IInstaFileFast image tools

Owner checklist

What still requires your action before launch

This page tracks only the remaining provider setup, staging validation, business decisions, and launch checks. Completed production work is recorded below so it is not accidentally repeated.

Do not put secrets on this page or in Git.Add them only through the relevant provider and Railway secret-variable interfaces.
Completed August 22, 2026.Production accounts were migrated from SQLite to PostgreSQL with an exact table-by-table verification, a fresh SQLite rollback backup, PostgreSQL daily backups and point-in-time recovery, a post-migration manual backup, an isolated restore drill, and a real email-code login test. Production is healthy on one PostgreSQL-backed API replica with account writes enabled; the canonical www host and HTTPS apex redirect are live.
Shared-media staging acceptance passed.The private R2 bucket, exact production/staging upload CORS, one-day failsafe cleanup, staging PostgreSQL job store, direct browser uploads, and a private all-lanes Railway worker are configured. GitHub Actions run 18 passed both required jobs. Live staging passed direct upload, authenticated download, image, video, GIF, PDF, webpage capture, remote import, and signed-in Pro vectorization; the vector test also confirmed exactly one successful input settled exactly one credit.
Five-worker launch capacity and shared-processing rollback passed.GitHub Actions run 24 passed both required jobs and deployed the worker-derived long-video deadline. The production-shaped ten-minute direct-R2 wave completed 5 of 5 concurrent 87.9 MB jobs with HTTP 200, one durable attempt each, and zero rejection, retry, polling, or health failures. Processing p50 was 336.3 seconds and p95/max was 588.7 seconds against the 1,800-second ceiling; end-to-end p95 was 688.4 seconds including upload. The rollback drill then disabled async jobs and direct uploads, kept health green, and completed a legacy multipart video conversion with HTTP 200. Restoring both flags returned direct uploads and completed another worker job with HTTP 200 on one attempt. Staging is back to one worker with normal quotas and empty queues.
Production shared processing went live August 23, 2026.Production now has a stable job-token secret, PostgreSQL job storage, the private R2 bucket, and five private Railway workers split across image, video/GIF, PDF, vector, and capture/import lanes. Railway reports every worker Online behind /health; direct uploads and async jobs are enabled. A real 52.8 KB video completed through direct R2 upload and the video worker with HTTP 200 on one attempt. The production rollback drill then disabled both features, completed the same conversion through legacy multipart with HTTP 200, restored both features, and completed another direct-R2 worker job with HTTP 200 on one attempt. Final health was ok with zero uploading, queued, or running jobs.
Production application, email, and billing-state monitoring is live.The private Railway Grafana Alloy collector is Online and sends metrics only to Grafana Cloud. All six protected metrics targets and all six real application health probes report healthy. The versioned InstaFile Production dashboard and all nine permanent alert rules are live. The owner email contact point, default route, and test notification passed. A safe simulated Resend bounce moved the permanent email rule from Normal to Firing and back to Normal. On August 26, the deployed unresolved-webhook and billing-review gauges both returned zero; rules bfwcyxjbkouf4b and ffwcyz5w8h2pse then completed live production evaluations in the Normal state with the owner-email route intact.
