-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
99 lines (89 loc) · 3.9 KB
/
Copy path.env.example
File metadata and controls
99 lines (89 loc) · 3.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
# Copy to .env. Values marked (required) must be set. Generate secrets with: openssl rand -base64 48
# ---- runtime ------------------------------------------------------------------------------
NODE_ENV=production
PORT=3333
LOG_LEVEL=info
# json in containers, pretty for local development (requires dev dependencies)
LOG_FORMAT=json
# number of reverse proxies in front of the api (Traefik = 1); 0 when exposed directly
TRUST_PROXY_HOPS=1
# ---- security -----------------------------------------------------------------------------
# (required) public https url of this api
APP_URL=https://api.example.com
# (required) 32+ random characters; keys the pseudonymous ballot ledger
APP_KEY=
# (required) comma separated web app origins allowed to call the api and receive logins.
# The first origin is the default login redirect target. Wildcards are not supported.
CORS_ORIGINS=https://app.example.com
# path on the web app that receives #code=... after Discord login
WEB_AUTH_CALLBACK_PATH=/auth/callback
SESSION_TTL_DAYS=30
# (required by docker compose) 32+ character secret shared by the api and the Discord bot
SERVICE_TOKEN=
# ---- postgres -----------------------------------------------------------------------------
DB_HOST=localhost
DB_PORT=5432
# schema owner, used only by migrations
DB_USER=platform
# (required)
DB_PASSWORD=
# docker compose: least-privilege role the api connects as (created on first database start)
APP_DB_USER=platform_app
# (required by docker compose)
APP_DB_PASSWORD=
DB_DATABASE=platform
# disable | require | verify-full
DB_SSL=disable
DB_POOL_MAX=20
# ---- redis --------------------------------------------------------------------------------
REDIS_HOST=localhost
REDIS_PORT=6379
# (required in production) use hex or base64 characters, e.g. openssl rand -hex 32
REDIS_PASSWORD=
REDIS_TLS=false
# docker compose only: memory cap for the redis container
REDIS_MAXMEMORY=128mb
# ---- discord application (shared by login and the bot) -----------------------------------
# (required)
DISCORD_CLIENT_ID=
# (required)
DISCORD_CLIENT_SECRET=
# (required) register in the Discord developer portal: <APP_URL>/api/v1/auth/discord/callback
DISCORD_REDIRECT_URI=https://api.example.com/api/v1/auth/discord/callback
# ---- discord bot ---------------------------------------------------------------------------
# (required by docker compose) bot token from the developer portal
DISCORD_BOT_TOKEN=
# (required by docker compose) the studio server the bot serves; it ignores every other server
DISCORD_GUILD_ID=
# (required by docker compose) web app origin used for "vote on the web" and docs links
WEB_APP_URL=https://app.example.com
# (optional) storage/CDN origins the web app may load media from and upload to, comma separated
WEB_STORAGE_ORIGINS=https://media.example.com,https://bucket.s3.example.com
# (optional) public Discord invite shown in the web app sidebar
DISCORD_INVITE_URL=
# ---- role assignment on login: comma separated Discord user ids ---------------------------
# at most two users; cannot be granted or revoked from the app
SUPER_ADMIN_DISCORD_IDS=
ADMIN_DISCORD_IDS=
SUPERVISOR_DISCORD_IDS=
MODERATOR_DISCORD_IDS=
SENIOR_DISCORD_IDS=
# ---- member verification -----------------------------------------------------------------
# (required in production) Resend API key and a sender on a domain verified in Resend
RESEND_API_KEY=
EMAIL_FROM=Stairway <verify@example.com>
# (required in production) Cloudflare Turnstile keys; hostname must match a CORS origin
TURNSTILE_SECRET_KEY=
TURNSTILE_SITE_KEY=
# ---- object storage (S3 / R2), optional ----------------------------------------------------
S3_ENDPOINT=
S3_REGION=auto
S3_ACCESS_KEY_ID=
S3_SECRET_ACCESS_KEY=
# private bucket for shot deliverables (downloads use short-lived signed urls)
S3_DELIVERABLES_BUCKET=
# public bucket for entry media, served from S3_MEDIA_PUBLIC_URL (https)
S3_MEDIA_BUCKET=
S3_MEDIA_PUBLIC_URL=
MEDIA_MAX_BYTES=5242880
DELIVERABLE_MAX_BYTES=2147483648