Skip to content

Production hardening

Everything you need before shipping: observability, governance, security, and testing.

For verified Python, Java and Go export behavior, reproducible build checks and remaining release gates, read Production readiness. The checklist below is general application guidance, not evidence that every generated target implements every feature.

Observability & logging

from langstitch import get_logger
log = get_logger(__name__)        # level from LOG_LEVEL env (default INFO)
log.info("handled request", extra={"intent": intent})
  • Set LOG_LEVEL via env.yaml / platform env. Use structured fields for machine-readable logs.
  • Propagate a correlation id: set X-Request-ID on inbound requests, register it with set_request_headers(), and list it in each service's propagate_headers so it flows downstream.
  • Wire LangSmith / Langfuse at the LLM layer (provider env vars) for traces and evals.

Guardrails, policies & error handling

  • Run get_input_guardrails() before the LLM and get_output_guardrails() after; honor each spec's action (block / warn / log) and severity.
  • Evaluate get_policies() in priority order (highest first) and short-circuit on a non-allow decision.
  • Treat missing extras as configuration errors: helpers raise RuntimeError with an install hint — fail fast at startup rather than per request. Wrap LLM/tool calls with retries and timeouts; get_http_client honors the configured timeout.

Security checklist

  • Secrets only via environment / ${ENV_VAR}; env.yaml gitignored.
  • Gate tools/agents with roles=[...] and select by role at context-build time.
  • Don't blindly propagate authorization to third-party hosts — only list headers a service should receive in its propagate_headers.
  • Pin dependency ranges; run pip audit in CI; rebuild images on base updates.

Testing

from langstitch import get_registry, reset_registry, Context, run_worker_agent

def test_components_register():
    import app                       # triggers registration
    reg = get_registry()
    assert "respond" in reg.nodes and reg.server is not None

def test_context_isolation():
    parent = Context(data={"topic": "x"})
    out = run_worker_agent(parent, "researcher", carry=["topic"])
    assert "researcher" in parent.data and "messages" not in parent.data  # no leakage

Use reset_registry() / reset_config_cache() between tests for isolation. Mock external HTTP with httpx MockTransport; the SDK's own suite runs on Python 3.10–3.13 in CI.