Docs

govbase.dev production deployment

govbase.dev production deployment

Intended production architecture for AIGov on govbase.dev. Topology JSON: ../../hosted-saas/govbase-production-topology.json.

Architecture overview#

                    ┌─────────────────────┐
                    │  govbase.dev        │
                    │  (Vercel dashboard) │
                    │  /, /docs, /help    │
                    │  /login, console    │
                    └──────────┬──────────┘
                               │ HTTPS
                               ▼
                    ┌─────────────────────┐
                    │ audit.govbase.dev   │
                    │ Rust audit API      │
                    │ /health /ready      │
                    └──────────┬──────────┘
                               │
                               ▼
                    ┌─────────────────────┐
                    │ Managed Postgres    │
                    │ ledger + tenants    │
                    └─────────────────────┘

Surfaces#

SurfaceURLNotes
Marketing and dashboardhttps://govbase.devNext.js dashboard/
Documentationhttps://govbase.dev/docsCanonical docs/*.md
Help centerhttps://govbase.dev/helpOperator guides
Hosted audit APIhttps://audit.govbase.devEvidence ingest and summaries
Tenant consolehttps://govbase.dev/tenant-consoleSnapshot-driven UI
Onboardinghttps://govbase.dev/onboardingLive checklist backed by tenant_onboarding_progress

Environment variables#

Dashboard (Vercel)#

VariablePurpose
NEXT_PUBLIC_SITE_URLhttps://govbase.dev
NEXT_PUBLIC_GOVAI_API_BASE_URLhttps://audit.govbase.dev
AIGOV_AUDIT_URLServer-side audit fetches
GOVAI_DATABASE_URLFirst-party email/password and OAuth user storage (same database as audit migrations)
GOVAI_DASHBOARD_JWT_SECRETShared HS256 signing secret; must match the audit API
GOVAI_DASHBOARD_JWT_ISSUEROptional issuer; defaults to govai-dashboard

Audit API#

VariablePurpose
DATABASE_URLPostgres connection
GOVAI_BASE_URLCanonical public URL in /status
GOVAI_DASHBOARD_JWT_SECRETSame HS256 secret as the dashboard
GOVAI_DASHBOARD_JWT_ISSUERSame issuer as the dashboard
GOVAI_STRIPE_SECRET_KEYOptional billing
GOVAI_STRIPE_WEBHOOK_SECRETOptional webhooks

See also ../hosted-backend-deployment.md and ../env-resolution.md.

Production secrets#

Store in the operator secret manager; rotate at least every 90 days. Never commit .env with production values.

Database#

Managed Postgres with TLS, RLS per tenant, and automated backups (see backup-and-disaster-recovery.md).

Monitoring#

  • Liveness: GET https://audit.govbase.dev/health
  • Readiness: GET https://audit.govbase.dev/ready
  • Metrics: GET https://audit.govbase.dev/metrics

Backups#

Follow backup-and-disaster-recovery.md. Verify restore in staging each quarter.

Signup-to-ready flow#

  1. User signs in on govbase.dev with first-party email/password or Google/GitHub OAuth. The dashboard issues an API JWT using the shared secret.
  2. Dashboard calls POST /api/tenants on audit.govbase.dev with the access token.
  3. Audit API provisions tenant, team, ledger binding, billing row, onboarding steps, and optional API key.
  4. User completes /onboarding; progress is stored in tenant_onboarding_progress.
  5. Integrations use the issued API key against /evidence and /compliance-summary (hash-resolved tenant scope).

Legacy pilots may still set GOVAI_API_KEYS / GOVAI_API_KEYS_JSON; provisioned keys in tenant_api_keys work without adding plaintext to env.

Deployment checklist#

  • NEXT_PUBLIC_SITE_URL and GOVAI_BASE_URL match public DNS
  • Migrations applied through 0022_tenant_registry.sql (sqlx migrate or GOVAI_AUTO_MIGRATE)
  • /ready green on audit origin
  • Stripe webhooks registered when billing enabled
  • WAF / rate limits configured at edge
  • make hosted-saas-readiness-check passes in CI
  • On-call rotation and status page configured

Signed in, but hosted API access is unavailable#

This message means the dashboard session has no audit API Bearer token. Signing in again cannot repair a missing signing secret. Check both deployment configuration and the session; do not bypass LegalEntitlementGuard on the hosted service.

  1. Set NEXT_PUBLIC_GOVAI_API_BASE_URL=https://audit.govbase.dev in the Vercel Production environment. Configure Preview separately for staging.
  2. Set GOVAI_DASHBOARD_JWT_SECRET to the same securely generated secret on the dashboard and audit server, separately for each environment. Never commit it or use a production development-token fallback.
  3. Redeploy both services. The public API URL is compiled into the browser bundle.
  4. Sign out and sign in again, then verify the commercial status request and /runs with an entitled tenant. A healthy /health endpoint alone does not establish JWT or tenant access.

Production OAuth and password sign-in now check the public API URL and resolved access token before creating the session. An unconfigured deployment returns an administrator configuration error instead of redirecting to an unusable console. Local development and explicitly configured AIGOV_SELF_HOSTED_NO_BILLING=true deployments retain their user-only session behavior. This flag is not a repair for hosted SaaS and must not be enabled to bypass billing or legal acceptance.

← Back to home