Skip to content

Guide: Going to Production

Work through this list before your first deployment. Each item links to the page that explains it.

  • APP_ENV=production, APP_DEBUG=false
  • A fresh APP_KEY and JWT_SECRET (php naluz key:generate --jwt --show), stored as environment variables, not committed
  • APP_URL set to the public HTTPS URL
  • A real database (MySQL, PostgreSQL or SQL Server) with a dedicated user. See Database drivers
  • CACHE_DRIVER, SESSION_DRIVER and QUEUE_CONNECTION on Redis if you run more than one server
  • HTTPS everywhere (HSTS and Secure cookies then activate automatically)
  • Document root is public/ only; .env and storage/ are not web-accessible
  • CORS origins listed if browsers on other origins call your API (config/security.php)
  • Tight throttle limits on login and password-reset routes
  • Real client IP restored at the web server (see Deployment)
  • Authorization checks on every write path. See Authorization
  • GraphQL introspection off (the default outside debug)
Terminal window
composer install --no-dev --optimize-autoloader
php naluz migrate
php naluz route:cache
php naluz view:clear
  • OPcache enabled with validate_timestamps=0; reload PHP-FPM after deploy
  • Queue workers under a supervisor, restarted on each deploy
  • The scheduler’s single cron entry
  • queue.retry_after above your slowest job
  • LOG_CHANNEL=production (daily files plus Slack for critical errors) or stderr with JSON in containers
  • Logs are collected and alerts exist for critical errors. See Logging
  • Hit GET /api/ping and a few real routes
  • Trigger a handled error and confirm no stack trace is shown to clients
  • Check the log file or Slack for the error you triggered