Load .env.<APP_ENV>, validate config at boot, keep secrets out of the image
`main.go` only ever loaded `.env`; the `APP_ENV` switch described in `.env.local` / `.env.production` did not exist, and a missing variable surfaced one restart at a time as a log.Fatalf inside db.Connect. config.Load now picks `.env.<APP_ENV>` (default local) then `.env`, with real environment winning, reads every setting into one typed Config and reports everything missing in one message. Production insists on a POS signing secret; local warns when DB_HOST is not a local address. db, redis and the image store take the Config instead of reading env themselves. Also: - livehub read MQTT_USERNAME while everything else uses MQTT_USER, so the console stream connected to the broker unauthenticated. Both accepted. - .dockerignore: `COPY . .` was baking .env.production into the image. Dockerfile sets APP_ENV=production. - Drop utils/config.go (dead viper loader) and create_table.go (unused, hardcoded production DSN); go mod tidy removes viper. - .env.example lists every variable the code reads; docs/ENVIRONMENT.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
23
.env
23
.env
@@ -1,16 +1,18 @@
|
||||
# Fiesta configuration.
|
||||
# Fiesta configuration — the shared base file.
|
||||
#
|
||||
# Copy to `.env` and fill in. `.env` and `.env.*` are gitignored (the one
|
||||
# exception is this file) — and they are gitignored for a reason: this
|
||||
# repository's history already contains a committed `.env` from before
|
||||
# 2026-08-03, so those database credentials are in the history and should be
|
||||
# rotated. Do not add another.
|
||||
# Loaded AFTER `.env.<APP_ENV>` (see config/config.go), and godotenv never
|
||||
# overwrites a value that is already set, so anything here is a fallback for
|
||||
# what the environment file and the real environment leave unset. Keep it
|
||||
# local: with APP_ENV unset this is loaded straight after `.env.local`, and a
|
||||
# production value here would silently reach a local run.
|
||||
#
|
||||
# `godotenv.Load()` in main.go reads `.env` from the working directory, so
|
||||
# `go run .` from this folder picks it up with no flags.
|
||||
# go run . → .env.local, then this file
|
||||
# APP_ENV=production go run . → .env.production, then this file
|
||||
#
|
||||
# The full list of settings, with what each one does, is in `.env.example`.
|
||||
|
||||
# ── Where it listens ────────────────────────────────────────────────────────
|
||||
# 1122 is what production serves on. Change it locally to run a second copy
|
||||
# 1122 locally; production serves on 1009. Change it to run a second copy
|
||||
# beside something else; the console then points at the same number.
|
||||
APP_PORT=1122
|
||||
|
||||
@@ -59,5 +61,8 @@ REDIS_USER=
|
||||
REDIS_DB=0
|
||||
|
||||
# ── Auth ────────────────────────────────────────────────────────────────────
|
||||
# Signs POS terminal sessions (16+ characters). A throwaway value so a till can
|
||||
# sign in against the local stack; production sets its own in the platform.
|
||||
POS_TOKEN_SECRET=local-dev-signing-secret-not-real
|
||||
JWT_SECRET_KEY=
|
||||
USER_CONTEXT_KEY=
|
||||
|
||||
Reference in New Issue
Block a user