Production setup
Public checklist for deploying Claire without exposing live infrastructure details.
This is the public checklist for deploying Claire. Live hostnames, project IDs, database proxies, and operator runbooks belong in a private operations repository, not in this tree.
Required services#
- The Claire API (
server/) - Postgres, Auth, and Realtime — self-hosted Supabase or a managed project
- Redis
- Optional: Matrix (Synapse plus mautrix bridges) when
PLATFORM_MODE=matrix
Server environment#
Copy .env.production.example and server/.env.example, then set real values in your host’s secret store.
| Variable | Purpose |
|---|---|
SUPABASE_URL | API gateway for Auth, PostgREST, and Realtime |
SUPABASE_ANON_KEY | Public anon key |
SUPABASE_SERVICE_KEY | Server-only service-role key |
DATABASE_URL | Postgres connection string |
JWT_SECRET | Session signing secret |
ENCRYPTION_KEY | Token encryption at rest |
OPENAI_API_KEY | Optional; mock mode does not need it |
PLATFORM_MODE | matrix or direct — must be explicit in production |
REDIS_URL | Queue and session cache |
Mobile environment#
Stored in EAS or a local, never-committed `.env.production`.
| Variable | Purpose |
|---|---|
EXPO_PUBLIC_SUPABASE_URL | The gateway the app itself can reach |
EXPO_PUBLIC_SUPABASE_ANON_KEY | Public anon key |
EXPO_PUBLIC_API_URL | Public Claire API origin |
EXPO_PUBLIC_ENV | production |
Store them in EAS so CI machines never need a local file:
bunx eas env:create --scope project --environment production \
--name EXPO_PUBLIC_SUPABASE_URL \
--value "$EXPO_PUBLIC_SUPABASE_URL" \
--type plainRepeat for the rest, then pull on a new machine with bunx eas env:pull --environment production.
Health checks#
curl https://<claire-api-host>/health
curl https://<supabase-kong-host>/auth/v1/health \
-H "apikey: $EXPO_PUBLIC_SUPABASE_ANON_KEY"Builds#
bunx eas build --profile preview --platform ios
bunx eas build --profile production --platform ios