Provisioning›Pre-flight Checklist

SE / Ops Pre-flight Checklist

Complete all 25 checks before marking a deployment go_live_verified.

0 / 25 checks complete0%
13 critical remaining
Infrastructure

VPC layout, ALB placement, ECS task networking, and security group rules.

0/6

VPC has ≥2 Availability Zones

Critical

ALB is in public subnets (≥2 AZs)

Critical

ECS tasks are in private subnets (no public IP)

Critical

Each private subnet has a NAT gateway or VPC endpoint

Critical

ALB SG: inbound 443 from 0.0.0.0/0, outbound 3000 → ECS SG

ECS SG: inbound 3000 from ALB SG (source = SG ID, not CIDR)

Critical
DNS & TLS

ACM certificate issuance, region alignment, and Route 53 alias records.

0/4

ACM certificate status: Issued (not Pending)

Critical

ACM cert is in the same region as the ALB

Critical

ACM cert domain matches the app domain (wildcard or exact)

Route 53 A (Alias) record points to ALB DNS name

App & Supabase

Environment variables, health endpoint, and Supabase connectivity.

0/6

ALB health check path is /api/health (NOT /healthz)

Critical

NEXT_PUBLIC_SUPABASE_URL is set correctly

Critical

SUPABASE_SERVICE_KEY and NEXT_PUBLIC_SUPABASE_ANON_KEY are configured

Critical

NEXT_PUBLIC_APP_URL matches the external URL

APP_VERSION matches the pinned image tag

Supabase migrations applied for this app version

Critical
IAM & Security

ECS execution role permissions, clock sync, log retention, and image pinning.

0/4

ECS task execution role has all required IAM permissions

Critical

ECS tasks use Amazon Time Sync Service (169.254.169.123)

CloudWatch log group retention set to 7–30 days

Production image pinned to sha-... tag (not latest)

Health & CCC Readiness

Final smoke tests before marking go_live_verified.

0/5

GET /api/health → {"status":"ok"} with HTTP 200

Critical

Login page renders at /login without errors

/login → workspace selection redirects correctly

CCC loads with products and dashboards visible

Direct API call to /api/products/... without auth → 403

The most frequent root causes of failed or broken deployments.

ALB targets show Unhealthy immediately after deploy

  • • Health check path set to /healthz instead of /api/health
  • • ECS security group does not allow inbound port 3000 from ALB SG (must use SG ID as source, not CIDR)
  • • /api/health returns 503 because NEXT_PUBLIC_SUPABASE_URL or SUPABASE_SERVICE_KEY is missing
  • • ECS task has no outbound internet access (missing NAT gateway) so it cannot reach Supabase

503 from /api/health even though ECS task is running

  • • Supabase environment variables are wrong or missing
  • • Private subnets have no NAT gateway → tasks cannot reach Supabase
  • • Check CloudWatch logs for the specific error

Users get 401 errors and are stuck in login loops

  • • ECS task clock is out of sync → JWT validation fails
  • • Fix: ensure NTP uses Amazon Time Sync Service (169.254.169.123)
  • • Also check SUPABASE_JWT_SECRET matches your Supabase project settings

App works in one AZ but fails randomly

  • • Single-AZ NAT problem: only one private subnet has a NAT gateway
  • • ECS tasks placed in the other AZ cannot reach Supabase or ECR
  • • Fix: deploy a NAT gateway in each AZ, or use VPC endpoints for ECR, Secrets Manager, S3

CCC tabs are empty or show silent 500 errors

  • • Supabase migrations not applied for this app version
  • • Check the Schema Compatibility Matrix tab for the correct migration folder

ACM certificate stuck on Pending Validation

  • • DNS validation CNAME record not added to Route 53
  • • Certificate in wrong region (must match ALB region)
  • • Fix: go to ACM console → copy the CNAME record → add to Route 53 hosted zone

Quick health check command:

curl -si https://YOUR-APP-DOMAIN/api/health | head -20
base44
Edit with Base44