Files
loyaly-catalogue/backend/.env.production.example
sriram c7e4d59188 Electronics Catalog: API, MCP server, frontend and deployment
Verified catalogue of mobiles and laptops sold in India, collected from
real retail listings (FastAPI backend, React frontend, Postgres/pgvector).

- REST API under /api/elec (read-only catalogue; admin endpoints need login)
- MCP server (FastMCP) at /mcp/ with list_categories, search_products,
  get_product and price_history tools
- Real ratings and reviews read from product pages and search results
- Production Dockerfile (requirements-api.txt, no PyTorch) and
  .env.production.example; remote database only via an explicit
  ELEC_ALLOW_REMOTE_DB host/name allowlist
- docs/API.md: endpoint and MCP reference with live examples

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-01 12:17:42 +05:30

44 lines
1.9 KiB
Plaintext

# Production environment for the Electronics Catalog API container.
# Copy to .env.production (never committed, never baked into the image) or paste
# each line into the deployment platform's Environment settings.
# --- Database: the production copy in loyalycatalogue (schema elec) ---
DB_HOST=31.97.228.132
DB_PORT=6054
DB_NAME=loyalycatalogue
DB_USER=admin
# The server is remote: allow more than the 5 s local default to connect.
DB_CONNECT_TIMEOUT_SECONDS=15
# The single quotes ARE part of this password. Container env values are taken
# literally (docker --env-file and platform Environment tabs do not strip
# quotes), so write it exactly as the password, quotes included:
DB_PASSWORD='<production password>'
# Explicit opt-in past the local-only guard in settings.py. Exact host and
# database only; any other remote target is still refused.
ELEC_ALLOW_REMOTE_DB=true
ELEC_REMOTE_DB_HOSTS=31.97.228.132
ELEC_REMOTE_DB_NAMES=loyalycatalogue
# --- Features not available in the container ---
USE_OLLAMA=false
ELEC_USE_LLM=false
USE_EMBEDDINGS=false
# --- Web search (only used by admin collection runs) ---
USE_DDG_SEARCH=true
USE_GOOGLE_CSE=false
ELEC_CONTACT=<contact email for robots-polite fetching>
# --- Browser access: every first-party web app that calls this API, exact
# origins only (no "*"). Pinned by tests/test_cors_origins.py; add a new app
# there and here together. Non-browser callers (curl, MCP clients) ignore CORS. ---
API_CORS_ORIGINS=https://app.nearledaily.com,http://localhost:3100,https://catalogue.nearle.ai.in
# --- Auth: guards the admin endpoints. Never deploy with AUTH_ENABLED=false
# or AUTH_ALLOW_ANY_LOGIN=true. ---
AUTH_ENABLED=true
AUTH_ALLOW_ANY_LOGIN=false
AUTH_SECRET_KEY=<new random value: python -c "import secrets; print(secrets.token_urlsafe(48))">
AUTH_ADMIN_USERNAME=admin
AUTH_ADMIN_PASSWORD_HASH=<same PBKDF2 hash as the local backend/.env>