Owner checklist
What still requires your action before launch
This page tracks only the remaining provider setup, staging validation, business decisions, and launch checks. Completed production work is recorded below so it is not accidentally repeated.
www host and HTTPS apex redirect are live./health; direct uploads and async jobs are enabled. A real 52.8 KB video completed through direct R2 upload and the video worker with HTTP 200 on one attempt. The production rollback drill then disabled both features, completed the same conversion through legacy multipart with HTTP 200, restored both features, and completed another direct-R2 worker job with HTTP 200 on one attempt. Final health was ok with zero uploading, queued, or running jobs.InstaFile Production dashboard and all nine permanent alert rules are live. The owner email contact point, default route, and test notification passed. A safe simulated Resend bounce moved the permanent email rule from Normal to Firing and back to Normal. On August 26, the deployed unresolved-webhook and billing-review gauges both returned zero; rules bfwcyxjbkouf4b and ffwcyz5w8h2pse then completed live production evaluations in the Normal state with the owner-email route intact.2026-08-24T17:37:46.247Z with no error; PostgreSQL, R2, and empty shared queues remained healthy through the post-run stability check.048a9e6, including the origin-lock regression and container vulnerability gates, before Railway promoted all seven services. The canonical www record is proxied, Cloudflare overwrites a secret origin header, and its active Free-plan burst rule blocks more than 10 POSTs in 10 seconds across remote import, webpage capture, vectorization, and upscale. A fake client-supplied secret was overwritten and the public homepage, auth config, and health remained HTTP 200. A direct Railway request with the production Host header returned HTTP 403, including with a spoofed CF-Connecting-IP; direct /health remained HTTP 200 and unauthenticated /metrics remained HTTP 401. PostgreSQL, R2, shared jobs, and all queues were healthy and empty. The Free plan does not include Cloudflare's managed ruleset, so the application quotas, worker limits, provider budgets, and container security gate remain the documented compensating controls.967a201, built the Bookworm production image with Chromium 151.0.7922.173 or newer enforced, removed the two fixable pypdf findings, and reported zero fixable High/Critical findings. The complete report's 335 High/Critical package matches reduce to 111 unique advisories; unresolved media and browser findings remain and are not being hidden. Run 41 then passed the duplicate-advisory reporting regression and the same complete production scan for commit 49829a8. FFmpeg/FFprobe inputs are restricted to local files and pipes, workers are private and resource-bounded, and two real production webpage captures completed in 3.248s and 2.995s. All seven Railway services are Online on the run 41 release; PostgreSQL, R2, shared jobs, and empty queues are healthy. The detailed reachable/unreachable review is in the deployment runbook. Owner risk approval and a fresh review before every release are still required.ok with PostgreSQL, R2, and shared jobs healthy and zero uploading, queued, or running jobs. Vectorization remains intentionally separate because billing acceptance must verify the locked Free preview, exact-result purchase, and Pro unlimited paths.b745632, and Railway ran the staging API and worker Online on that exact commit. A Free account received a watermarked PNG while its clean SVG remained locked; a real $0.99 Stripe sandbox Checkout unlocked only that exact result, whose two repeat downloads were identical. Canceled Checkout granted nothing, a full refund relocked only the purchased result, and a $0.50 partial refund relocked paid access, placed the disposable account under review, and blocked another Checkout with HTTP 409. An active $4.99/month Pro account then created job b0d7304e-d518-4555-a262-55e3cfa42847 with the SVG immediately unlocked and downloadable without a per-image payment. The same account also completed the full published 12-image Pro batch in one attempt: all 12 SVGs were unlocked, valid, and downloadable after 12.2 seconds. Both disposable purchase accounts were deleted afterward; staging returned to zero review accounts and webhook failures with PostgreSQL, R2, shared jobs, and every queue healthy.sub_1U8i2pFpv5juia6idQ3wcQz1 renewed successfully once, then invoice AYHTMSEV-0003 failed on Stripe’s renewal-decline