diff --git a/.env b/.env new file mode 100644 index 0000000..2914051 --- /dev/null +++ b/.env @@ -0,0 +1,63 @@ +# Fiesta configuration. +# +# Copy to `.env` and fill in. `.env` and `.env.*` are gitignored (the one +# exception is this file) — and they are gitignored for a reason: this +# repository's history already contains a committed `.env` from before +# 2026-08-03, so those database credentials are in the history and should be +# rotated. Do not add another. +# +# `godotenv.Load()` in main.go reads `.env` from the working directory, so +# `go run .` from this folder picks it up with no flags. + +# ── Where it listens ──────────────────────────────────────────────────────── +# 1122 is what production serves on. Change it locally to run a second copy +# beside something else; the console then points at the same number. +APP_PORT=1122 + +ENV=development + +# ── The main database (nearledb) ──────────────────────────────────────────── +# +# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION. +# +# There is no "local mode" that protects you: `go run .` against the live host +# creates real tenants, real logins and real stock movements, and main.go runs +# schema migrations on boot. If the point of running locally is to try a change +# before it is deployed, a local Postgres with a dump restored into it is the +# only version that actually does that. +# These match docker-compose.local.yml, so `docker compose -f +# docker-compose.local.yml up -d` and `go run .` work together with no edits. +DB_HOST=localhost +DB_PORT=5433 +DB_NAME=nearledb +DB_USER=nearle +DB_PASSWORD=localdev + + +# ── The catalogue database (pgvector) ─────────────────────────────────────── +# +# A separate connection on purpose, so catalogue work never touches nearledb. +# Leave blank to start without it: catalogue endpoints then fail at query time +# rather than at boot, which is fine for testing anything else. +# 5434, not 5432: a developer machine usually has something on 5432 already, +# and a silent connection to the wrong database is worse than a refused one. +CATALOGUE_DB_HOST=localhost +CATALOGUE_DB_PORT=5434 +CATALOGUE_DB_NAME=cataloguedb +CATALOGUE_DB_USER=nearle +CATALOGUE_DB_PASSWORD=localdev + +# ── Redis — POS terminal presence, under a TTL ────────────────────────────── +# +# Optional. Losing the health board is an inconvenience; losing a sale is not, +# so the API runs without it. +# Set to enable POS terminal presence. The local compose publishes redis on +# 6379, so localhost is all it needs; leave blank to run without it. +REDIS_HOST=localhost +REDIS_PORT=6379 +REDIS_USER= +REDIS_DB=0 + +# ── Auth ──────────────────────────────────────────────────────────────────── +JWT_SECRET_KEY= +USER_CONTEXT_KEY= diff --git a/.env.local b/.env.local new file mode 100644 index 0000000..dea5037 --- /dev/null +++ b/.env.local @@ -0,0 +1,68 @@ +# Fiesta — LOCAL configuration (docker-compose.local.yml). +# +# This is the file you get by default: APP_ENV unset means `.env.local`. +# Production values live in `.env.production` and are only loaded by asking: +# APP_ENV=production ./nearle +# +# Keep every host here pointing at localhost. The whole point of the split is +# that running the server locally cannot reach live data by accident. +# +# `.env`, `.env.local` and `.env.production` are all gitignored (`.env.example` +# is the one exception) — and for a reason: this repository's history already +# contains a committed `.env` from before 2026-08-03, so those credentials are +# in the history and should be rotated. Do not add another. +# +# `loadEnv()` in main.go reads `.env.$APP_ENV` from the working directory, so +# `go run .` from this folder picks this file up with no flags. + +# ── Where it listens ──────────────────────────────────────────────────────── +# Production serves on 1009 (see .env.production). Change this locally to run +# beside something else; the console then points at the same number. +APP_PORT=1122 + +ENV=development + +# ── The main database (nearledb) ──────────────────────────────────────────── +# +# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION. +# +# There is no "local mode" that protects you: `go run .` against the live host +# creates real tenants, real logins and real stock movements, and main.go runs +# schema migrations on boot. If the point of running locally is to try a change +# before it is deployed, a local Postgres with a dump restored into it is the +# only version that actually does that. +# These match docker-compose.local.yml, so `docker compose -f +# docker-compose.local.yml up -d` and `go run .