Deployment and configuration
Required platform settings
| Variable | Purpose |
|---|---|
THYRIS_LICENSE_GEO_SERVICES | Enables the GEO Services product where environment licensing is used |
GEO_INTERNAL_WORKER_TOKEN | Shared secret between GEO workers and internal control-plane routes |
GEO_CONTROL_PLANE_URL | Internal app/control-plane base URL |
GEO_WORKER_INTERVAL | Worker polling interval; minimum one second |
GEO_SERVICE_ADDR | Optional runtime listen address; default :8080 |
GEO_*_SERVICE_URL | Control-plane address for each independent GEO service |
GEO_CONNECTOR_ALLOW_INSECURE_HTTP=true and private-network connector overrides reduce protection and should be limited to controlled development environments.
Service URLs
Configure service URLs for observation, intelligence, core, component, knowledge, content, channel, simulation, action, reporting, tracking, attribution, entity, citation graph, prompt demand, narrative, experiment and autopilot services. Use internal service discovery rather than public endpoints.
Production topology
Only the web/API and intended collection/share routes should be externally reachable. Domain services, worker routes, PostgreSQL, object storage and secret manager stay on private networks.
Health contracts
Each GEO runtime exposes /healthz, /readyz, /v1/capabilities and its domain endpoint. Health means the process is running; readiness and capability checks are required before routing work.
| Probe | Success condition | Routing consequence |
|---|---|---|
Liveness /healthz | Process event loop/server responds | Restart when repeatedly unhealthy |
Readiness /readyz | Required configuration and domain initialization are usable | Remove from service routing when false |
Capabilities /v1/capabilities | Expected service name/version/operations are advertised | Fail deployment validation on mismatch |
| Domain smoke | Representative safe request returns the expected schema | Do not declare release accepted without it |
Database
Apply the canonical GEO migration chain before enabling workers. Existing PostgreSQL volumes do not rerun initialization automatically. Run migrations through the reviewed migration path and verify schema/integrity checks.
Worker routes
Schedules, actions, publications, reports, tracking maintenance and webhook delivery call internal control-plane routes with GEO_INTERNAL_WORKER_TOKEN. Do not expose these routes as customer APIs.
Environment separation
Use separate databases, secrets, provider/channel credentials, tracking sites/tokens, object-storage paths and external callback URLs for development, staging and production. A staging key must not be able to mutate a production destination.
Rollout order
- Apply and verify reviewed migrations.
- Configure secret manager and internal worker identity.
- Deploy PostgreSQL/object storage dependencies or verified external equivalents.
- Deploy domain runtimes and verify health/readiness/capabilities.
- Deploy web/control plane with service URLs.
- Deploy workers with bounded concurrency and budgets.
- Run tenant-isolation and domain smoke tests.
- Configure one staging provider and channel connection.
- Exercise observation, dry-run publication, tracking and report delivery.
- Enable production schedules only after acceptance evidence is recorded.
Production guidance
- Use distinct production secrets and bounded worker budgets.
- Configure restart/health policy for every runtime.
- Centralize structured logs and alert on retry/dead-letter growth.
- Back up PostgreSQL and test restore procedures.
- Restrict egress to approved providers and channel destinations.
- Validate all licensed product and service URL configuration before rollout.