card. Stripe became past_due and staging immediately changed the account to Free with no grace period and no unlimited vector entitlement. Retrying that exact invoice on the valid card made it Paid and restored active Pro and unlimited vectorization. Deleting the disposable account returned HTTP 200, canceled the active sandbox subscription, invalidated the old session, and removed the account. All 15 signed billing webhooks returned 2xx; the protected failure and review queues were empty. A protected manual reconciliation completed at 2026-08-26T15:13:47.142Z with zero errors, while PostgreSQL, R2, shared jobs, cleanup, and every queue remained healthy. The production dashboard now includes the durable billing gauges, and both database-backed billing alerts evaluated zero/Normal at 2026-08-26T15:49:29Z.sub_1U8jC4Fpv5juia6iu2Oqqh0v, which was canceled immediately in Stripe while InstaFile intentionally remained stale on Pro. Protected targeted reconciliation completed at 2026-08-26T16:02:03.193Z with one account checked, one changed, and zero errors, returning the account to Free. The webhook was restored to Active; PostgreSQL, R2, shared jobs, and empty queues remained healthy with zero review accounts and zero unresolved webhook failures. The disposable account was permanently deleted, and a fresh staging page showed no authenticated session or account controls.0 B production bucket after the acceptance fixtures had aged out or been removed. Railway PostgreSQL showed PITR coverage through 2026-08-26 15:07, a current 1.23 GB daily backup, four prior daily backups, and restore controls. Grafana reported $0 current billable usage, $0 plan cost, and $0 overages with 12 trial days remaining and no paid observability usage. Railway compute usage was $2.88 with a $5.79 estimate after the owner-approved $75 site-stopping compute hard limit was saved; the $20 compute email warning remains active. Replicate showed $0 current-month usage, $4.22 prepaid credit, and auto-reload disabled. The owner chose to disable AI Enhance for launch: production has no provider token, reports aiAvailable: false, and the launch code adds a separate default-off feature flag so a token alone cannot enable it.Required
Prepare production promotion
- Keep one production API replica through the final launch gate.
Production accounts, shared jobs, private object storage, five worker lanes, live direct-upload smoke, the production rollback drill, and application monitoring have passed. Keep one API replica and retain the legacy rollback volume until the remaining account and billing checks, cross-browser checks, and final representative-lane smoke tests pass.
Railway
Finish core production configuration
- Retain the protected SQLite rollback source.
Keep the August 22 pre-migration volume backup and the original volume through the approved rollback window. Do not detach or delete the volume until the volume-free staging deployment and PostgreSQL incident procedure are accepted.
- Keep PostgreSQL recovery current.
Daily volume backups, point-in-time recovery, the isolated restore drill, and the August 22 post-migration manual backup are complete. The August 26 follow-up confirmed current PITR coverage, five visible daily backups, and restore controls. Repeat a restore check before removing the legacy volume.
Accounts
Verify real account providers
- Complete the remaining Google Identity acceptance.
The dedicated
instafile-production-2026project, verified InstaFile branding, public audience, exacthttps://www.instafile.netJavaScript origin, Railway public client ID, production deployment, and owner-account desktop login, logout, and relogin passed on August 25, 2026. Before launch, use a separate disposable Google account—never the owner account—to test new signup, matching-Gmail linking, deploy persistence, conflicting-link rejection, full deletion, iPhone Safari, and Android Chrome.
Billing
Create products and activate subscriptions
- Finish the Stripe business account.
Complete identity, payout, business-address, support, refund, statement-descriptor, tax, and live-mode requirements.
- Promote the approved prices to live mode after business approval.
The launch model is a free watermarked preview, a $0.99 one-time purchase for that exact clean SVG, and a $4.99/month Pro subscription with unlimited ordinary manual vectorization and all Pro batch benefits. After Stripe approves the business account, create matching live-mode Prices rather than copying test-mode IDs.
- Add live billing secrets and display labels.
