All screens
42 days

Environment Matrix

Every service in an Uploz deployment, side by side across DEV, STAGING and PROD — where it binds, its rollout status, and the secrets each environment needs wired before a service can come up. STAGING is the one that is actually deployed and live today (container uploz-staging @ 62.169.27.202). Postgres is the source of truth and the enforcement boundary (R5); the web app and worker are the only callers of its write-path RPCs.

10

Services tracked

6

Live in STAGING

5

Live in PROD

3

Secrets missing in STAGING

DEVSuccess

local

Local Supabase stack + dev servers.

STAGINGSuccess

uploz-staging @ 62.169.27.202

Live: web :8090, dev-admin :8091, supabase-api :8095. Both apps build GREEN; 94 migrations applied (0001-0095 + 0150) + seeded. swarmiq-os untouched.

PRODIn progress

pending

Not yet promoted from staging.

Service topology

Each row is one service across all three environments. Grouped by tier; addresses are the bind target (DEV), the host:port on the staging box (STAGING), or the public endpoint behind the edge (PROD).

Edge
ServiceDEVSTAGINGPROD

Supabase API / Auth

PostgREST + GoTrue + Realtime. RLS-governed read path and auth.

Live

127.0.0.1:54321

Live

62.169.27.202:8095

PostgREST + GoTrue live; auth login verified (17 users / 17 identities, JWT 200).

Live

api.uploz.io:443

Realtime / WS

Postgres-changes + presence fan-out to the cockpit (Health Timeline, presence).

Live

127.0.0.1:54321

Multiplexed on the API port.

Planned

uploz-staging

Out of scope for the single-image build; no live push yet.

Partial

api.uploz.io:443

Presence channel live; broadcast throttling still being tuned.

Edge / CDN

TLS termination, routing, static asset caching.

N/A

—

No edge in DEV; the app binds directly.

N/A

—

No edge in staging; ports bind directly on the host.

Live

*.uploz.io:443

Application
ServiceDEVSTAGINGPROD

apps/web

Next.js mission-control UI (App Router, RSC). The operator-facing surface.

Live

localhost:3000

Live

62.169.27.202:8090

Live in container uploz-staging; build GREEN (192 static pages).

Live

app.uploz.io:443

Behind the edge; served from the Node runtime, not static export.

apps/dev-admin

Internal build cockpit (this app). Project-tracking + system board.

Live

localhost:3001

Live

62.169.27.202:8091

Live in container uploz-staging; build GREEN (101 static pages).

Partial

admin.uploz.io:443

IP-allowlisted; not yet behind SSO. Read-only against PROD.

Data
ServiceDEVSTAGINGPROD

Supabase Postgres

Source of truth + enforcement boundary. Owns the schema (R5) and all write-path RPCs.

Live

127.0.0.1:54322

Local Supabase stack.

Live

uploz-staging:5432

94 migrations applied (0001-0095 + 0150); seeded (3 events, 8 nodes, 43 roles).

Live

db.uploz.io:5432

Managed Supabase project; PITR enabled.

Supabase Storage

Instruction attachments + run-of-show assets.

Live

127.0.0.1:54321

Live

62.169.27.202:8095

Served via the Supabase API container.

Live

api.uploz.io:443

Async / workers
ServiceDEVSTAGINGPROD

apps/worker

Timer-driven escalation + notification dispatcher (drives fn_due_escalations).

Live

localhost

Single in-process loop.

Live

uploz-staging

Escalation loop up; readiness snapshots live (fn_readiness_summary populating).

Partial

worker.internal

One replica; leader-election before scaling out (avoids double-fire).

Web Push (VAPID)

Browser push delivery for the notification log (push_subscriptions).

Partial

localhost

VAPID keys generated; delivery logged but not dispatched.

Planned

uploz-staging

Self-hosted SMTP not wired; magic-link/push delivery not yet live.

Planned

push.uploz.io:443

Observability
ServiceDEVSTAGINGPROD

OpenTelemetry collector

Trace + metric ingestion from web / worker.

Partial

localhost:4317

Console exporter only; no backend in DEV.

Planned

uploz-staging

No collector in the single-image build.

Planned

otel.internal:4317

Secrets checklist

What must be wired before a build can be promoted. A service stays Partial / Planned until its secrets land in the target environment.

KeyPurposeDEVSTAGINGPROD
NEXT_PUBLIC_SUPABASE_URLBrowser/SSR Supabase endpoint for the read path.WiredWiredWired
NEXT_PUBLIC_SUPABASE_ANON_KEYAnon JWT for RLS-governed client reads.WiredWiredWired
SUPABASE_SERVICE_ROLE_KEYServer-only key for worker write-path RPC calls. Never exposed to the browser.WiredWiredRotating
DATABASE_URLDirect Postgres connection for migrations + the worker.WiredWiredWired
VAPID_PUBLIC_KEYPublic half of the Web Push signing pair.WiredMissingMissing
VAPID_PRIVATE_KEYPrivate Web Push signing key (worker-only).WiredMissingMissing
OTEL_EXPORTER_OTLP_ENDPOINTWhere traces/metrics are shipped.WiredMissingMissing
ADMIN_ALLOWLIST_CIDRIP allowlist guarding the dev-admin cockpit in PROD.WiredWiredWired

DEV / STAGING / PROD authored from the compose / infra config (illustrative project-tracking state, permitted per R1), not a query against live infrastructure — though STAGING mirrors the live single-image roll-out on container uploz-staging @ 62.169.27.202. Service-role keys and VAPID secrets are worker/server-only and are never shipped to the browser.