Extending

Configuration

Configuration is validated before anything boots. A malformed value stops the process immediately rather than failing halfway through startup.

Environment variables

PORTnumber
Defaults to 4000. Must be 1–65535; non-numeric values are rejected.
NODE_ENV"production" | "development" | "test"
Defaults to development.
STORAGE_SECRETstring
Signs storage URLs. Required when NODE_ENV=production. Outside production a temporary secret is generated and a warning is logged.
DATABASE_URLstring
SQLite file path. Defaults to Database/app.db.
AUTH_SECRETstring
Sign and verify auth tokens. Set this explicitly in production.
APP_URLstring
Used in verification links and the WebAuthn origin.

Validation

Values are checked at boot. A problem stops the process with a readable message rather than surfacing later as a confusing error.

startup outputtext
EnvValidationError: Invalid environment configuration:  - PORT must be a number, received "4000abc"  - STORAGE_SECRET is required when NODE_ENV=production
Warning
An ephemeral STORAGE_SECRET invalidates every signed URL on restart. In production this fails startup instead — which is the behaviour you want.

Health probes

Two endpoints, served before anything else so they stay responsive under load.

probesjson
GET /healthz  → 200 { "status": "ok" } GET /readyz  → 200 {      "status": "ready",      "topology": {        "cpuCores": 2,        "cpuWorkers": 1,        "ioWorkers": 2,        "totalWorkers": 3      },      "inFlightTasks": 0    }  → 503 when the fleet has no workers
Note
Liveness never touches the runtime. If readiness were used as a liveness signal, a busy worker pool would make the orchestrator kill a perfectly healthy process.

Security headers

Applied to every routed response:

texttext
X-Content-Type-Options: nosniffX-Frame-Options: DENYReferrer-Policy: strict-origin-when-cross-originX-XSS-Protection: 0Strict-Transport-Security: max-age=31536000; includeSubDomains   ← HTTPS only
Note
HSTS is sent only over real HTTPS — including when a proxy forwards x-forwarded-proto: https. Sending it over plain HTTP can lock a local development origin out of the browser.

Storage secrets

Generating one for development is convenient, but generate a real one for anything shared:

terminalbash
openssl rand -hex 32