Stop tracking .env
It has been in the repository since the initial commit carrying the live database host, user and password. Removing it from the index stops that getting worse; the credentials are still in history and should be rotated, which needs coordinating with everything that reads them. Deployments should pass configuration as container environment rather than shipping a file — a file on disk is one `git add -f` away from being committed again. Also closes the last untested path: a shopper registration published over the broker rather than posted over HTTP. All three MQTT topics — order, customer and health — have now been fired against the live Mosquitto instance and acknowledged. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
21
.env
21
.env
@@ -1,21 +0,0 @@
|
||||
APP_PORT=1009
|
||||
DB_HOST=66.116.207.225
|
||||
DB_PORT=5433
|
||||
DB_NAME=nearledb
|
||||
DB_USER=admin
|
||||
DB_PASSWORD="Package@123#"
|
||||
|
||||
# --- Catalogue Postgres / pgvector (separate DB, read-only integration) ---
|
||||
CATALOGUE_DB_HOST=31.97.228.132
|
||||
CATALOGUE_DB_PORT=6054
|
||||
CATALOGUE_DB_NAME=pgvector
|
||||
CATALOGUE_DB_USER=admin
|
||||
CATALOGUE_DB_PASSWORD="'Package@321#'"
|
||||
|
||||
# --- DigitalOcean Spaces (S3-compatible), catalogue product images ---
|
||||
USE_S3=true
|
||||
S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ
|
||||
S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug
|
||||
S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com
|
||||
S3_BUCKET=nearle
|
||||
S3_REGION=sgp1
|
||||
Reference in New Issue
Block a user