Production hardening¶
Everything you need before shipping: observability, governance, security, and testing.
For verified Python, Java and Go export behavior, reproducible build checks and remaining release gates, read Production readiness. The checklist below is general application guidance, not evidence that every generated target implements every feature.
Observability & logging¶
from langstitch import get_logger
log = get_logger(__name__) # level from LOG_LEVEL env (default INFO)
log.info("handled request", extra={"intent": intent})
- Set
LOG_LEVELviaenv.yaml/ platform env. Use structured fields for machine-readable logs. - Propagate a correlation id: set
X-Request-IDon inbound requests, register it withset_request_headers(), and list it in each service'spropagate_headersso it flows downstream. - Wire LangSmith / Langfuse at the LLM layer (provider env vars) for traces and evals.
Guardrails, policies & error handling¶
- Run
get_input_guardrails()before the LLM andget_output_guardrails()after; honor each spec'saction(block/warn/log) andseverity. - Evaluate
get_policies()inpriorityorder (highest first) and short-circuit on a non-allowdecision. - Treat missing extras as configuration errors: helpers raise
RuntimeErrorwith an install hint — fail fast at startup rather than per request. Wrap LLM/tool calls with retries and timeouts;get_http_clienthonors the configuredtimeout.
Security checklist¶
- Secrets only via environment /
${ENV_VAR};env.yamlgitignored. - Gate tools/agents with
roles=[...]and select by role at context-build time. - Don't blindly propagate
authorizationto third-party hosts — only list headers a service should receive in itspropagate_headers. - Pin dependency ranges; run
pip auditin CI; rebuild images on base updates.
Testing¶
from langstitch import get_registry, reset_registry, Context, run_worker_agent
def test_components_register():
import app # triggers registration
reg = get_registry()
assert "respond" in reg.nodes and reg.server is not None
def test_context_isolation():
parent = Context(data={"topic": "x"})
out = run_worker_agent(parent, "researcher", carry=["topic"])
assert "researcher" in parent.data and "messages" not in parent.data # no leakage
Use reset_registry() / reset_config_cache() between tests for isolation. Mock
external HTTP with httpx MockTransport; the SDK's own suite runs on Python
3.10–3.13 in CI.