - Tight
throttlelimits on login and password-reset routes - Real client IP restored at the web server (see Deployment)
- Authorization checks on every write path. See Authorization
- GraphQL introspection off (the default outside debug)
3. Build and release
Section titled “3. Build and release”composer install --no-dev --optimize-autoloaderphp naluz migratephp naluz route:cachephp naluz view:clear- OPcache enabled with
validate_timestamps=0; reload PHP-FPM after deploy
4. Background work
Section titled “4. Background work”- Queue workers under a supervisor, restarted on each deploy
- The scheduler’s single cron entry
-
queue.retry_afterabove your slowest job
5. Observability
Section titled “5. Observability”-
LOG_CHANNEL=production(daily files plus Slack for critical errors) orstderrwith JSON in containers - Logs are collected and alerts exist for critical errors. See Logging
6. Optional performance
Section titled “6. Optional performance”- Model caching with Redis (
MODEL_CACHING=true,MODEL_CACHE_DRIVER=redis) - Read replicas if reads dominate
7. After deploying
Section titled “7. After deploying”- Hit
GET /api/pingand a few real routes - Trigger a handled error and confirm no stack trace is shown to clients
- Check the log file or Slack for the error you triggered