Flexport Production Checklist
Overview
Pre-deployment and go-live checklist for Flexport logistics integrations covering API configuration, webhook setup, monitoring, and rollback procedures.
Prerequisites
- A launch owner, approver, rollback operator, approved data-flow inventory, and staging evidence using fictional shipments.
- Redacted monitoring, explicit target/destination policies, and a secure path for credentials and incident evidence.
Instructions
- Attach evidence or an owner decision for every applicable checklist control; leave no implicit acceptance.
- Verify scoped secrets, signature validation, idempotent processing, redacted diagnostics, and retention/access behavior.
- Run a small staging or production canary with synthetic data and observe aggregate health, queue, and delivery outcomes.
- Stop promotion and invoke rollback on permission, policy, integrity, or safety thresholds; record the decision and recovery test.
Output
Create a go-live receipt with completed controls, evidence links, canary metrics, exceptions, approver, launch/rollback owners, and follow-up dates. Keep documents, addresses, commercial terms, and credentials out of it.
Error Handling
- Pause unsafe automation or notifications on signature, permission, destination, or reconciliation failures.
- Quarantine failed work by opaque ID and rotate credentials if exposure is possible.
- Confirm rollback and no unintended replay before resolving the launch incident.
Examples
Process a fictional shipment milestone through the canary, revoke a test destination’s access, and simulate an upstream outage. Promote only after the designated approver records that the handler paused safely, produced redacted metrics, and rolled back cleanly.
Pre-Deployment
Authentication & Secrets
API Integration
Webhooks
Data Integrity
Monitoring & Alerting
// Health check endpoint
app.get('/health', async (req, res) => {
const start = Date.now();
try {
const r = await fetch('https://api.flexport.com/shipments?per=1', {
headers: {
'Authorization': `Bearer ${process.env.FLEXPORT_API_KEY}`,
'Flexport-Version': '2',
},
});
res.json({
status: r.ok ? 'healthy' : 'degraded',
flexport: { connected: r.ok, latencyMs: Date.now() - start },
});
} catch {
res.status(503).json({ status: 'unhealthy', flexport: { connected: false } });
}
});
Alert Thresholds
| Metric |
Warning |
Critical |
| API error rate |
> 5% |
> 20% |
| p99 latency |
> 3000ms |
> 10000ms |
| 429 rate limits |
> 5/hour |
> 20/hour |
| Webhook failures |
> 2/hour |
> 10/hour |
| Auth failures (401/403) |
Any |
Any |
Rollback Procedure
# Immediate rollback
kubectl rollout undo deployment/flexport-integration
# Or for non-k8s: revert to last known good image/version
Resources
Next Steps
For version upgrades, see flexport-upgrade-migration.
1---2name: flexport-prod-checklist3description: Execute Flexport production deployment checklist for logistics integrations. Use when deploying shipment tracking, booking automation, or supply chain integrations to production with proper monitoring and rollback. Trigger: "flexport production", "deploy flexport", "flexport go-live checklist".4license: MIT5---6# Flexport Production Checklist
7
8## Overview
9
10Pre-deployment and go-live checklist for Flexport logistics integrations covering API configuration, webhook setup, monitoring, and rollback procedures.
11
12## Prerequisites
13
14- A launch owner, approver, rollback operator, approved data-flow inventory, and staging evidence using fictional shipments.
15- Redacted monitoring, explicit target/destination policies, and a secure path for credentials and incident evidence.
16
17## Instructions
18
191. Attach evidence or an owner decision for every applicable checklist control; leave no implicit acceptance.
202. Verify scoped secrets, signature validation, idempotent processing, redacted diagnostics, and retention/access behavior.
213. Run a small staging or production canary with synthetic data and observe aggregate health, queue, and delivery outcomes.
224. Stop promotion and invoke rollback on permission, policy, integrity, or safety thresholds; record the decision and recovery test.
23
24## Output
25
26Create a go-live receipt with completed controls, evidence links, canary metrics, exceptions, approver, launch/rollback owners, and follow-up dates. Keep documents, addresses, commercial terms, and credentials out of it.
27
28## Error Handling
29
30- Pause unsafe automation or notifications on signature, permission, destination, or reconciliation failures.
31- Quarantine failed work by opaque ID and rotate credentials if exposure is possible.
32- Confirm rollback and no unintended replay before resolving the launch incident.
33
34## Examples
35
36Process a fictional shipment milestone through the canary, revoke a test destination’s access, and simulate an upstream outage. Promote only after the designated approver records that the handler paused safely, produced redacted metrics, and rolled back cleanly.
37
38## Pre-Deployment
39
40### Authentication & Secrets
41
42- [ ] Production API key stored in secret manager (not env files)
43- [ ] Webhook secret configured and verified
44- [ ] Key rotation procedure documented
45- [ ] No keys in git history (`git log -p | grep -i flexport_api`)
46
47### API Integration
48
49- [ ] All endpoints tested against production API
50- [ ] Pagination implemented for list endpoints (`/shipments`, `/products`)
51- [ ] Rate limit handling with exponential backoff
52- [ ] Retry logic for transient 5xx errors
53- [ ] Idempotency keys on POST/PATCH operations
54- [ ] `Flexport-Version: 2` header on all requests
55
56### Webhooks
57
58- [ ] HTTPS endpoint with valid TLS certificate
59- [ ] `X-Hub-Signature` verification implemented
60- [ ] Webhook endpoint responds within 5 seconds
61- [ ] Dead letter queue for failed webhook processing
62- [ ] Idempotent webhook handlers (replay-safe)
63
64### Data Integrity
65
66- [ ] HS codes validated against customs requirements
67- [ ] UN/LOCODE port codes verified
68- [ ] Commercial invoice totals cross-checked
69- [ ] Product catalog synced with Flexport Product Library
70
71## Monitoring & Alerting
72
73```typescript
74// Health check endpoint
75app.get('/health', async (req, res) => {
76 const start = Date.now();
77 try {
78 const r = await fetch('https://api.flexport.com/shipments?per=1', {
79 headers: {
80 'Authorization': `Bearer ${process.env.FLEXPORT_API_KEY}`,
81 'Flexport-Version': '2',
82 },
83 });
84 res.json({
85 status: r.ok ? 'healthy' : 'degraded',
86 flexport: { connected: r.ok, latencyMs: Date.now() - start },
87 });
88 } catch {
89 res.status(503).json({ status: 'unhealthy', flexport: { connected: false } });
90 }
91});
92```
93
94### Alert Thresholds
95
96| Metric | Warning | Critical |
97|--------|---------|----------|
98| API error rate | > 5% | > 20% |
99| p99 latency | > 3000ms | > 10000ms |
100| 429 rate limits | > 5/hour | > 20/hour |
101| Webhook failures | > 2/hour | > 10/hour |
102| Auth failures (401/403) | Any | Any |
103
104## Rollback Procedure
105
106```bash
107# Immediate rollback
108kubectl rollout undo deployment/flexport-integration
109# Or for non-k8s: revert to last known good image/version
110```
111
112## Resources
113
114- [Flexport Status](https://status.flexport.com)
115- [Flexport API Reference](https://apidocs.flexport.com/)
116
117## Next Steps
118
119For version upgrades, see `flexport-upgrade-migration`.