Post-cutover account regression passed August 24, 2026.A separate Gmail plus-alias account completed real signup, PostgreSQL persistence, direct R2 upload, one-attempt image-worker processing, shared Free-plan usage accounting, authenticated job history, logout, session invalidation, email-code relogin, history persistence, and full account/job/usage deletion. The deleted session now has no user and cannot read job history; the owner account was never selected for deletion. Immediate resend was correctly rate-limited, and a controlled resend after the cooldown delivered the login code. The first hourly production cleanup completed at 2026-08-24T17:37:46.247Z with no error; PostgreSQL, R2, and empty shared queues remained healthy through the post-run stability check.
Production promotion and shutdown safeguards passed August 25, 2026.GitHub Actions run 36 passed the shared-job integration and full launch gate. Railway Wait for CI is enabled on the API, five private workers, and metrics collector, and all seven services use a 20-second deployment-draining window so future releases are tested before promotion and receive time for graceful shutdown.
Cloudflare edge protection and origin locking passed August 25, 2026.GitHub Actions run 38 passed both required jobs for commit 048a9e6, including the origin-lock regression and container vulnerability gates, before Railway promoted all seven services. The canonical www record is proxied, Cloudflare overwrites a secret origin header, and its active Free-plan burst rule blocks more than 10 POSTs in 10 seconds across remote import, webpage capture, vectorization, and upscale. A fake client-supplied secret was overwritten and the public homepage, auth config, and health remained HTTP 200. A direct Railway request with the production Host header returned HTTP 403, including with a spoofed CF-Connecting-IP; direct /health remained HTTP 200 and unauthenticated /metrics remained HTTP 401. PostgreSQL, R2, shared jobs, and all queues were healthy and empty. The Free plan does not include Cloudflare's managed ruleset, so the application quotas, worker limits, provider budgets, and container security gate remain the documented compensating controls.
Production container advisory review completed August 25, 2026.GitHub Actions run 40 passed both required jobs for commit 967a201, built the Bookworm production image with Chromium 151.0.7922.173 or newer enforced, removed the two fixable pypdf findings, and reported zero fixable High/Critical findings. The complete report's 335 High/Critical package matches reduce to 111 unique advisories; unresolved media and browser findings remain and are not being hidden. Run 41 then passed the duplicate-advisory reporting regression and the same complete production scan for commit 49829a8. FFmpeg/FFprobe inputs are restricted to local files and pipes, workers are private and resource-bounded, and two real production webpage captures completed in 3.248s and 2.995s. All seven Railway services are Online on the run 41 release; PostgreSQL, R2, shared jobs, and empty queues are healthy. The detailed reachable/unreachable review is in the deployment runbook. Owner risk approval and a fresh review before every release are still required.
Production worker-lane smoke passed August 25, 2026.After GitHub Actions run 42 passed and Railway promoted all seven services, a guarded production runner submitted one small job at a time across image, PDF, GIF, video, capture, and remote-import lanes. Every job completed on its first attempt in 2.045–4.699 seconds, every result download matched its expected file signature, and the image, PDF, GIF, and video inputs uploaded directly to private R2. Final production health was ok with PostgreSQL, R2, and shared jobs healthy and zero uploading, queued, or running jobs. Vectorization remains intentionally separate because billing acceptance must verify the locked Free preview, exact-result purchase, and Pro unlimited paths.
Historical Stripe pack acceptance passed August 25, 2026; that offer is now retired.Runs 44–47 proved the original 100-credit Vector Pack, Pro subscription, portal, cancellation, refund, dispute, signed-webhook, and review controls in Stripe test mode. On August 26 the owner replaced that customer offer with a simpler three-level model: free watermarked previews, a $0.99 one-time unlock for one exact clean SVG, and $4.99/month Pro. The old tests remain useful evidence for subscription, webhook, refund, and dispute safety, but they do not approve the new single-SVG Checkout path for launch.
