Extending
Configuration
Configuration is validated before anything boots. A malformed value stops the process immediately rather than failing halfway through startup.
Environment variables
PORTnumberDefaults to 4000. Must be 1–65535; non-numeric values are rejected.
NODE_ENV"production" | "development" | "test"Defaults to development.
STORAGE_SECRETstringSigns storage URLs. Required when NODE_ENV=production. Outside production a temporary secret is generated and a warning is logged.
DATABASE_URLstringSQLite file path. Defaults to Database/app.db.
AUTH_SECRETstringSign and verify auth tokens. Set this explicitly in production.
APP_URLstringUsed in verification links and the WebAuthn origin.
Validation
Values are checked at boot. A problem stops the process with a readable message rather than surfacing later as a confusing error.
EnvValidationError: Invalid environment configuration: - PORT must be a number, received "4000abc" - STORAGE_SECRET is required when NODE_ENV=productionWarning
An ephemeral
STORAGE_SECRET invalidates every signed URL on restart. In production this fails startup instead — which is the behaviour you want.Health probes
Two endpoints, served before anything else so they stay responsive under load.
GET /healthz → 200 { "status": "ok" } GET /readyz → 200 { "status": "ready", "topology": { "cpuCores": 2, "cpuWorkers": 1, "ioWorkers": 2, "totalWorkers": 3 }, "inFlightTasks": 0 } → 503 when the fleet has no workersNote
Liveness never touches the runtime. If readiness were used as a liveness signal, a busy worker pool would make the orchestrator kill a perfectly healthy process.
Security headers
Applied to every routed response:
X-Content-Type-Options: nosniffX-Frame-Options: DENYReferrer-Policy: strict-origin-when-cross-originX-XSS-Protection: 0Strict-Transport-Security: max-age=31536000; includeSubDomains ← HTTPS onlyNote
HSTS is sent only over real HTTPS — including when a proxy forwards
x-forwarded-proto: https. Sending it over plain HTTP can lock a local development origin out of the browser.Storage secrets
Generating one for development is convenient, but generate a real one for anything shared:
openssl rand -hex 32