One project. Staging first. Public domains only for Studio/API; private networking for data/workers.
Operations
Railway, PostgreSQL, Redis, Temporal, workers, providers and runtime readiness in one place.
Redis accelerates reads and coordinates short duplicate work. It never owns accepted production truth.
Production worker has 13 canonical activities; runtime boot still requires validated concrete adapters/entrypoint.
Service readiness
Connection discipline
Process-scoped async pool, pre-ping, conservative pool budget and Alembic as the only relational migration path.
Cache workflow
Versioned project keys, bounded TTLs, cache-aside reads, SCAN invalidation, short token-safe leases and durable-source fallback.
/readyz
Railway should switch API traffic only when required PostgreSQL and Redis dependencies respond successfully.
Railway A → Z
Runner unproven
Last inspected GitHub jobs were blocked before startup by account billing or spending limits. Resolve the account restriction, then require passing checks on the exact review commit.
Measure first
Start one replica. Increase worker concurrency/API replicas only from p95 latency, backlog, saturation and provider-limit evidence.
Durable truth
Postgres + Temporal + object storage drive recovery. Redis flush should require recomputation, not business-data restoration.