Senior Node.js / DevOps Contractor — Replit Production Migration for Health SaaS
Rozpočet: $4000.0
FIXED /
⭐ 0.00 (0)
United States
node.js, postgresql, devops, git, cicd, amazon-web-services
HealthStory is an early-stage women's health SaaS platform. It is currently developed and hosted in Replit. I need an experienced individual contractor to move the existing production infrastructure off Replit into HealthStory-owned accounts and a production environment appropriate for handling protected health information.
This is an infrastructure migration only. It is not a feature-development project, UI redesign, app rewrite, or full HIPAA compliance audit.
CURRENT STACK
-- Node.js / Express backend
-- React frontend
-- Drizzle ORM
-- PostgreSQL currently on Replit-managed Neon infrastructure
-- OpenAI API currently routed through a Replit-managed proxy
-- Sentry error monitoring
-- Existing in-memory lab PDF upload/parsing code using pdf-parse and tesseract.js
-- Replit will remain the development environment for synthetic or de-identified test data only
There are no active customer-account migration concerns.
PRODUCTION ARCHITECTURE
Preferred baseline:
-- Fly.io for production hosting
-- HealthStory-owned Neon account for PostgreSQL
-- HealthStory-owned Git repository and repeatable Git-based deployment process
-- Direct OpenAI API routing from production
-- Replit removed from production hosting, database access, AI routing, and production secrets
AWS may be recommended if it offers a clear cost, operational, or future document-storage advantage. HealthStory has an existing signed AWS BAA, so contractors may propose an AWS-based alternative with a clear explanation and first-year cost estimate.
SCOPE
The selected contractor will:
-- Review the codebase, Replit dependencies, database access, environment variables, and production data paths.
-- Set up client-owned production accounts, production secrets, access controls, and deployment workflow.
-- Establish a Git-based release process so HealthStory can continue developing in Replit and deploy approved code outside Replit.
-- Migrate the existing app and PostgreSQL database from Replit-managed infrastructure.
-- Configure HTTPS, domain routing, health checks, backups, and complete a restore test.
-- Remove the Replit-managed OpenAI proxy and configure direct OpenAI API routing.
-- Audit Sentry and other connected services so PHI, AI prompts/outputs, request bodies, and secrets are not unintentionally captured.
-- Test existing core workflows before cutover.
-- Regression-test the existing lab PDF upload/parsing functionality using synthetic test PDFs only.
-- Provide a rollback plan, production cutover, documentation, and a recorded handoff.
-- Provide 14 calendar days of post-cutover support for migration-caused issues.
NOT INCLUDED
-- New product features
-- New lab-upload, document-storage, OCR, or AI-extraction functionality
-- UI/UX redesign
-- Major refactoring unrelated to migration
-- Formal HIPAA certification, legal advice, or penetration testing
-- Ongoing support after the included 14-day stabilization period
-- Vendor subscription and usage costs
TIMELINE
-- Technical review and migration plan: within 3 business days
-- Working synthetic-data deployment: target by Day 7
-- Production cutover: target within 10-15 business days
-- Final stabilization and handoff: 14 days after cutover
Total engagement may span up to approximately four calendar weeks.
BUDGET
Fixed-price proposals up to $4,000.
Milestone payments will be based on accepted deliverables:
-- 25% - verified production foundation and working synthetic-data deployment
-- 45% - completed migration and production cutover
-- 30% - completed 14-day stabilization period, documentation, and handoff
No hourly overages or change orders without written approval.
REQUIRED EXPERIENCE
Please apply only if you have direct, hands-on experience with production infrastructure for healthcare, PHI/ePHI, BAA-backed vendors, or similarly sensitive regulated data.
General website deployment experience or "healthcare-adjacent" work alone is not sufficient.
You should be able to demonstrate experience with:
-- Mapping where ePHI may be created, received, stored, transmitted, backed up, or logged across an application and its vendors.
-- Working with BAA-backed vendors and identifying when hosting, database, logging, email, AI, storage, or authentication providers may be part of the ePHI data path.
-- Configuring production safeguards such as secrets management, encryption in transit and at rest, MFA, least-privilege access, backups, restore testing, and rollback procedures.
-- Preventing PHI exposure through logs, Sentry/error monitoring, request bodies, query strings, analytics, email notifications, and AI requests.
-- Production Node.js / Express deployments.
-- PostgreSQL migrations, backup configuration, and restore testing.
-- Git-based deployment workflows / CI/CD.
-- Fly.io and Neon, or AWS ECS/EC2 and RDS.
This is not a request for legal advice, HIPAA certification, or a formal compliance audit. However, the selected contractor must be able to identify where PHI/ePHI can be created, received, stored, transmitted, logged, backed up, or exposed across the application and its vendors.
PLEASE INCLUDE IN YOUR PROPOSAL
-- Your fixed price and estimated hours.
-- Relevant Node/Postgres production migration experience.
-- Experience with Fly.io + Neon and/or AWS.
-- Your recommended architecture and why.
-- A brief explanation of how you would move production away from Replit while allowing continued development in Replit.
-- Your approach to backups, restore testing, cutover, and rollback.
-- Assumptions, exclusions, and likely blockers.
-- Whether you use subcontractors or perform work outside the United States.
-- Describe one production system you personally deployed or maintained that handled PHI/ePHI or operated in a BAA-backed healthcare-data environment. Briefly explain the cloud stack, how you handled backups and access controls, and how you prevented sensitive data from entering logs or error-monitoring tools.
Detailed scope, milestones, acceptance criteria, and HIPAA-aligned technical requirements will be shared with shortlisted candidates.
Otevřít na Upwork