-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.env.example
More file actions
95 lines (86 loc) · 4.64 KB
/
Copy path.env.example
File metadata and controls
95 lines (86 loc) · 4.64 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# pulse-frontend environment variables
#
# NEXT_PUBLIC_* values are inlined into the client JavaScript bundle by
# `next build`. They MUST be set at build time:
# - In CI: via `build-args:` in .github/workflows/build-and-push.yml
# - In local dev: via `.env.local` (copy this file to .env.local first)
#
# Prod vs staging differences are set in the CI workflow's `target` step,
# keyed on github.ref (main → prod, staging → staging-app).
#
# Values prefixed with NEXT_PUBLIC_ end up in the browser and are NOT secret.
#
# scripts/validate-env.mjs enforces that required vars are set at build time
# and fails the build loudly if not — no more silent localhost fallbacks
# shipping to production.
# -------- REQUIRED at build time (all client-side, all baked into bundle) --------
# pulse-backend API base URL.
# Prod: https://pulse-api.ciphera.net
# Staging: https://pulse-api-staging.ciphera.net
# Dev: http://localhost:8082
NEXT_PUBLIC_API_URL=https://pulse-api.ciphera.net
# id-frontend public URL (used for OAuth redirects from pulse → id).
# Prod + Staging: https://id.ciphera.net
# Dev: http://localhost:3001
NEXT_PUBLIC_ID_URL=https://id.ciphera.net
# pulse-frontend's own public URL (used for self-links like /faq, OAuth
# callback redirect_uri, and the SiteVisibilityTab share link builder).
# Prod: https://pulse.ciphera.net
# Staging: https://pulse-staging.ciphera.net
# Dev: http://localhost:3003
NEXT_PUBLIC_APP_URL=https://pulse.ciphera.net
# id-backend API base URL (used by token refresh and server actions).
# Prod + Staging: https://api.id.ciphera.net
# Dev: http://localhost:8081
NEXT_PUBLIC_ID_API_URL=https://api.id.ciphera.net
# Captcha service base URL (includes /api/v1 suffix).
# Prod + Staging: https://captcha.ciphera.net/api/v1
# Dev: http://localhost:8083/api/v1
NEXT_PUBLIC_CAPTCHA_API_URL=https://captcha.ciphera.net/api/v1
# CDN base URL for static images (includes project prefix)
# Leave empty for local development (serves from public/)
# Production: https://cdn.ciphera.net/pulse
NEXT_PUBLIC_CDN_URL=
# ─────────────────────────────────────────────────────────────────────────────
# FAVICON_UPSTREAM_URL — REQUIRED, server-side only, no default.
#
# The upstream that /api/favicon proxies to. Unlike everything above this is a
# RUNTIME variable read by the route handler, not a NEXT_PUBLIC_* baked in at
# build time — it is set on the Kubernetes Deployment, so changing it is a
# rollout rather than a rebuild.
#
# There is deliberately NO fallback in the code. Until 13-08-2026 this route
# defaulted to https://www.google.com/s2/favicons, production never set the
# variable, and so every domain a Pulse customer tracks was resolved by Google.
# It never failed, which is exactly why nobody noticed. Unset now means 503.
#
# Prod + Staging: https://icons.ciphera.net/icon
# Sigil on Bunny Magic Containers, 42 regions. This is the ONLY
# resolver — see the note below.
# Dev: point this at any Sigil instance you can reach, or at
# https://icons.ciphera.net/icon. Leaving it unset renders
# monograms, which is the intended loud failure, not a bug.
#
# ⚠️ There is no longer an in-cluster Sigil. `http://sigil.apps.svc.cluster.local`
# resolves to nothing since 15-08-2026 — do not copy that value from an older
# copy of this file, a runbook, or git history.
FAVICON_UPSTREAM_URL=https://icons.ciphera.net/icon
# FAVICON_FALLBACK_UPSTREAM_URL — OPTIONAL second resolver.
#
# Tried only when the primary fails or has no icon. Absent means "no fallback",
# which is a supported deployment — unlike FAVICON_UPSTREAM_URL, this one is not
# required.
#
# ⛔ UNSET IN PRODUCTION AND STAGING SINCE 15-08-2026, and there is nothing to
# point it at. The in-cluster Sigil it used to name was deleted along with its
# Service and NetworkPolicy, making Magic Containers the only favicon resolver
# (owner decision — Infra/docs/plans/15-08-2026-mc-decommission-in-cluster-copies.md).
#
# The code branch is untouched and still unit-tested. Nothing was reverted — the
# variable is simply unconfigured, so do not "fix" app/api/favicon/route.ts.
#
# 🔴 If you ever set this again: it must NOT share the primary's failure modes.
# Pointing both at Bunny makes it decorative. Restoring an in-cluster resolver is
# a rebuild (Deployment + Service + NetworkPolicy — the netpol is the step people
# forget, and without it every icon silently 404s), not just setting this line.
# FAVICON_FALLBACK_UPSTREAM_URL=