Production needs the live
PULPIMG_STRIPE_SECRET_KEY, Pro and vector-download Price IDs, matching public labels, public origin, approved automatic-tax setting, a separate longPULPIMG_BILLING_ADMIN_TOKEN, and scheduled reconciliation. The production server refuses to start with a live Stripe key unless the full safety bundle and entitlement enforcement are configured together. - Decide the failed-payment and refund rules.
Approve zero-day suspension or a short
PULPIMG_BILLING_GRACE_DAYSwindow. Approve how support handles single-download refunds, subscription refunds, partial refunds, and disputes; the code revokes the refunded result after a full one-time refund and conservatively flags ambiguous cases for review. - Register the signed webhook.
Point Stripe to
https://www.instafile.net/api/v1/billing/webhook. Subscribe to completed and asynchronous-success Checkout, subscription and invoice lifecycle,charge.refunded, and dispute-created/closed events, then addPULPIMG_STRIPE_WEBHOOK_SECRET. - Configure the live hosted customer portal.
The test-mode portal passed subscription, payment-method, invoice, paid-period cancellation, and immediate-cancellation acceptance. Mirror the accepted cancellation, payment-method, invoice, and intended plan-change settings in live mode.
- Run final live-mode billing acceptance.
The complete three-level offer passed Stripe sandbox acceptance on staging. Existing test-mode evidence also covers the Pro portal, renewal, failed-payment recovery, cancellation, disputes, account deletion, reconciliation, and alerts. Repeat the critical money paths with the approved live products and a real low-value payment before public checkout is enabled.
Product rules
Turn on the approved limits with live billing
- Plan limits approved and published.
The Plans page publishes every Free and Pro server batch and daily-job allowance. Free accounts receive one watermarked vector preview per job and three per UTC day. Pro receives 12 images per job and 200 submitted vector jobs per UTC day; expensive video, GIF, PDF, capture, import, upscale, and general image limits are bounded separately.
- Set
PULPIMG_ENTITLEMENTS_ENFORCED=1.Do this only after live billing, account email, the plan page, and webhook processing pass end-to-end tests.
- Verify the intended rules.
Large general-purpose server batches require Pro. Vectorization requires an account. Free receives the published watermarked previews; a one-time purchase unlocks only the exact clean SVG named at Checkout; active Pro removes the per-result charge and raises the vector batch and daily limits. Queue, concurrency, daily fair-use, file-size, and anti-automation controls still apply.
Scale
Maintain production shared processing
- Keep the R2 bucket private and rotate its credential.
The dedicated Standard bucket, bucket-scoped token, disabled public access, exact production/staging
PUTCORS, and enabled one-dayuploads//jobs/lifecycle rules are configured. The August 26 follow-up found the production bucket empty after the acceptance fixtures had aged out or been removed. Rotate the token on schedule and remove the staging origin if staging is retired. - Back up the production job-token secret.
The long secret is stored and hidden in Railway and production health reports
tokenConfigured: true. Copy it once into the approved password manager, restrict access, and document the rotation procedure before sealing it in Railway.
Operations
Maintain production monitoring
- Review Grafana Cloud Free usage again before the trial ends.
The private metrics-only collector, six protected targets, six health probes, production dashboard, owner email contact, and all nine permanent alert rules are live. The first follow-up review reported $0 current billable usage, $0 plan cost, $0 overages, and no paid product usage with 12 trial days remaining. Before the trial ends, confirm the account falls back to Free and active-series usage remains within the free allowance.
- Approve latency thresholds.
The reviewed launch alerts cover health, metrics loss, queue backlog and rejection, job failure or retry, billing-webhook errors, any durable unresolved Stripe event, and any account requiring billing review; Railway separately covers deployment failure, crash, OOM, and usage. The controlled email fire-and-recovery drill and both new billing-state live evaluations passed. After collecting a representative traffic baseline, approve p95 queue-wait and processing-time thresholds and record the response procedure.
- Validate browser-local processing.
On current iPhone Safari, Android Chrome, desktop Safari, Chrome, Firefox, and Edge, verify JPEG/PNG resize, crop, rotate, compression, conversion, download, and workflow handoff. Confirm the Network panel shows no media API upload for supported local operations.
