Solutions · Production readiness

Know the stack is ready before you ship

Tests check your code. They don't check that production's webhook exists and verifies signatures, that the auth provider allows your production URL, or that a test key isn't in production. Ahena checks the external stack your code depends on, and can block a deploy that isn't ready.

What breaks on launch day

The failures that tests and code review don't catch:

  • A webhook endpoint that's missing, disabled, or accepts unsigned requests.
  • A production redirect or site URL the auth provider doesn't allow.
  • A test-mode key in production, or a production secret that was never stored.
  • A sending domain whose DNS records were never verified.
  • A credential that expired or lost a permission.

What Ahena checks

  1. Doctor

    ahena doctor runs each connected provider's checks against its real state (credentials and permissions, configuration, webhooks, domains, CORS, migrations and more, per provider) plus environment separation and required secrets. Every finding says what's wrong and how to fix it.

  2. A deploy gate

    ahena deploy-check runs Doctor for one environment, plus drift against ahena.lock, and exits 1 when it isn't ready to deploy, with each blocker labelled.

  3. In CI

    ahena ci init writes a GitHub Actions workflow that runs the check with a read-only, project-scoped token.

  4. Fixes through plans

    Findings Ahena can fix become a plan you approve (ahena doctor --fix); the rest list the exact manual steps.

What deploy-check reports

BlockerTypical cause
missing production secretA secret the app needs isn't stored
invalid provider credentialsA key was revoked, expired or lacks permissions
configuration driftA high-severity value changed outside Ahena
broken webhookEndpoint missing, disabled, or accepting unsigned requests
development credential in productionA test-mode key configured in production
missing OAuth callbackProduction redirect or site URL not allowed
missing providerThe app needs a provider that isn't connected

Before a release

$ ahena doctor -e production
$ ahena deploy-check --environment production # exit code 1 if it isn't ready
$ ahena ci init # the same check on every push

Good to know

  • Ahena checks provider configuration, not your application: it doesn't test your code or guarantee it has no bugs.
  • Checks vary by provider; each integration page lists its Doctor checks.
  • Warnings don't fail deploy-check unless you pass --strict.

Questions

How do I verify provider configuration before deployment?

Run ahena doctor -e production to check each connected provider's real configuration, and add ahena deploy-check --environment production to CI so a deploy fails when a required secret, webhook, redirect URL or credential isn't right.