# Handoff: northwind-site

| | |
| --- | --- |
| Client | Northwind Bakery (hello@northwindbakery.example) |
| Repository | [northwind/site](https://github.com/northwind/site) |
| Generated | 2026-09-29 21:46 UTC |

All times UTC. This document lists environment variable **names only**; it never contains their values.

## Required environment variables

Every variable the code references in the latest scan (deploy `1a5a8be` on `main`, 2026-09-28 18:13 UTC), grouped by the env-file scope that has to define it. None missing.

### Repository root

| Variable | Defined in | Status |
| --- | --- | --- |
| `DATABASE_URL` | `.env.example`, `.env` | ok |
| `SHOPIFY_STORE_DOMAIN` | `.env.example`, `.env` | ok |
| `SHOPIFY_WEBHOOK_SECRET` | `.env.example` | ok |

## Monitored endpoints

| Endpoint | URL | Check | Expects | Uptime, 30 days |
| --- | --- | --- | --- | --- |
| Northwind site | https://example.org/ | GET every 5 minutes | 200 | 99.85% |

## GitHub Action

Scans run in CI on every push. Save the project's ingest token as the repository secret `DEPLOYHEALTH_TOKEN` (tokens are shown once; regenerate one on the project's settings page), then commit this workflow:

```yaml
# .github/workflows/deployhealth.yml
name: deployhealth

# Must not run on pull_request events from forks: the job reads a repository secret.
on:
  push:
    branches: [main]

jobs:
  env-scan:
    runs-on: ubuntu-latest
    permissions:
      contents: read
    steps:
      - uses: actions/checkout@v5
        with:
          persist-credentials: false
      - uses: actions/setup-node@v5
        with:
          node-version: 22
          package-manager-cache: false
      - name: Scan env vars and report to deployhealth
        env:
          DEPLOYHEALTH_TOKEN: ${{ secrets.DEPLOYHEALTH_TOKEN }}
        run: |
          npx --yes deployhealth-scan@0.1.0 \
            --url https://deployhealth.dev \
            --token "$DEPLOYHEALTH_TOKEN" \
            --sha "$GITHUB_SHA" \
            --branch "$GITHUB_REF_NAME"
```

## Open findings

### Unused (1)

_defined in an env file, never referenced_

- `SENDGRID_API_KEY`: defined at .env.example:4, never referenced

## Uptime, last 30 days

**99.85%** on average across 1 endpoint, 2026-08-31 00:00 UTC to 2026-09-29 21:46 UTC.

## Alerts, last 30 days

| Opened | Resolved | Duration | What happened |
| --- | --- | --- | --- |
| 2026-09-26 20:18 UTC | 2026-09-26 20:28 UTC | 10m | Northwind site started failing; no deploy in the 30 minutes before the first failure |

## How to deploy

Static marketing site plus a small order API, both on Railway (`northwind` project).

1. Push to `main`; Railway deploys it.
2. Shopify webhooks point at `/webhooks/orders`. After rotating `SHOPIFY_WEBHOOK_SECRET`, update it in Shopify **and** Railway.
