Skip to content

Production Checklist

Remem 0.5 is a Go service backed by Pebble. It is designed to run as a durable single-node deployment today, with tenant-aware storage and a clear path to future multi-node operation.

  • REMEM_SERVER_ENV=production is set
  • REMEM_SERVER_API_KEY is a long, random secret and is not committed
  • The server is reachable only through the intended network boundary
  • TLS is terminated by Nginx, Caddy, or a load balancer
  • API credentials are rotated if they have been exposed

Generate a key:

Terminal window
openssl rand -hex 32
  • /var/lib/remem is backed by a persistent host directory or volume
  • The directory is writable by the container user, uid 10001
  • The Pebble data directory is backed up regularly
  • Backups are tested before an upgrade

The Compose release bind-mounts REMEM_DATA_DIR to /var/lib/remem. This keeps the corpus visible to ordinary host tools and protects it from docker compose down -v.

  • GET /api/v1/ready is monitored for readiness
  • GET /api/v1/health is monitored for process health
  • GET /api/v1/health/deep is monitored when authenticated storage checks are needed
  • Logs use format = "json" in the [log] section of remem.toml
  • Rate limits and job workers are sized for the expected tenant workload
  • remem-admin export and verification are available to the operator

Pull the new source snapshot, review the release notes, back up the data directory, and rebuild the image:

Terminal window
git pull
docker compose up --build -d

Remem tracks its on-disk format and runs required migrations before serving the store. Use the administrative snapshot and verification commands for a portable backup or a cross-environment migration.