Production Checklist
Remem 0.5 is a Go service backed by Pebble. It is designed to run as a durable single-node deployment today, with tenant-aware storage and a clear path to future multi-node operation.
Security
Section titled “Security”-
REMEM_SERVER_ENV=productionis set -
REMEM_SERVER_API_KEYis a long, random secret and is not committed - The server is reachable only through the intended network boundary
- TLS is terminated by Nginx, Caddy, or a load balancer
- API credentials are rotated if they have been exposed
Generate a key:
openssl rand -hex 32Persistence
Section titled “Persistence”-
/var/lib/rememis backed by a persistent host directory or volume - The directory is writable by the container user, uid
10001 - The Pebble data directory is backed up regularly
- Backups are tested before an upgrade
The Compose release bind-mounts REMEM_DATA_DIR to /var/lib/remem. This keeps
the corpus visible to ordinary host tools and protects it from
docker compose down -v.
Health and operations
Section titled “Health and operations”-
GET /api/v1/readyis monitored for readiness -
GET /api/v1/healthis monitored for process health -
GET /api/v1/health/deepis monitored when authenticated storage checks are needed - Logs use
format = "json"in the[log]section ofremem.toml - Rate limits and job workers are sized for the expected tenant workload
-
remem-adminexport and verification are available to the operator
Upgrades
Section titled “Upgrades”Pull the new source snapshot, review the release notes, back up the data directory, and rebuild the image:
git pulldocker compose up --build -dRemem tracks its on-disk format and runs required migrations before serving the store. Use the administrative snapshot and verification commands for a portable backup or a cross-environment migration.
