Deployment

What has to be in place before a deploy serves real traffic.

Required environment variables

VariablePurpose
NEXT_PUBLIC_SUPABASE_URLSupabase project URL.
NEXT_PUBLIC_SUPABASE_ANON_KEYPublishable key (sb_publishable_… on new projects). Safe to expose.
SUPABASE_SERVICE_ROLE_KEYServer-only. Never expose to the browser.
DATABASE_URLPostgres connection string used by Drizzle.
GROQ_API_KEYInference. Absent in production, the app refuses to serve AI results rather than faking them.
RESEND_API_KEYTransactional email. Absent, sends fail loudly instead of silently.
NEXT_PUBLIC_APP_URLCanonical origin. Used to validate post-login redirects.
UPSTASH_REDIS_REST_URLRate limiting. Absent in production, every LLM endpoint returns 503 by design.
UPSTASH_REDIS_REST_TOKENPaired with the URL above.

Fail-closed behaviour

Missing configuration degrades loudly, not silently. Without a rate-limit backend the protected endpoints return 503 rather than running uncapped LLM spend. Without an inference key production refuses to start a session rather than returning fabricated evaluations. A resume that cannot be parsed returns 502 rather than inventing a profile.

Email DNS

The sending domain needs DKIM, an SPF record on the bounce subdomain, and a DMARC policy. A policy of p=none publishes no enforcement — move to p=quarantine with an rua address once alignment is confirmed.

Auth redirect URLs

The Supabase project's Site URL and Redirect URLs must include the production origin and/auth/callback. OAuth sign-in fails at the final redirect if these do not match the deployed domain exactly.