# WorxAI infrastructure controls

## Scripts

- `pnpm backup:db` — compressed PostgreSQL backup with retention cleanup.
- `pnpm healthcheck` — checks the app, gateway, database configuration, and payment configuration.
- `pnpm monitor:stack` — repeats health checks and can notify a Discord or Matrix-compatible webhook through `WEBHOOK_URL`.
- `pnpm restart:stack` — safely restarts Docker Compose services without deleting volumes.
- `pnpm manage:cluster` — runs backup, validates Compose, cycles services, and verifies recovery.

## Network edge

`infra/nginx.conf` provides TLS termination, proxy forwarding, request-size limits, rate limiting, and baseline security headers. Set `UPSTREAM` and certificate paths in the deployment environment; do not commit private keys.

## Safety

Maintenance commands are intentionally non-destructive by default. Pruning requires an explicit `ALLOW_PRUNE=1`, and backup paths must be configured through environment variables.
