Docs / Operations Operate
Production Setup
A checklist for running EKOS beyond a laptop.
- [ ] One writer. Run indexing from a single job per workspace; serve from separate read-only processes.
- [ ] Dedicated workspace directory with its own
ekos.toml; do not pointpathsat a directory containing other projects' venvs or build outputs. - [ ] Exclusions reviewed —
ekos config preview-scanbefore the first build; virtualenvs,node_modules, generated docs and test-run output out. - [ ] Secrets — provider keys from environment or a secret manager, never in
ekos.toml. Understand the redaction baseline; add[security]extensions for your own secret shapes. - [ ] Network — MCP over TCP/HTTP on loopback or a private network, with
--token-file, TLS via a reverse proxy. - [ ] LLM spend — leave
[llm-description]and[document-semantics]off in automation unless intended; usecommit --yesdeliberately. - [ ] Health check —
ekos doctor --jsonin monitoring. - [ ] Backups — see Backup & Recovery.
- [ ] Pin the binary version and read Upgrades before changing it.