Stop tracking .env and restore the ignore rules that 3455ad0 removed
3455ad0 deleted the .env patterns from .gitignore and committed a
real .env carrying a live ANTHROPIC_API_KEY. Two problems:
- The key is now in shared history and must be rotated; untracking
the file here stops the bleeding but does not un-publish it.
- That .env does not boot the API. It sets ANTHROPIC_API_KEY with no
MODEL_API_KEY, which config.go:503 refuses at startup — the same
guard that crash-looped krow-2 on 2026-09-07. Nothing in the
codebase reads ANTHROPIC_API_KEY; the MCP surface needs
OAUTH_ISSUER and MCP_RESOURCE, not a model credential.
The file stays on disk and is ignored again, along with
infrastructure/.env which the deleted pattern also covered.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PJvibeSc1JYXjatankqM1g
This commit is contained in:
67
.env
67
.env
@@ -1,67 +0,0 @@
|
||||
# ============================================================================
|
||||
# Krow backend — example environment
|
||||
#
|
||||
# Copy to .env and fill in. .env is gitignored and must never be committed.
|
||||
# Every value below is a placeholder or a safe local default: no real password,
|
||||
# API key or token belongs in this file.
|
||||
#
|
||||
# cp .env.example .env
|
||||
# ============================================================================
|
||||
|
||||
# ── Application ─────────────────────────────────────────────────────────────
|
||||
APP_ENV=development
|
||||
LOG_LEVEL=info # debug | info | warn | error
|
||||
|
||||
# ── HTTP server ─────────────────────────────────────────────────────────────
|
||||
HTTP_HOST=127.0.0.1
|
||||
HTTP_PORT=8080
|
||||
HTTP_READ_TIMEOUT=15s
|
||||
# An agent run on the deep tier may legally take 2m0s. A 30s write timeout
|
||||
# aborted the response mid-run and the proxy reported it as 502.
|
||||
HTTP_WRITE_TIMEOUT=2m30s
|
||||
HTTP_IDLE_TIMEOUT=60s
|
||||
HTTP_SHUTDOWN_TIMEOUT=10s
|
||||
|
||||
# ── PostgreSQL ──────────────────────────────────────────────────────────────
|
||||
# The local development database. DATABASE_NAME is mixed-case and hyphenated,
|
||||
# so anything that interpolates it into SQL must quote it: "Krow-force".
|
||||
DATABASE_HOST=127.0.0.1
|
||||
DATABASE_PORT=5432
|
||||
DATABASE_NAME=Krow-force
|
||||
DATABASE_USER=postgres
|
||||
DATABASE_PASSWORD=
|
||||
DATABASE_SCHEMA=public
|
||||
|
||||
# sslmode: disable is fine for a loopback dev database. APP_ENV=production
|
||||
# rejects `disable` at startup — use require or verify-full there.
|
||||
DATABASE_SSLMODE=disable
|
||||
|
||||
# Pool and timeout tuning.
|
||||
DATABASE_MAX_OPEN_CONNS=25
|
||||
DATABASE_MIN_IDLE_CONNS=2
|
||||
DATABASE_CONN_MAX_LIFETIME=30m
|
||||
DATABASE_CONNECT_TIMEOUT=5s
|
||||
DATABASE_STATEMENT_TIMEOUT=10s
|
||||
|
||||
# ── Migrations ──────────────────────────────────────────────────────────────
|
||||
# Consumed by the Makefile, which builds the golang-migrate URL from the
|
||||
# DATABASE_* values above. Keep it pointed at the repository's migrations/.
|
||||
MIGRATIONS_DIR=./migrations
|
||||
|
||||
# ── Seed ────────────────────────────────────────────────────────────────────
|
||||
# The demo fixture, generated from the frontend repository's src/api/seed.js.
|
||||
# The Makefile passes an absolute path; this default suits running from the
|
||||
# repository root.
|
||||
SEED_FIXTURE_PATH=./seed/fixtures/seed.json
|
||||
|
||||
# ── Model gateway ───────────────────────────────────────────────────────────
|
||||
ANTHROPIC_API_KEY=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
|
||||
|
||||
# ── Knowledge layer (retrieval) ─────────────────────────────────────────────
|
||||
# A real semantic embedding model, running locally. No credential, no per-token
|
||||
# cost, and no tenant text leaving this machine. Change either of the first two
|
||||
# and the stored vectors stop being searched — run `make reembed ORG=<slug>`.
|
||||
EMBED_PROVIDER=ollama
|
||||
EMBED_MODEL=nomic-embed-text
|
||||
EMBED_DIMENSIONS=768
|
||||
EMBED_BASE_URL=http://localhost:11434
|
||||
3
.gitignore
vendored
3
.gitignore
vendored
@@ -1,5 +1,8 @@
|
||||
# Secrets and local configuration
|
||||
# A bare pattern matches at any depth, so this covers infrastructure/.env too.
|
||||
.env
|
||||
.env.local
|
||||
.env.*.local
|
||||
|
||||
# TLS material. The local-db overlay generates a self-signed pair inside the
|
||||
# postgres volume, but nothing stops someone dropping certs here by hand.
|
||||
|
||||
Reference in New Issue
Block a user