Operational previewLive, durable, planning and unavailable states must remain visually distinct.
Infrastructure & deployment

Operations

Railway, PostgreSQL, Redis, Temporal, workers, providers and runtime readiness in one place.

not configured
Deployment target
Railway

One project. Staging first. Public domains only for Studio/API; private networking for data/workers.

Cache law
Disposable

Redis accelerates reads and coordinates short duplicate work. It never owns accepted production truth.

Worker truth
13 stages

Production worker has 13 canonical activities; runtime boot still requires validated concrete adapters/entrypoint.

Runtime topology

Service readiness

not_configured
cartoonos-studio · Next.js command center · public
configure
cartoonos-api · FastAPI · public · /readyz
configure
Postgres · durable transactional truth · private
required
Redis · disposable cache + coordination · private
required
Temporal · durable workflow history
required
Media bucket · immutable accepted binary assets
required
production-worker · 13 canonical production activities · private
staging proof
operating-worker · observations / evals / decisions · private
staging proof
PostgreSQL

Connection discipline

Process-scoped async pool, pre-ping, conservative pool budget and Alembic as the only relational migration path.

Redis

Cache workflow

Versioned project keys, bounded TTLs, cache-aside reads, SCAN invalidation, short token-safe leases and durable-source fallback.

Deployment gate

/readyz

Railway should switch API traffic only when required PostgreSQL and Redis dependencies respond successfully.

Staging sequence

Railway A → Z

runbook
01
Create Railway staging project/environment
pending proof
02
Provision private PostgreSQL + Redis
pending proof
03
Deploy API and wire reference variables
pending proof
04
Run Alembic to current head and verify /readyz
pending proof
05
Deploy Studio against API public domain
pending proof
06
Connect Temporal and boot validated workers
pending proof
07
Verify object-storage checksum round-trip
pending proof
08
Refresh provider capabilities and run Golden Shot
pending proof
CI

Runner unproven

Last inspected GitHub jobs were blocked before startup by account billing or spending limits. Resolve the account restriction, then require passing checks on the exact review commit.

Scaling

Measure first

Start one replica. Increase worker concurrency/API replicas only from p95 latency, backlog, saturation and provider-limit evidence.

Recovery

Durable truth

Postgres + Temporal + object storage drive recovery. Redis flush should require recomputation, not business-data restoration.