Deployment
What has to be in place before a deploy serves real traffic.
Required environment variables
| Variable | Purpose |
|---|---|
| NEXT_PUBLIC_SUPABASE_URL | Supabase project URL. |
| NEXT_PUBLIC_SUPABASE_ANON_KEY | Publishable key (sb_publishable_… on new projects). Safe to expose. |
| SUPABASE_SERVICE_ROLE_KEY | Server-only. Never expose to the browser. |
| DATABASE_URL | Postgres connection string used by Drizzle. |
| GROQ_API_KEY | Inference. Absent in production, the app refuses to serve AI results rather than faking them. |
| RESEND_API_KEY | Transactional email. Absent, sends fail loudly instead of silently. |
| NEXT_PUBLIC_APP_URL | Canonical origin. Used to validate post-login redirects. |
| UPSTASH_REDIS_REST_URL | Rate limiting. Absent in production, every LLM endpoint returns 503 by design. |
| UPSTASH_REDIS_REST_TOKEN | Paired with the URL above. |
Fail-closed behaviour
Missing configuration degrades loudly, not silently. Without a rate-limit backend the protected endpoints return 503 rather than running uncapped LLM spend. Without an inference key production refuses to start a session rather than returning fabricated evaluations. A resume that cannot be parsed returns 502 rather than inventing a profile.
Email DNS
The sending domain needs DKIM, an SPF record on the bounce subdomain, and a DMARC policy. A policy of p=none publishes no enforcement — move to p=quarantine with an rua address once alignment is confirmed.
Auth redirect URLs
The Supabase project's Site URL and Redirect URLs must include the production origin and/auth/callback. OAuth sign-in fails at the final redirect if these do not match the deployed domain exactly.