Security and cost
Finish provider-side guardrails
- Approve the current residual container risk and repeat the review before every release.
Runs 40 and 41 passed with zero fixable High/Critical findings, and run 41 verified that its complete report contains 111 unique vendor-unfixed High/Critical advisories rather than merely showing 335 repeated package matches. The runbook records which product paths are exposed, the existing isolation and resource limits, and the special no-sandbox Chromium risk on Railway. Before launch, explicitly accept that residual risk or disable the affected feature; rebuild promptly when fixes ship and review every new SARIF report.
- Choose log retention and incident contacts.
Document who receives availability, abuse, security, privacy, billing, and provider-spend alerts and how quickly each class must be handled.
Final gate
Complete non-code launch decisions and smoke tests
- Complete trademark/name clearance.
Have a qualified professional assess the InstaFile name and any conflicting document-management marks before investing in promotion.
- Approve third-party license obligations.
Have qualified counsel review the shipped FFmpeg/FFprobe, Ghostscript, PyMuPDF, sharp/libvips, Chromium, fonts, and other SBOM components. Obtain commercial licenses or change the implementation where required; the notices file is an inventory, not clearance.
- Identify the legal seller and governing terms.
Add the contracting entity, business/contact address, governing jurisdiction, dispute forum, and any legally required subscription or cancellation disclosures before public paid checkout.
- Review privacy and vendor obligations.
Confirm the final Privacy Policy and Terms with qualified counsel, execute any required data-processing agreements, and verify provider regions and retention settings for Railway, Cloudflare, Stripe, Resend, Google, PostgreSQL, object storage, and monitoring.
- Approve pricing, refunds, taxes, and support promises.
Make sure the live checkout, plan page, Terms, Privacy Policy, and customer support process say the same thing.
- Finish the final production smoke test.
Production health, homepage, the branded browser-facing 404 and JSON non-browser fallback, desktop email-code and Google login, direct R2 upload, one-attempt image/PDF/GIF/video/capture/import worker jobs, the legacy multipart fallback, feature restoration, zero-queue verification, protected metrics, the Grafana dashboard, a controlled alert fire-and-recovery drill, and current backup visibility passed. Stripe test-mode staging also passed the complete three-level vector offer, the published 12-image Pro vector batch, Pro renewal, failed-payment suspension and recovery, subscription cancellation, refunds, disputes, active-subscription account deletion, and controlled reconciliation-drift correction. Still test mobile accounts, disposable-account Google linking and deletion, and live-mode checkout and account deletion.
Implemented in code
What you do not need to build manually
- Structured capacity telemetry and protected Prometheus metrics
- Cold-checkout-safe smoke and production-representative load suites
- A guarded, one-job-at-a-time production lane runner with direct-R2 and output-signature verification
- Feature-flagged PostgreSQL accounts and usage, shared sessions/throttles/quotas, guarded SQLite migration, verification, and rollback compatibility
- Account-aware daily limits, subscription batch gates, locked Free vector previews, exact-result purchase access, and unlimited Pro vectorization
- Stripe Checkout, signed idempotent/out-of-order-safe webhooks, exact-result purchases, refunds/disputes, failed-event recovery, customer portal, scheduled/manual reconciliation, and deletion safeguards
- Browser-local JPEG/PNG resize, crop, rotate, compression, and conversion with server fallback
- Short-lived browser-to-private-bucket uploads with pre-admission, exact size/type verification, reusable-URL isolation, cookie separation, cancellation, and orphan cleanup
- PostgreSQL-backed atomic weighted admission, idempotency, Pro/free priority with anti-starvation aging, optional reserved worker classes, private object storage, crash recovery, and expiry cleanup
- A noindex Jobs page with account history, anonymous browser recovery tickets, filtering, cancellation, downloads, and expired-result guidance
- A disposable PostgreSQL/MinIO integration suite wired as a separate GitHub launch gate
Last updated August 26, 2026