Load .env.<APP_ENV>, validate config at boot, keep secrets out of the image
`main.go` only ever loaded `.env`; the `APP_ENV` switch described in `.env.local` / `.env.production` did not exist, and a missing variable surfaced one restart at a time as a log.Fatalf inside db.Connect. config.Load now picks `.env.<APP_ENV>` (default local) then `.env`, with real environment winning, reads every setting into one typed Config and reports everything missing in one message. Production insists on a POS signing secret; local warns when DB_HOST is not a local address. db, redis and the image store take the Config instead of reading env themselves. Also: - livehub read MQTT_USERNAME while everything else uses MQTT_USER, so the console stream connected to the broker unauthenticated. Both accepted. - .dockerignore: `COPY . .` was baking .env.production into the image. Dockerfile sets APP_ENV=production. - Drop utils/config.go (dead viper loader) and create_table.go (unused, hardcoded production DSN); go mod tidy removes viper. - .env.example lists every variable the code reads; docs/ENVIRONMENT.md. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -11,13 +11,15 @@
|
||||
# run. If the point is to try a change before it ships, use `.env.local` with a
|
||||
# dump restored into the local Postgres — that is the only version that does.
|
||||
#
|
||||
# Gitignored by `.env.*`. Never commit it, and never paste it into a chat, an
|
||||
# issue or a PR description: the credentials below have to be rotated if it
|
||||
# leaves this machine.
|
||||
# On the deployed host these values come from the platform's environment
|
||||
# settings (Dokploy / Kubernetes), never from this file: the image is built
|
||||
# without any `.env.*` (see .dockerignore). Keep the two in step — a variable
|
||||
# added here and not there is a variable that is unset in production, and
|
||||
# startup will refuse to boot on a missing required one.
|
||||
#
|
||||
# On the deployed host these values come from Dokploy's environment settings
|
||||
# rather than from this file. Keep the two in step — a variable added here and
|
||||
# not there is a variable that is unset in production.
|
||||
# This file is currently committed to git, which means every credential in it
|
||||
# has to be treated as public: rotate them, and keep the new values out of
|
||||
# the repository.
|
||||
|
||||
# ── Where it listens ────────────────────────────────────────────────────────
|
||||
APP_PORT=1009
|
||||
|
||||
Reference in New Issue
Block a user