# Deploying the API at fiq.kemeinnovations.com (cPanel)

1. **Subdomain.** cPanel > Domains > Create `fiq.kemeinnovations.com`. Set the *document root* to the project's `public/` folder, e.g. `/home/USER/fiq/public`, NOT `public_html`. The project root (with `.env`, `app/`, `writable/`) must sit above the document root.
2. **DNS.** If the zone is not managed by cPanel, add an A record `fiq` pointing to the server IP.
3. **HTTPS.** cPanel > SSL/TLS Status > run AutoSSL for the subdomain. The API redirects HTTP to HTTPS (`forcehttps` filter). Mobile builds use `https://fiq.kemeinnovations.com/api/v1`.
4. **PHP.** Select PHP 8.2+ for the subdomain with extensions: intl, mbstring, mysqlnd, curl, json.
5. **Install.**
   ```bash
   cd /home/USER
   composer create-project codeigniter4/appstarter fiq
   # copy the backend overlay (app/, tests/, docs/) over it; keep the overlay's app/Config/Routes.php and Filters.php
   cd fiq && cp env .env   # then paste values from env.example
   chmod 600 .env
   php spark migrate
   php spark db:seed DatabaseSeeder
   php spark user:create you@kemeinnovations.com admin
   ```
   In `.env` set the database credentials, `APIFOOTBALL_KEY` and `ANTHROPIC_API_KEY`. Keep `CI_ENVIRONMENT = production`.
6. **Authorization header (important on cPanel).** Apache with CGI/FastCGI often strips `Authorization`, which would make every authenticated call return 401. Add to `public/.htaccess`, above the existing rewrite rules:
   ```apache
   RewriteEngine On
   RewriteCond %{HTTP:Authorization} .
   RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization}]
   ```
7. **Cron** (cPanel > Cron Jobs):
   ```
   * * * * *    /usr/local/bin/php /home/USER/fiq/spark jobs:work --limit=10
   0 */6 * * *  /usr/local/bin/php /home/USER/fiq/spark ingest:fixtures --days=2 --queue
   15 */3 * * * /usr/local/bin/php /home/USER/fiq/spark ingest:odds --days=2 --limit=40
   45 */3 * * * /usr/local/bin/php /home/USER/fiq/spark predict:run --days=3
   30 * * * *   /usr/local/bin/php /home/USER/fiq/spark predict:settle
   ```
   Adjust to your API-Football plan's daily request limit: odds cost one call per fixture (up to three pages).
8. **Smoke test.**
   ```bash
   curl -s https://fiq.kemeinnovations.com/api/v1/health
   curl -s -X POST https://fiq.kemeinnovations.com/api/v1/auth/login -H 'Content-Type: application/json' \
        -d '{"email":"you@kemeinnovations.com","password":"..."}'
   ```
9. **Mobile.** Release builds default to the production URL; for local work use `--dart-define=API_BASE_URL=http://10.0.2.2:8080/api/v1`.

Security notes: `.env` and `writable/` must not be web-accessible (they are not when the document root is `public/`); the Anthropic and API-Football keys stay server-side only; back up MySQL and test a restore before launch.
