Secrets checklist
- Copy
secrets.local.example→secrets.local - Fill values from your current host dashboards (temporary dump while migrating)
- Remove or rotate secrets on the upstream
open-bio-page/open-bio-pagerepository if that repo should stay clean - On each forked instance, upload the secrets again to Actions and to the serverless env
- Confirm
secrets.localis gitignored (it is listed in.gitignore)
Never put secrets in VITE_* variables. Those values ship in the client bundle.
PostHog keys and where each one goes: Analytics and admin stats.