# Handoff: acme-storefront

| | |
| --- | --- |
| Client | Acme Corp (ops@acme.example) |
| Repository | [acme/storefront](https://github.com/acme/storefront) |
| Generated | 2026-09-29 21:47 UTC |

All times UTC. This document lists environment variable **names only**; it never contains their values.

## Required environment variables

Every variable the code references in the latest scan (deploy `b52952e` on `main`, 2026-09-29 19:47 UTC), grouped by the env-file scope that has to define it. **3 variables missing.**

### `apps/api`

| Variable | Defined in | Status |
| --- | --- | --- |
| `DATABASE_URL` | `.env.example`, `.env` | ok |
| `JWT_SECRET` | `.env.example`, `.env` | ok |
| `LOG_LEVEL` | `.env.example`, `.env` | ok |
| `PORT` | `.env.example` | ok |
| `REDIS_URL` | — | **missing** |
| `SENTRY_DSN` | `.env.example`, `.env` | ok |
| `STRIPE_KEY` | — | **missing** |
| `STRIPE_WEBHOOK_SECRET` | `.env.example`, `.env` | ok |

### `apps/web`

| Variable | Defined in | Status |
| --- | --- | --- |
| `ANALYTICS_WRITE_KEY` | — | **missing** |
| `NEXT_PUBLIC_API_URL` | `.env.example`, `.env` | ok |
| `NEXT_PUBLIC_CHECKOUT_V2` | `.env` | ok |
| `NEXT_PUBLIC_SUPPORT_EMAIL` | `.env.example`, `.env` | ok |
| `SENTRY_DSN` | `.env.example`, `.env` | ok |

### `apps/worker`

| Variable | Defined in | Status |
| --- | --- | --- |
| `DATABASE_URL` | `.env.example`, `.env` | ok |
| `REDIS_TLS_URL` | `.env.example` | ok |
| `S3_BUCKET` | `.env.example` | ok |

## Monitored endpoints

| Endpoint | URL | Check | Expects | Uptime, 30 days |
| --- | --- | --- | --- | --- |
| Acme storefront | https://example.com/ | HEAD every 5 minutes | 200 | 99.90% |
| Acme API | https://deployhealth.dev/api/demo/broken | GET every minute | 200 | 99.23% |

## GitHub Action

Scans run in CI on every push. Save the project's ingest token as the repository secret `DEPLOYHEALTH_TOKEN` (tokens are shown once; regenerate one on the project's settings page), then commit this workflow:

```yaml
# .github/workflows/deployhealth.yml
name: deployhealth

# Must not run on pull_request events from forks: the job reads a repository secret.
on:
  push:
    branches: [main]

jobs:
  env-scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
    steps:
      - uses: actions/checkout@v5
        with:
          persist-credentials: false
      - uses: actions/setup-node@v5
        with:
          node-version: 22
          package-manager-cache: false
      - name: Scan env vars and report to deployhealth
        env:
          DEPLOYHEALTH_TOKEN: ${{ secrets.DEPLOYHEALTH_TOKEN }}
        run: |
          npx --yes deployhealth-scan@0.1.0 \
            --url https://deployhealth.dev \
            --token "$DEPLOYHEALTH_TOKEN" \
            --sha "$GITHUB_SHA" \
            --branch "$GITHUB_REF_NAME"
```

## Open findings

### Missing (3)

_referenced in code, not defined in its scope_

- `ANALYTICS_WRITE_KEY`: referenced at apps/web/src/lib/analytics.ts:4
- `REDIS_URL`: referenced at apps/api/src/lib/cache.ts:6
- `STRIPE_KEY`: referenced at apps/api/src/billing/stripe.ts:3

### Unused (2)

_defined in an env file, never referenced_

- `OLD_PAYPAL_CLIENT_ID`: defined at apps/api/.env.example:14, never referenced
- `S3_REGION`: defined at apps/worker/.env.example:5, never referenced

### Mismatch (1)

_.env and .env.example disagree_

- `NEXT_PUBLIC_CHECKOUT_V2`: defined at apps/web/.env:4, absent from apps/web/.env.example

## Uptime, last 30 days

**99.56%** on average across 2 endpoints, 2026-08-31 00:00 UTC to 2026-09-29 21:47 UTC.

## Alerts, last 30 days

| Opened | Resolved | Duration | What happened |
| --- | --- | --- | --- |
| 2026-09-29 19:52 UTC | still open | 1h 54m so far | Acme API started failing 4m after deploy b52952e, which introduced 2 missing env vars: REDIS_URL, STRIPE_KEY |

## How to deploy

## Where it runs

- **Web and API:** Railway project `acme-prod`, services `web` and `api`.
- **Worker:** Railway service `worker` (queues on Redis).
- **DNS:** Cloudflare; `acme.example` points at Railway.

## Deploying

1. Merge to `main`. Railway builds and deploys `web`, `api` and `worker`.
2. Database migrations run in the API's pre-deploy step (`pnpm db:migrate`).
3. Urgent billing fixes: branch `hotfix/<name>` from `main`, open a PR, merge.

## Secrets

Set per service in Railway, under **Variables**. The names are listed in *Required environment
variables* above; the values are in the client's 1Password vault **Acme / Production**.

## Rolling back

Railway → service → **Deployments** → redeploy the previous build. See the
[Railway deployment docs](https://docs.railway.com/guides/deployments).
