Production Deployment
Lasso is a standard Elixir/Phoenix release. It runs anywhere you can deploy an OTP release: containers, VMs, bare metal, or PaaS platforms.Building a Release
Dockerfile.
Production environment variables
Provider API Keys
Provider URLs in profile YAML support${ENV_VAR} substitution. Unresolved placeholders crash at startup.
Health Check
Core v0.5.0 exposesGET /api/health for application liveness and
GET /api/ready for route readiness. Configure your orchestrator to use
health for process availability. Scope readiness with profile and chain
when a load balancer needs to assess one application route.
The health endpoint confirms that the application is running and reports cluster
topology. Readiness uses local eligible HTTP routes and fresh head observations;
it does not make a live upstream request. Pair both endpoints with an
upstream-backed RPC check for your actual method and provider pool.
HTTPS
Lasso serves HTTP. Terminate TLS at your reverse proxy or load balancer. SetPHX_HOST to your public hostname. Production URL generation defaults to HTTPS; set PHX_SCHEME=http when serving locally without a TLS proxy.
Production Checklist
-
SECRET_KEY_BASEset (64+ bytes) -
PHX_HOSTset to public hostname - HTTP server responds to
GET /api/health - Intended profile and chain respond to
GET /api/ready?profile=...&chain=...after head observation warms -
LASSO_NODE_IDset to a unique, stable value - Provider credentials set when referenced by profile configuration
- Health check (
GET /api/health) monitored by orchestrator - Profile YAML validated with
bin/lasso check-configbeforebin/lasso reload; unresolved${ENV_VAR}prevents readiness at cold start - Client request limits enforced at the reverse proxy; profile rate settings only configure the dashboard tester
- TLS terminated at reverse proxy / load balancer
- Console log drain configured; set
LOG_FORMAT=jsonif your collector requires JSON - Each node’s
GET /metricsscrape restricted to the collector and labeled by instance - RPC and dashboard protected by reverse-proxy authentication or a private network boundary (Lasso OSS has no built-in client authentication)
- If clustering: named nodes, shared cookie, DNS discovery, and private distribution connectivity configured; peers visible in
Node.list()