The three-level vector offer passed staging acceptance August 26, 2026.GitHub Actions run 53 passed both required jobs for commit b745632, and Railway ran the staging API and worker Online on that exact commit. A Free account received a watermarked PNG while its clean SVG remained locked; a real $0.99 Stripe sandbox Checkout unlocked only that exact result, whose two repeat downloads were identical. Canceled Checkout granted nothing, a full refund relocked only the purchased result, and a $0.50 partial refund relocked paid access, placed the disposable account under review, and blocked another Checkout with HTTP 409. An active $4.99/month Pro account then created job b0d7304e-d518-4555-a262-55e3cfa42847 with the SVG immediately unlocked and downloadable without a per-image payment. The same account also completed the full published 12-image Pro batch in one attempt: all 12 SVGs were unlocked, valid, and downloadable after 12.2 seconds. Both disposable purchase accounts were deleted afterward; staging returned to zero review accounts and webhook failures with PostgreSQL, R2, shared jobs, and every queue healthy.
Stripe sandbox renewal, recovery, paid-account deletion, and billing-alert acceptance passed August 26, 2026.Subscription sub_1U8i2pFpv5juia6idQ3wcQz1 renewed successfully once, then invoice AYHTMSEV-0003 failed on Stripe’s renewal-decline card. Stripe became past_due and staging immediately changed the account to Free with no grace period and no unlimited vector entitlement. Retrying that exact invoice on the valid card made it Paid and restored active Pro and unlimited vectorization. Deleting the disposable account returned HTTP 200, canceled the active sandbox subscription, invalidated the old session, and removed the account. All 15 signed billing webhooks returned 2xx; the protected failure and review queues were empty. A protected manual reconciliation completed at 2026-08-26T15:13:47.142Z with zero errors, while PostgreSQL, R2, shared jobs, cleanup, and every queue remained healthy. The production dashboard now includes the durable billing gauges, and both database-backed billing alerts evaluated zero/Normal at 2026-08-26T15:49:29Z.
Stripe sandbox reconciliation-drift acceptance passed August 26, 2026.The staging webhook was temporarily disabled for only disposable subscription sub_1U8jC4Fpv5juia6iu2Oqqh0v, which was canceled immediately in Stripe while InstaFile intentionally remained stale on Pro. Protected targeted reconciliation completed at 2026-08-26T16:02:03.193Z with one account checked, one changed, and zero errors, returning the account to Free. The webhook was restored to Active; PostgreSQL, R2, shared jobs, and empty queues remained healthy with zero review accounts and zero unresolved webhook failures. The disposable account was permanently deleted, and a fresh staging page showed no authenticated session or account controls.
Production retention and cost follow-up passed August 26, 2026.Cloudflare still showed both enabled one-day deletion rules, disabled public bucket access, and an empty 0 B production bucket after the acceptance fixtures had aged out or been removed. Railway PostgreSQL showed PITR coverage through 2026-08-26 15:07, a current 1.23 GB daily backup, four prior daily backups, and restore controls. Grafana reported $0 current billable usage, $0 plan cost, and $0 overages with 12 trial days remaining and no paid observability usage. Railway compute usage was $2.88 with a $5.79 estimate after the owner-approved $75 site-stopping compute hard limit was saved; the $20 compute email warning remains active. Replicate showed $0 current-month usage, $4.22 prepaid credit, and auto-reload disabled. The owner chose to disable AI Enhance for launch: production has no provider token, reports aiAvailable: false, and the launch code adds a separate default-off feature flag so a token alone cannot enable it.
1

