Running the platform
Security checklist before going live
1. Set your secrets
Both must be long random values in .env. Generate them with openssl rand -base64 48.
JWT_SECRET— signs login sessions. Left at the default, anyone could forge a session for any account. Changing it logs everyone out once.APP_KEY— encrypts stored GitHub tokens. Set it once: changing it later means users must reconnect GitHub.
2. Lock down file permissions
sudo ./scripts/harden-permissions.sh
3. Understand the sandbox limits
Generated apps run on the same machine as this platform, as the same user. Directory permissions raise the bar but do not fully contain code running as that user. Before opening public signups, run sandboxes as their own unix user or in containers.
4. Email deliverability
If you send password resets from the server, add an SPF record and reverse DNS for the IP, or they will land in spam.