helixordevelopers

Production checklist

Work through this list before you go live and again after every major change. Each item links to the page that explains why it matters and how to do it.

Security#

DoneItemSee
☐The license file is in a secret manager, mounted read-only, mode 600 or 440, and absent from images and repositories.Security
☐The license is passed by path, never in a URL, query string or logged environment variable.Security
☐Production and non-production use separate licenses where your agreement allows.Security
☐Commands that contact Helixor (compile --remote, catalog, download-pack) run on build agents only.Security
☐The decision service is bound to 127.0.0.1, or has a service token and is reachable only through a gateway or proxy that terminates TLS.Deployment patterns
☐CORS, maximum body size and timeouts are enforced at the gateway; the service is never exposed to browsers.Security
☐No log, trace or error report captures payloads, full results or matched_items.Security
☐Egress is denied, or restricted to what the application needs, by network policy or firewall.Security
☐Receipts are signed or anchored if you need tamper-evident audit.Security
☐Containers run as non-root with a read-only root file system and all capabilities dropped.Deployment patterns
☐The runtime wheel is pinned by checksum.Security
☐Only redacted text is ever sent to the hosted reasoning API, and the API key is in a secret manager.Deployment patterns

Reliability#

DoneItemSee
☐Every caller treats an exception, timeout or unreachable service as a block.Reliability
☐Start-up verifies the loaded pack_id and refuses to serve the Community pack when you expect your own.Reliability
☐Readiness uses the evaluation probe; liveness uses the probe or GET /v1/health.Reliability
☐A daily license expiry check alerts 30 days ahead and during the grace period.Reliability
☐License and packs are versioned and deployed as one pair, and renewal includes rebuilding every pack.Reliability
☐A rollback to the previous pair has been rehearsed.Reliability
☐One engine per worker process, one streaming session per stream.Reliability
☐Production runs an Enterprise license, not a rate-limited Developer license.Licensing
☐Hosts are synced to a trusted time source.Security

Performance efficiency#

DoneItemSee
☐The placement is the closest that meets your needs: in-process, then sidecar, then shared service.Performance efficiency
☐Latency is measured at the caller, not taken from latency_us.Performance efficiency
☐Each process runs one warm-up evaluation before it reports ready.Performance efficiency
☐Payload size is bounded at the gateway, and large documents are split.Performance efficiency
☐Live token streams use a streaming session or the WebSocket endpoint.Streaming
☐The system scales with processes or replicas, sized from a benchmark on production hardware.Performance efficiency

Operational excellence#

DoneItemSee
☐One structured log line per decision, with receipt hash, pack version and digest.Operational excellence
☐Decision, rule, error, latency, license-days and pack-info metrics are emitted and on a dashboard.Operational excellence
☐Playbooks are in source control, reviewed, and version-bumped on every change.Operational excellence
☐CI compiles each pack and runs a golden test set that covers every rule.Testing policies
☐Promoted packs are identified by digest and never rebuilt after approval.Operational excellence
☐Runbooks exist for start-up failure, license expiry, wrong pack, and rate or error spikes.Operational excellence

Cost optimization#

DoneItemSee
☐Replica count and memory requests come from a measurement, not the example values.Cost optimization
☐Escalation to hosted reasoning is rule-based, counted and reviewed.Cost optimization
☐Logs carry a fixed field set; no payloads, no scheduled polling.Cost optimization