VibeOps Club / Guides
Production checklist for vibe-coded apps: 30 checks before launch
Your app works on localhost and the agent says it is ready. This checklist covers what the agent usually does not: secrets, data access, its own permissions, backups, cost and visibility. Most sections link to a real incident where skipping it went wrong.
You do not need to be a DevOps engineer to go through it. Most items are a setting, a question to your agent, or a five-minute test. You can paste any section into your agent as a task and then verify the result yourself.
1. Secrets and API keys
- No secret keys in frontend code. Only publishable keys (Supabase anon key, Stripe publishable key) may reach the browser. Service role keys, OpenAI keys and Stripe secret keys stay on the server. Moltbook
- Secrets live in environment variables or your platform's secret store, never in the repository.
.envis in.gitignore. - Secret scanning is on. GitHub push protection, or a pre-commit hook such as gitleaks or trufflehog.
- Leaked keys are rotated. If a key ever appeared in a commit, a screenshot or a chat, issue a new one. Deleting the commit is not enough.
- Each key has one purpose and minimal rights. Separate keys per environment and per service, scoped to what they actually need. PocketOS
In detail: where API keys belong in a vibe-coded app and how to check for leaks.
2. Database and data access
- RLS is enabled on every table (Supabase) with explicit policies for select, insert, update and delete. Lovable
- Test as an anonymous user. Call your API with only the public key and try to read data. You should get nothing.
- Test as the wrong user. Log in as user A and request user B's records by changing the ID in the request.
- Payments, quotas and roles are checked on the server, not only hidden in the UI. EnrichLead
- Storage buckets are private by default. Only truly public files go into public buckets. Tea
3. Agent permissions
- The agent has no production credentials. Production changes go through CI or through you.
- Tokens the agent can see are narrow: read-only where possible, short-lived, limited to one project.
- Destructive actions need a human. Dropping tables, deleting volumes, force-pushing and running migrations in prod require explicit confirmation. Replit
- You review diffs that touch auth, infrastructure config and migrations before they are merged.
In detail: how to give an AI agent access to your infrastructure without losing production.
4. Environments and backups
- Dev and prod are separate: different databases, different keys, different URLs. Replit
- Automatic backups are on and stored where the app's own credentials cannot delete them. PocketOS
- A restore has been tested at least once. Until you have restored from a backup, you do not know that it works.
- Database migrations are reviewed and you know how to roll them back.
5. Cost limits
- Spend limits or budget alerts are set on hosting (for example Vercel Spend Management, the Supabase spend cap). Cara
- Usage limits and budget notifications are set on AI APIs (OpenAI, Anthropic and others). EnrichLead
- Public endpoints are rate-limited, especially those that call paid APIs.
- Signup and forms have bot protection such as Cloudflare Turnstile or a CAPTCHA.
- Log retention is configured. Keep what you need for debugging and delete the rest after a set period.
6. Visibility and monitoring
- You have a list of everything that is public: domains, preview deployments, internal tools. Internal tools are behind a login. RedAccess
- Preview deployments are protected or at least not indexed by search engines.
- Errors and uptime are monitored, with alerts sent to a channel you actually read.
- You get alerted on unusual spend and spikes in failed logins.
- There is a one-page runbook: how to roll back, how to rotate keys, whom to contact at your hosting provider.
7. Basics that are easy to forget
- HTTPS everywhere, with HTTP redirecting to HTTPS.
- Dependencies are scanned (Dependabot,
npm auditor similar).
How to use this list with an agent
Do not ask the agent "is my app secure?". Give it one section at a time as a task with acceptance criteria, for example: "Find every place where a secret key is used in client code. List files and lines. Move them behind a server endpoint. Show me the diff." Then check the result yourself with the tests above: anonymous access, wrong-user access, a restore.
For real cases where these checks were skipped, read 8 real vibe coding security incidents.