Docs / Production checklist
Production checklist
Walk through this before flipping traffic to a live key.
- 1
Distinct keys per environment
Never reuse tfp_test_ keys in production. Verify the prefix in CI.
- 2
Secrets in a manager
AWS / GCP / Vault. No keys in env files, container images, or logs.
- 3
Backoff on 429 and 5xx
Honor the Retry-After header. Cap exponential backoff at 60 s.
- 4
requestId logged on every error
Wire the requestId from the error envelope into your structured logs.
- 5
Webhooks signed and verified
Use the HMAC-SHA256 signature. Reject requests with timestamps > 5 min off.
- 6
Webhook endpoint returns 200 fast
Persist the payload and process async. A 2xx must be returned within 5 s.
- 7
Dead-letter handling for failed hooks
After 24 h of retries, the delivery is moved to dead-letter. Monitor for new entries.
- 8
Quota alerts wired up
Set a budget at 80% of monthly quota; emit an alert so you can top up before 100%.
- 9
Health check on the consumer
Add a /healthz endpoint to your service so the gateway can detect dead consumers.
- 10
Logs shipped to your central store
TEO requestId → your trace; the gateway logs ship the same id to the shared stream.