Operate & go live

What you do after the code works — take an App, Theme or integration to production, keep it healthy, and find out what went wrong when a call fails.

The other guide paths end at a working deployment. This one starts there.

Going live is a different job from building: you are settling access, domains, rollbacks and escalation rather than writing features, and most of it is done once per project by someone who will not touch the code again. The reference pages below already describe each piece. The guides in this bucket stitch them into the order you actually need them.

Before you go live

You need these decided, not just deployed.

  • Production keys. Separate keys per environment, scoped to what the caller genuinely needs, and a plan for rotating them. See API keys.
  • A domain. One CNAME in your own zone. See Domains.
  • A rollback you have tried. Not the first time under pressure. See Instant rollbacks.
  • Somewhere to look. Know where your logs are before you need them, not after. See Logs.
  • An escalation path. Who you contact, and what they need from you. See Get help.

What the platform already handles

A security review will ask about these. None of them is a task on your side.

ConcernWhat happensReference
TLSCertificates issued and renewed automaticallyTLS
Web application firewallManaged, on for every tenantWAF
DDoS filteringOn by default, nothing to enableDDoS
CompressionText responses compressed at the edgeCompression
Rate limitsPer tenant at the gateway — a 429 is a limit to handle, not a setting to changeRate limits

Operating what you shipped

Was this page helpful?