Required

Prepare production promotion

  1. Keep one production API replica through the final launch gate.

    Production accounts, shared jobs, private object storage, five worker lanes, live direct-upload smoke, the production rollback drill, and application monitoring have passed. Keep one API replica and retain the legacy rollback volume until the remaining account and billing checks, cross-browser checks, and final representative-lane smoke tests pass.

2

Railway

Finish core production configuration

  1. Retain the protected SQLite rollback source.

    Keep the August 22 pre-migration volume backup and the original volume through the approved rollback window. Do not detach or delete the volume until the volume-free staging deployment and PostgreSQL incident procedure are accepted.

  2. Keep PostgreSQL recovery current.

    Daily volume backups, point-in-time recovery, the isolated restore drill, and the August 22 post-migration manual backup are complete. The August 26 follow-up confirmed current PITR coverage, five visible daily backups, and restore controls. Repeat a restore check before removing the legacy volume.

3

Accounts

Verify real account providers

  1. Complete the remaining Google Identity acceptance.

    The dedicated instafile-production-2026 project, verified InstaFile branding, public audience, exact https://www.instafile.net JavaScript origin, Railway public client ID, production deployment, and owner-account desktop login, logout, and relogin passed on August 25, 2026. Before launch, use a separate disposable Google account—never the owner account—to test new signup, matching-Gmail linking, deploy persistence, conflicting-link rejection, full deletion, iPhone Safari, and Android Chrome.

4

Billing

Create products and activate subscriptions

  1. Finish the Stripe business account.

    Complete identity, payout, business-address, support, refund, statement-descriptor, tax, and live-mode requirements.

  2. Promote the approved prices to live mode after business approval.

    The launch model is a free watermarked preview, a $0.99 one-time purchase for that exact clean SVG, and a $4.99/month Pro subscription with unlimited ordinary manual vectorization and all Pro batch benefits. After Stripe approves the business account, create matching live-mode Prices rather than copying test-mode IDs.

  3. Add live billing secrets and display labels.

    Production needs the live PULPIMG_STRIPE_SECRET_KEY, Pro and vector-download Price IDs, matching public labels, public origin, approved automatic-tax setting, a separate long PULPIMG_BILLING_ADMIN_TOKEN, and scheduled reconciliation. The production server refuses to start with a live Stripe key unless the full safety bundle and entitlement enforcement are configured together.

  4. Decide the failed-payment and refund rules.

    Approve zero-day suspension or a short PULPIMG_BILLING_GRACE_DAYS window. Approve how support handles single-download refunds, subscription refunds, partial refunds, and disputes; the code revokes the refunded result after a full one-time refund and conservatively flags ambiguous cases for review.

  5. Register the signed webhook.

    Point Stripe to https://www.instafile.net/api/v1/billing/webhook. Subscribe to completed and asynchronous-success Checkout, subscription and invoice lifecycle, charge.refunded, and dispute-created/closed events, then add PULPIMG_STRIPE_WEBHOOK_SECRET.

  6. Configure the live hosted customer portal.

    The test-mode portal passed subscription, payment-method, invoice, paid-period cancellation, and immediate-cancellation acceptance. Mirror the accepted cancellation, payment-method, invoice, and intended plan-change settings in live mode.

  7. Run final live-mode billing acceptance.

    The complete three-level offer passed Stripe sandbox acceptance on staging. Existing test-mode evidence also covers the Pro portal, renewal, failed-payment recovery, cancellation, disputes, account deletion, reconciliation, and alerts. Repeat the critical money paths with the approved live products and a real low-value payment before public checkout is enabled.

5

Product rules

Turn on the approved limits with live billing

  1. Plan limits approved and published.

    The Plans page publishes every Free and Pro server batch and daily-job allowance. Free accounts receive one watermarked vector preview per job and three per UTC day. Pro receives 12 images per job and 200 submitted vector jobs per UTC day; expensive video, GIF, PDF, capture, import, upscale, and general image limits are bounded separately.

  2. Set PULPIMG_ENTITLEMENTS_ENFORCED=1.

    Do this only after live billing, account email, the plan page, and webhook processing pass end-to-end tests.

  3. Verify the intended rules.

    Large general-purpose server batches require Pro. Vectorization requires an account. Free receives the published watermarked previews; a one-time purchase unlocks only the exact clean SVG named at Checkout; active Pro removes the per-result charge and raises the vector batch and daily limits. Queue, concurrency, daily fair-use, file-size, and anti-automation controls still apply.

6

Scale

Maintain production shared processing

  1. Keep the R2 bucket private and rotate its credential.

    The dedicated Standard bucket, bucket-scoped token, disabled public access, exact production/staging PUT CORS, and enabled one-day uploads//jobs/ lifecycle rules are configured. The August 26 follow-up found the production bucket empty after the acceptance fixtures had aged out or been removed. Rotate the token on schedule and remove the staging origin if staging is retired.

  2. Back up the production job-token secret.

    The long secret is stored and hidden in Railway and production health reports tokenConfigured: true. Copy it once into the approved password manager, restrict access, and document the rotation procedure before sealing it in Railway.

