5158c52db5
- Introduced new endpoints for account overview, analytics, and metrics. - Implemented authorization matrix and backup/restore documentation. - Added smoke test script and updated package dependencies. - Created detailed production checklist and runbook for deployment. - Established cron operations and notification event matrix documentation. - Enhanced security and validation audits for analytics and metrics services. - Added unit tests for analytics and metrics functionalities.
1.3 KiB
1.3 KiB
Production Checklist
- Infrastructure sized, isolated, patched, TLS-enabled
- Secrets generated, injected, access-limited, rotation tested
- MySQL fresh/upgrade migrations verified on restored data
- Backup and restore drill meets approved RPO/RTO
- Redis auth/persistence/loss behavior validated
- Private S3 upload, signed download, expiry, delete, versioning tested
- SMTP security and non-customer test recipients verified
- Stripe and PayHere sandbox flows/webhooks/refunds validated
- Roles and all Phase 1–11 permissions seeded/reviewed
- Authorization matrix and IDOR E2E suite approved
- Dependency/image scan risk accepted; remaining majors planned
- API, workers, and exactly one cron scheduler deployed
- Queue retry/backlog/failure alerts tested
- Health and protected metrics scraped/alerted
- Nginx proxy trust, size, timeout, webhook, HTTPS behavior tested
- Frontend/mobile uses
/api/v1and handles standard errors - Full retail/business/payment/delivery/return/loyalty/support E2E passes
- Concurrency/idempotency tests pass on real InnoDB/Redis
- Non-destructive production smoke passes
- Go-live owner, rollback authority and incident contacts assigned
- Post-go-live reconciliation and monitoring window scheduled