Files
doormile_backend/.env.example

64 lines
2.4 KiB
Plaintext

# App Config
APP_PORT=8081
ENV=development
JWT_SECRET_KEY=change-me-locally
INTERNAL_API_KEY=doormile-internal-2024
# Reverse proxy — comma-separated IPs/CIDRs allowed to set X-Forwarded-For.
# Rate limiting keys on the client IP, so if this service sits behind nginx or
# any TLS terminator this MUST list that proxy; otherwise every request looks
# like it came from the proxy and all clients share one rate-limit bucket.
# Leave empty only when the app is exposed directly.
# TRUSTED_PROXIES=127.0.0.1,10.0.0.0/8
# PostgreSQL Database Configuration
DB_HOST=31.97.228.132
DB_PORT=5433
DB_NAME=logistics
DB_USER=admin
DB_PASSWORD=
# Redis Configuration
REDIS_HOST=31.97.228.132
REDIS_PORT=6379
REDIS_USER=admin
REDIS_PASSWORD=
# SMTP Configuration (email OTP verification)
SMTP_HOST=smtp.gmail.com
SMTP_PORT=465
SMTP_USER=your-email@gmail.com
SMTP_PASSWORD=your-16-char-app-password
SMTP_FROM=your-email@gmail.com
$env:PATH += ";C:\Program Files\Docker\Docker\resources\bin"
>>
>> docker build -t doormile/doormile-backend:latest .
>> docker push doormile/doormile-backend:latest
>>
# ── Required / changed 2026-09-11 ───────────────────────────────────────────
# JWT_SECRET_KEY no longer has a default. It used to fall back to a literal in
# config/config.go, which meant anyone holding this repository could mint a
# valid token for any user id and any role against a deployment that had not
# overridden it.
# ENV=production + unset -> the service REFUSES TO START (cfg.Validate).
# anything else + unset -> an ephemeral per-process key is generated and a
# warning logged; tokens will not survive a restart.
# Set it for a stable local session, and make sure it is set in production
# before deploying (the JWT_SECRET_KEY line above).
#
# NATS_URL and the AI/optimiser hosts also lost their defaults, which pointed at
# the real production cluster — an unconfigured local run silently joined the
# live stream and competed with the production workers. Unset now means
# "disabled": no NATS connection, no route sequencing, legacy assignment
# scoring. Set them explicitly where you actually want them.
# NATS_URL=nats://localhost:4222
# NATS_USER=
# NATS_PASSWORD=
# AI_LAYER_BASE_URL=
# ROUTE_OPTIMIZER_URL=
#
# DB_PASSWORD has no default either — set it for your own database.