7

Operations

Maintain production monitoring

  1. Review Grafana Cloud Free usage again before the trial ends.

    The private metrics-only collector, six protected targets, six health probes, production dashboard, owner email contact, and all nine permanent alert rules are live. The first follow-up review reported $0 current billable usage, $0 plan cost, $0 overages, and no paid product usage with 12 trial days remaining. Before the trial ends, confirm the account falls back to Free and active-series usage remains within the free allowance.

  2. Approve latency thresholds.

    The reviewed launch alerts cover health, metrics loss, queue backlog and rejection, job failure or retry, billing-webhook errors, any durable unresolved Stripe event, and any account requiring billing review; Railway separately covers deployment failure, crash, OOM, and usage. The controlled email fire-and-recovery drill and both new billing-state live evaluations passed. After collecting a representative traffic baseline, approve p95 queue-wait and processing-time thresholds and record the response procedure.

  3. Validate browser-local processing.

    On current iPhone Safari, Android Chrome, desktop Safari, Chrome, Firefox, and Edge, verify JPEG/PNG resize, crop, rotate, compression, conversion, download, and workflow handoff. Confirm the Network panel shows no media API upload for supported local operations.

8

Security and cost

Finish provider-side guardrails

  1. Approve the current residual container risk and repeat the review before every release.

    Runs 40 and 41 passed with zero fixable High/Critical findings, and run 41 verified that its complete report contains 111 unique vendor-unfixed High/Critical advisories rather than merely showing 335 repeated package matches. The runbook records which product paths are exposed, the existing isolation and resource limits, and the special no-sandbox Chromium risk on Railway. Before launch, explicitly accept that residual risk or disable the affected feature; rebuild promptly when fixes ship and review every new SARIF report.

  2. Choose log retention and incident contacts.

    Document who receives availability, abuse, security, privacy, billing, and provider-spend alerts and how quickly each class must be handled.

9

Final gate

Complete non-code launch decisions and smoke tests

  1. Complete trademark/name clearance.

    Have a qualified professional assess the InstaFile name and any conflicting document-management marks before investing in promotion.

  2. Approve third-party license obligations.

    Have qualified counsel review the shipped FFmpeg/FFprobe, Ghostscript, PyMuPDF, sharp/libvips, Chromium, fonts, and other SBOM components. Obtain commercial licenses or change the implementation where required; the notices file is an inventory, not clearance.

  3. Identify the legal seller and governing terms.

    Add the contracting entity, business/contact address, governing jurisdiction, dispute forum, and any legally required subscription or cancellation disclosures before public paid checkout.

  4. Review privacy and vendor obligations.

    Confirm the final Privacy Policy and Terms with qualified counsel, execute any required data-processing agreements, and verify provider regions and retention settings for Railway, Cloudflare, Stripe, Resend, Google, PostgreSQL, object storage, and monitoring.

  5. Approve pricing, refunds, taxes, and support promises.

    Make sure the live checkout, plan page, Terms, Privacy Policy, and customer support process say the same thing.

  6. Finish the final production smoke test.

    Production health, homepage, the branded browser-facing 404 and JSON non-browser fallback, desktop email-code and Google login, direct R2 upload, one-attempt image/PDF/GIF/video/capture/import worker jobs, the legacy multipart fallback, feature restoration, zero-queue verification, protected metrics, the Grafana dashboard, a controlled alert fire-and-recovery drill, and current backup visibility passed. Stripe test-mode staging also passed the complete three-level vector offer, the published 12-image Pro vector batch, Pro renewal, failed-payment suspension and recovery, subscription cancellation, refunds, disputes, active-subscription account deletion, and controlled reconciliation-drift correction. Still test mobile accounts, disposable-account Google linking and deletion, and live-mode checkout and account deletion.

Implemented in code

What you do not need to build manually

Last updated August 26, 2026