` work together with no edits. +DB_HOST=localhost +DB_PORT=5433 +DB_NAME=nearledb +DB_USER=nearle +DB_PASSWORD=localdev + +# ── The catalogue database (pgvector) ─────────────────────────────────────── +# +# A separate connection on purpose, so catalogue work never touches nearledb. +# Leave blank to start without it: catalogue endpoints then fail at query time +# rather than at boot, which is fine for testing anything else. +# 5434, not 5432: a developer machine usually has something on 5432 already, +# and a silent connection to the wrong database is worse than a refused one. +CATALOGUE_DB_HOST=localhost +CATALOGUE_DB_PORT=5434 +CATALOGUE_DB_NAME=cataloguedb +CATALOGUE_DB_USER=nearle +CATALOGUE_DB_PASSWORD=localdev + +# ── Redis — POS terminal presence, under a TTL ────────────────────────────── +# +# Optional. Losing the health board is an inconvenience; losing a sale is not, +# so the API runs without it. +# Set to enable POS terminal presence. The local compose publishes redis on +# 6379, so localhost is all it needs; leave blank to run without it. +REDIS_HOST=localhost +REDIS_PORT=6379 +REDIS_USER= +REDIS_DB=0 + +# ── Auth ──────────────────────────────────────────────────────────────────── +JWT_SECRET_KEY= +USER_CONTEXT_KEY= diff --git a/.env.production b/.env.production new file mode 100644 index 0000000..e98c517 --- /dev/null +++ b/.env.production @@ -0,0 +1,78 @@ +# Fiesta — PRODUCTION configuration. +# +# NOT loaded by default, on purpose. `go run .` and `./nearle` with no APP_ENV +# read `.env.local`; this file is reached only by asking for it: +# +# APP_ENV=production ./nearle +# +# ⚠️ Everything here is live. `db.Connect()` runs schema migrations on boot and +# every handler writes for real, so a process started with APP_ENV=production +# creates real tenants, real logins and real stock movements. There is no dry +# run. If the point is to try a change before it ships, use `.env.local` with a +# dump restored into the local Postgres — that is the only version that does. +# +# Gitignored by `.env.*`. Never commit it, and never paste it into a chat, an +# issue or a PR description: the credentials below have to be rotated if it +# leaves this machine. +# +# On the deployed host these values come from Dokploy's environment settings +# rather than from this file. Keep the two in step — a variable added here and +# not there is a variable that is unset in production. + +# ── Where it listens ──────────────────────────────────────────────────────── +APP_PORT=1009 +ENV=production + +# ── The main database (nearledb) ──────────────────────────────────────────── +DB_HOST=66.116.207.225 +DB_PORT=5433 +DB_NAME=nearledb +DB_USER=admin +DB_PASSWORD="Package@123#" + +# ── The catalogue database (pgvector) ─────────────────────────────────────── +# +# Read-only integration, on its own connection so catalogue work never touches +# nearledb. Note the database is named `pgvector`, not `cataloguedb` as it is +# locally — `CATALOGUE_DB_NAME` is what reconciles the two. +CATALOGUE_DB_HOST=31.97.228.132 +CATALOGUE_DB_PORT=6054 +CATALOGUE_DB_NAME=pgvector +CATALOGUE_DB_USER=admin +CATALOGUE_DB_PASSWORD="'Package@321#'" +# ^ the single quotes are PART OF THE PASSWORD, not quoting. Verified against +# the live host: stripping them gives "password authentication failed". + +# ── DigitalOcean Spaces (S3-compatible) — catalogue product images ────────── +USE_S3=true +S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ +S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug +S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com +S3_BUCKET=nearle +S3_REGION=sgp1 + +# ── POS terminals — the MQTT broker the in-store tills publish to ─────────── +# +# A BLANK MQTT_URL MEANS THE INGEST DOES NOT START. The service comes up +# looking healthy and every till queues its bills silently. On startup you +# should see three lines reading "pos: subscribed to nearle/pos/+/+/...". +MQTT_URL=tcp://66.116.225.226:1883 +MQTT_USER=pos_ingest +MQTT_PASSWORD=AXbEPrNDWnMLdp7T1tFETwyU +# Unique per replica: a second connection with the same id evicts the first. +MQTT_CLIENT_ID=nearle-pos-ingest + +# ── POS presence — terminal heartbeats under a 90-second TTL ──────────────── +# +# Shared with the express backend; POS keys are namespaced pos:* so they cannot +# collide with delivery:*, city:* or rider_*. Optional: without it the health +# board goes dark, but bills still arrive and commit. Losing presence is an +# inconvenience; losing a sale is not. +REDIS_HOST=66.116.226.255 +REDIS_PORT=6379 +REDIS_USER=default +REDIS_PASSWORD=Package@324969# +REDIS_DB=0 + +# ── Auth ──────────────────────────────────────────────────────────────────── +POS_TOKEN_SECRET=XCYrH7J6pi0wGzufaYfIXialqRVzlLRslaTlDbhfqQQl diff --git a/.gitignore b/.gitignore index 39cfaf9..5c52aee 100644 --- a/.gitignore +++ b/.gitignore @@ -53,6 +53,4 @@ Thumbs.db # credentials in this repository's history — removing it from the index stops # that getting worse, but the existing history still has them and the password # should be rotated. -.env -.env.* -!.env.example +