Production launch
Staging validates features on a raw IP. Production uses the io deploy profile (see config/deploy.io.yml).
Quick preflight
bin/prepare-prod --check-only # secrets + 2-box topology checklist
bin/go-live # DNS, HTTPS, Stripe, SMTP, registry, app domain
First customers on the same staging boxes: see PRODUCTION-FIRST-CUSTOMERS.md.
Fix any ✗ items, then follow the runbook below.
Runbook (ordered)
1. Secrets on your workstation
Edit .kamal/secrets (copy from .kamal/secrets.example). Required for managed hosting:
| Variable | Purpose |
|---|---|
TYCOONBOX_PRODUCTION_IP |
Panel server IP |
KAMAL_REGISTRY_PASSWORD |
Customer image push |
TYCOONBOX_PLATFORM_APPS_HOST_IP |
Apps host (wildcard DNS target) |
TYCOONBOX_APP_DOMAIN |
e.g. apps.tycoonbox.io |
Sync to the io host:
bin/kamal-secrets-sync io
2. DNS (Cloudflare — grey cloud / DNS only)
| Record | Value |
|---|---|
| A | tycoonbox.io → TYCOONBOX_PRODUCTION_IP |
| CNAME | www → tycoonbox.io (optional) |
| A or wildcard | *.apps.tycoonbox.io → apps host IP |
Re-run bin/go-live until DNS and HTTPS pass.
3. Stripe billing
bin/stripe-setup
Adds STRIPE_SECRET_KEY, price IDs, and webhook secret to secrets. Re-sync:
bin/kamal-secrets-sync io
Webhook endpoint: https://tycoonbox.io/webhooks/stripe
4. Transactional email
bin/smtp-setup
Sets MAILBIRD_SMTP_PASSWORD for beta invites, password reset, deploy notifications.
5. Optional integrations
| Integration | Command / env |
|---|---|
| Beta signup alerts | bin/webhook-setup → BETA_SIGNUP_WEBHOOK_URL |
| Google sign-in | TYCOONBOX_GOOGLE_CLIENT_ID + TYCOONBOX_GOOGLE_CLIENT_SECRET in .kamal/secrets (auto-enabled when both are set; set TYCOONBOX_GOOGLE_OAUTH=false to hide). In Google Cloud, authorized redirect URI: https://tycoonbox.io/auth/google/callback |
| Admin beta queue | TYCOONBOX_ADMIN_TOKEN — openssl rand -hex 24 |
| Invite-only launch | TYCOONBOX_OPEN_REGISTRATION=false on io |
6. Publish sample app repos (production git URLs)
Staging ships demos from the panel image. Production should clone public GitHub repos:
bin/publish-demos 21tycoons # gh auth login, or GITHUB_TOKEN=ghp_...
# or init only (manual push):
bin/publish-demos 21tycoons --init-only
Verify:
bin/verify-demo-repos 21tycoons
Set on the io host if needed: TYCOONBOX_DEMO_GIT_BASE=https://github.com/21tycoons
7. Deploy production
bin/io-deploy
Runs secrets sync, production deploy, and db:migrate.
8. Smoke test
- https://tycoonbox.io/up → 200
- Settings → Production launch checklist — all required ✓
- Dashboard → Deploy sample app → pick a stack → live URL +
/up - https://tycoonbox.io/beta/new?source=launch
Panel checklist
Admins see Settings → Production launch checklist — mirrors bin/go-live with links to this guide and setup scripts.
URLs
| URL | Purpose |
|---|---|
| https://tycoonbox.io | Marketing + panel |
| https://tycoonbox.io/beta/new | Beta signup |
| https://tycoonbox.io/admin/beta_signups | Admin (TYCOONBOX_ADMIN_TOKEN) |
| https://tycoonbox.io/embed/beta | Embeddable signup iframe |
Interim branded URL (before tycoonbox.io)
Point tycoonbox.21tycoons.dev A → production IP, then:
bin/interim-deploy
See Staging deploy for IP-based validation — not used for production GTM.