# Production checklist (/deploy/production-checklist)



Use this list before KubeMQ takes production traffic. Each item links to the page that shows how. The last group covers your client applications.

## Cluster shape [#cluster-shape]

* [ ] An odd number of servers, at least three, chosen for the long term ([Requirements and supported setups](/deploy/install/requirements#kubernetes)).
* [ ] CPU and memory set per server, and servers spread across nodes ([Deployment & High Availability](/configure/reference/deployment#high-availability)).
* [ ] A storage class with room for every server's volume ([Requirements and supported setups](/deploy/install/requirements#sizing)).

## License [#license]

* [ ] A license key or an offline license file, not the evaluation or a trial key ([Plans compared](/licensing#which-one-fits)).
* [ ] The license check shows every server `active` ([Install on Kubernetes](/deploy/install/kubernetes#steps)).
* [ ] License expiry and license state monitored ([How licensing works](/licensing/how-it-works#check-license-status)).
* [ ] On an air-gapped cluster, a reminder to renew the offline license file ([Install air-gapped](/deploy/install/air-gapped#renew-before-it-expires)).

## Security [#security]

* [ ] A management certificate from an authority you trust ([Install on Kubernetes](/deploy/install/kubernetes#management-certificate)).
* [ ] The administrator password kept in your secrets manager ([Install on Kubernetes](/deploy/install/kubernetes#send-a-test-message)).
* [ ] Client authentication on, and a test client with no credentials refused ([Security (Auth · TLS)](/configure/reference/security#authentication)).
* [ ] Channel permissions set per client ([Security (Auth · TLS)](/configure/reference/security#authorization)).
* [ ] TLS on the interfaces your clients use ([Security (Auth · TLS)](/configure/reference/security#tls--mtls)).
* [ ] Connectors you use secured: Kafka [Authentication](/connectors/kafka/how-to/authentication) and [TLS and mTLS](/connectors/kafka/how-to/tls-and-mtls); RabbitMQ [Authentication](/connectors/rabbitmq/how-to/authentication) and [TLS and mTLS](/connectors/rabbitmq/how-to/tls-and-mtls).
* [ ] Network policies that limit which workloads reach the server ports ([Requirements and supported setups](/deploy/install/requirements#network)).

## Network [#network]

* [ ] Outbound HTTPS to `license.kubemq.io`, or an offline license file ([Requirements and supported setups](/deploy/install/requirements#network)).
* [ ] Your applications reach the interfaces they use ([Install on Kubernetes](/deploy/install/kubernetes#connect-your-applications)).
* [ ] Only the interfaces you use exposed outside the cluster ([Interfaces (gRPC · REST · API · HTTP)](/configure/reference/interfaces)).

## Data [#data]



* [ ] A backup method chosen and a restore tested ([Back up and restore](/operate/backup-and-restore#steps)). Back up the Docker volume with the container stopped. For Kubernetes, [contact support](mailto:support@kubemq.io) before relying on a restore.

## Operations [#operations]

* [ ] Metrics scraped and alerts set ([Prometheus Metrics](/operate/observability/metrics)).
* [ ] Logs collected ([Structured Logging](/operate/observability/logging)).
* [ ] An upgrade plan written ([Upgrade KubeMQ](/deploy/upgrade)).
* [ ] With GitOps, the chart version pinned (Pin a version on [Install on Kubernetes](/deploy/install/kubernetes)).

## Your applications [#your-applications]

* [ ] Clients reconnect with backoff after a server restart and handle each error category ([Error Handling Patterns](/learn/guides/error-handling)).
* [ ] A timeout on every command and query ([Configure Timeouts & Retries](/learn/rpc/how-to/timeout-configuration)).
* [ ] A dead-letter queue on every critical queue ([Dead Letter Queue](/learn/queues/tutorials/dead-letter-queue)).
* [ ] Visibility timeouts matched to processing time ([Configure Visibility Timeout](/learn/queues/how-to/visibility-timeout)).
* [ ] TLS on every client connection ([Connect with TLS & mTLS](/learn/guides/connect-with-tls)).
* [ ] Traces and metrics from every client ([OpenTelemetry Integration](/learn/guides/opentelemetry)).
* [ ] Channel names and their lifecycle managed ([Channel Management](/learn/guides/channel-management)).
* [ ] Volumes sized for channel growth: retention limits apply only on the legacy storage engine ([Storage Engines](/configure/reference/storage-engines#native-retention-scope)).

## Related [#related]

* [Install on Kubernetes](/deploy/install/kubernetes)
* [Upgrade KubeMQ](/deploy/upgrade)
* [Messaging Fundamentals](/learn/concepts)
