From Demo to Production: The Pre-Launch Checklist for AI-Generated Code
The demo is 10%; shipping is the other 90%. A pre-launch checklist built for AI-generated projects: security, data, observability, performance & cost, release & rollback — because agents have three systematic blind spots, and 'shippable' judgment is yours.

The sweetest trap in AI programming is the demo: one afternoon, and you have a product that runs, looks good, and you can even show your friends. Then you put it online, and three days later: API keys drained by bots, database wiped, user data leaked, billing exploded. The demo is 10%; shipping is the other 90%. This article is a pre-launch checklist designed specifically for AI-generated projects — the agent wrote your code, but the judgment call of "is this shippable" is forever yours.
Why do AI-generated projects need this checklist so badly? Because agent output has three systematic blind spots: it doesn't think about cost (every API call spends like it's free), it doesn't think about attackers (it assumes the whole world is friendly), and it doesn't think about "later" (no backups, no migrations, no rollback plan). Those three things are, collectively, the entire job of production.
1. Security: Plug the Holes That Kill First
- Secrets and credentials. Verify every API key, database password, and JWT secret lives in environment variables. AI-generated code loves hardcoding keys into source — grep for
sk-,api_key,secret, and confirm none were ever committed (git log -p | grepthe history). Any committed key is compromised: rotate it immediately. - Injection surface. Everywhere user input reaches a database, a shell, or a template — confirm parameterization/escaping. Run a dedicated "attacker view" review with the agent: prompt it directly with "assume you're a hacker; find 5 injection points in this code."
- Auth and authorization. For every endpoint ask: callable without login? Can a logged-in user touch someone else's data? AI-generated CRUD routinely does "authorization via hidden buttons in the frontend." Write 3 curl tests — anonymous, regular user, admin — and hit every endpoint.
- Dependencies and supply chain. Run
npm audit/pip auditand fix everything high and above. Check whether the agent pulled in obscure packages you've never heard of — every dependency is trust, and every extra package is another poisoning vector.
2. Data: Everything Is Recoverable Except Data
- Backup strategy. Does the database back up automatically? How long are backups kept? Have you done one restore drill? "Having backups" and "being able to restore" are two different things — an untested backup is no backup.
- Migration discipline. Do schema changes go through migration files, or does the agent hand-edit the production database? The latter is a disaster factory. Confirm every schema change ships with a rollback-able migration.
- Deletion and privacy. When a user deletes their account, is the data actually gone? Do logs contain plaintext passwords, tokens, ID numbers? AI-generated logging notoriously "logs too much" — grep for sensitive fields before launch.
3. Observability: Flying Blind After Launch Is the Most Expensive Option
- Logging. Do critical paths (login, payments, core actions) emit structured logs? Is there a request ID tying one full call chain together? When something breaks at 2 AM, what do you debug with — vibes?
- Alerting. At minimum three: error-rate spike, core-endpoint P99 latency breach, disk/memory over 80%. An alert must be able to actually wake you — one routed to an inbox you never open is decoration.
- Health checks. Is there a
/healthendpoint? Your deployment platform uses it to decide if the service is alive. Plenty of AI-generated projects ship without one — and nobody notices when they die.
4. Performance and Cost: The New Ledger of the AI Era
- N+1 and slow queries. Have the agent run EXPLAIN over everything; check list pages for queries inside loops. This is the single most common performance bug in AI-generated code, bar none.
- Caching. Is read-heavy data (configs, leaderboards, homepages) cached? Launching without a cache is an open invitation for the world to melt your database.
- AI call costs. If your product itself calls LLM APIs: are results cached? Is there a per-user/per-day token cap? Is there rate limiting against abuse? This really happened: a project woke up to a $50,000 token bill on day one.
- Static assets. Are images compressed, is a CDN configured? AI-generated frontends routinely reference 5MB originals — every mobile user curses once per load.
5. Release and Rollback: Leave Yourself an Exit
- Rollback plan. If this release goes sideways, can you roll back to the previous version in 5 minutes? If you can't say "yes," don't ship. Container image tags and down-migration scripts are rollback ammunition.
- Gradual rollout. Can you validate on 5% of traffic first? At minimum, be able to roll everything back fast. Assume an AI-generated codebase's first production deploy has bugs — gradual rollout isn't insecurity, it's professionalism.
- Environment isolation. Are dev, staging, and production three separate environments and databases? Something the agent got working "in dev," run against the production database, is an incident announcement.
My View: Checklists Aren't Bureaucracy — They Convert Luck Into Certainty
Many indie developers dislike checklists as big-company bureaucracy. But the truth is: big companies use checklists because they've paid tuition; you don't because you haven't yet. AI has driven the cost of "building a demo" to near zero, which makes "shipping" the new scarce capability — and shipping is half technique, half reverence.
One level deeper: in the agent era, the judgment of "is this shippable" is becoming the dividing line between humans and AI. Writing code, tests, and docs — agents keep getting better. But "how will this system die in the real world" requires understanding human nature (attackers, users who misclick), economics (costs, bills), and Murphy's Law — precisely the agent's blind spots. Every minute you spend on this checklist reinforces that dividing line.
One actionable suggestion to close: save this checklist as PRODUCTION_CHECKLIST.md in your project, and before each release have the agent self-audit item by item with evidence (screenshots, command output, links) — you only spot-check at the end. Crossing from "trusting the agent" to "verifying the agent" is the moment your vibe coding truly graduates.
Related articles

Every vibe project hits the same moment: a list page firing a dozen DB queries per load, the database melting under modest traffic. This guide starts from the three-question caching mindset, then layers HTTP cache headers, Next.js data caching, Redis application caching with key design and the penetration/breakdown/avalanche defenses, and AI result caching (semantic cache, prompt caching), plus invalidation strategy and a launch checklist.

On October 3, 'Sites in ChatGPT' hit the HN front page with ~209 points and 218 comments. Not a launch — a reckoning: is prompt-to-URL a toy, a prototype host, or a productivity tool? The four debates, the doc-backed facts (D1/R2, sign-in, custom domains), and three verdicts for vibe coders.

On October 3, engineer Kevin Liao published a polemic that hit the HN front page: agent memory plugins are a lottery over RAG snippets; what agents need is a documentation workspace. The essay's diagnosis, its open-source Operator Memory plugin, the two strongest objections, and the minimal practice you can start tonight.