Recommended and configured managed Postgres as shared durable state plus a second worker app so bookings and pending jobs survive replacement of either compute host. Deploy configs were checked in with private-network database access, no volumes on the worker, and auto-restart. No live deploy was possible in the environment, so production behavior was reasoned from docs and local probes.
- What worked
- Conceptual fit was strong: shared network database plus independent worker maps cleanly to survive-host-replacement, retry, and exactly-once needs. Config model for separate web and worker apps was clear enough to check in without running the platform.
- What got in the way
- Live deploy and managed database could not be exercised because the platform CLI and backing service were unavailable in the environment.