Give the server its settings
How environment variables reach the server on Node, Docker and Cloudflare Workers, and how their values are read.
The settings every site needs
The handful of settings a production site cannot do without, what each one does, and a complete .env template to copy.
Check your configuration
Run the configuration check, read what it prints, and look up every problem it can report and every error that stops the server.
Keep secrets in files: NAME_FILE
Read any setting from a file by adding _FILE to its name, which is how Docker and Kubernetes secrets are mounted.
Use a secrets manager
Have the server fetch its secrets at start from HashiCorp Vault, AWS Secrets Manager, Doppler or Infisical.
Choose a database
Which of SQLite, PostgreSQL, MySQL or MariaDB, and Cloudflare D1 suits your site, and what to know before choosing.
SQLite
The default database, a file on the server's own disk. Where it is kept, the three files it is made of, and what to watch for.
PostgreSQL
Run the site on a PostgreSQL database: the two settings, creating the database and user, encryption, and what the site does not do for you.
MySQL and MariaDB
Run the site on a MySQL or MariaDB database: the two settings, creating the database and user, encryption, and what the site does not do for you.
Cloudflare D1
The database of a site on Cloudflare Workers: the DB binding, applying the schema by hand, and running a statement against it.
How the database schema is kept up to date
When the site creates its tables, how to do it by hand, why it is safe to repeat, and what each table holds.
How files are stored
The public and private file stores, the storage providers for each platform, and local disk storage in full.
S3-compatible storage
Keep uploaded files in two buckets on AWS S3, Cloudflare R2, MinIO, Backblaze B2, DigitalOcean Spaces, Wasabi or Google Cloud Storage.
R2 on Cloudflare
Keep files in two Cloudflare R2 buckets bound to the Worker, which is the default for a site on Cloudflare Workers.
Public file addresses and upload limits
Where browsers fetch public files from, and the size limit for each kind of upload.
9 items
Sessions and how long people stay logged in
Where logins are remembered (database, Redis, memory or Cloudflare KV), how long admins and members stay logged in, and how to log everyone out.
Stop spam with a bot check
Add Cloudflare Turnstile, hCaptcha or Google reCAPTCHA to the contact form, the ticket order form and the give-by-card form.
Admin sign-in
Choose between one shared username and password and a separate login by emailed link for every admin, and how the two work together.
The first admin, and lock-outs
Create the first admin account on a site where each admin has their own login, from the command line or with wrangler, and recover when nobody can log in.
Ship your own defaults: site.config.json
What the site.config.json file is, how saved settings are laid over it, when to edit it, and how to keep your edits through an update.