Self-hosting gives you control over where an application runs. It also gives your team responsibility for the services that make it dependable. Before inviting customers into a support workspace, make those responsibilities explicit.
Start with the public address
Choose a stable HTTPS origin for the installation and configure the application to use it. An origin mismatch can affect browser requests and account links. Configure the public website origin at build time so its canonical URLs and sitemap match the deployed domain.
Treat email as part of account access
Password recovery only helps when the message arrives. Configure your SMTP provider, run the connectivity check, and then complete a real reset flow using an account you control. A successful SMTP connection test alone does not prove that a message will reach a recipient’s inbox.
Connext encrypts queued email payloads using a configured key. Keep that key with your deployment secrets. Monitor failed delivery jobs and have a process for correcting provider configuration when delivery stops.
Practice recovery before you need it
Create a database backup and restore it into an isolated environment. Check that the restored application can read conversations and authenticate a test user. Record the procedure and who can carry it out. A backup file that has never been restored leaves a significant question unanswered.
Review access and monitoring
Keep migration credentials separate from application runtime credentials. Assign workspace roles according to responsibility and periodically review platform administrator access. Use the readiness endpoint to monitor dependencies, alongside application logs and infrastructure metrics.
Validate the actual deployment
Local application tests are useful evidence, but they do not exercise every network, storage or provider setting in your environment. Before launch, test a visitor message, an agent reply, account recovery and a process restart on the deployed stack.
The self-hosting documentation lists the Connext configuration areas to review. The security page describes the implemented controls and their limits.