env
This commit is contained in:
63
.env
Normal file
63
.env
Normal file
@@ -0,0 +1,63 @@
|
|||||||
|
# Fiesta configuration.
|
||||||
|
#
|
||||||
|
# Copy to `.env` and fill in. `.env` and `.env.*` are gitignored (the one
|
||||||
|
# exception is this file) — and they are gitignored for a reason: this
|
||||||
|
# repository's history already contains a committed `.env` from before
|
||||||
|
# 2026-08-03, so those database credentials are in the history and should be
|
||||||
|
# rotated. Do not add another.
|
||||||
|
#
|
||||||
|
# `godotenv.Load()` in main.go reads `.env` from the working directory, so
|
||||||
|
# `go run .` from this folder picks it up with no flags.
|
||||||
|
|
||||||
|
# ── Where it listens ────────────────────────────────────────────────────────
|
||||||
|
# 1122 is what production serves on. Change it locally to run a second copy
|
||||||
|
# beside something else; the console then points at the same number.
|
||||||
|
APP_PORT=1122
|
||||||
|
|
||||||
|
ENV=development
|
||||||
|
|
||||||
|
# ── The main database (nearledb) ────────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION.
|
||||||
|
#
|
||||||
|
# There is no "local mode" that protects you: `go run .` against the live host
|
||||||
|
# creates real tenants, real logins and real stock movements, and main.go runs
|
||||||
|
# schema migrations on boot. If the point of running locally is to try a change
|
||||||
|
# before it is deployed, a local Postgres with a dump restored into it is the
|
||||||
|
# only version that actually does that.
|
||||||
|
# These match docker-compose.local.yml, so `docker compose -f
|
||||||
|
# docker-compose.local.yml up -d` and `go run .` work together with no edits.
|
||||||
|
DB_HOST=localhost
|
||||||
|
DB_PORT=5433
|
||||||
|
DB_NAME=nearledb
|
||||||
|
DB_USER=nearle
|
||||||
|
DB_PASSWORD=localdev
|
||||||
|
|
||||||
|
|
||||||
|
# ── The catalogue database (pgvector) ───────────────────────────────────────
|
||||||
|
#
|
||||||
|
# A separate connection on purpose, so catalogue work never touches nearledb.
|
||||||
|
# Leave blank to start without it: catalogue endpoints then fail at query time
|
||||||
|
# rather than at boot, which is fine for testing anything else.
|
||||||
|
# 5434, not 5432: a developer machine usually has something on 5432 already,
|
||||||
|
# and a silent connection to the wrong database is worse than a refused one.
|
||||||
|
CATALOGUE_DB_HOST=localhost
|
||||||
|
CATALOGUE_DB_PORT=5434
|
||||||
|
CATALOGUE_DB_NAME=cataloguedb
|
||||||
|
CATALOGUE_DB_USER=nearle
|
||||||
|
CATALOGUE_DB_PASSWORD=localdev
|
||||||
|
|
||||||
|
# ── Redis — POS terminal presence, under a TTL ──────────────────────────────
|
||||||
|
#
|
||||||
|
# Optional. Losing the health board is an inconvenience; losing a sale is not,
|
||||||
|
# so the API runs without it.
|
||||||
|
# Set to enable POS terminal presence. The local compose publishes redis on
|
||||||
|
# 6379, so localhost is all it needs; leave blank to run without it.
|
||||||
|
REDIS_HOST=localhost
|
||||||
|
REDIS_PORT=6379
|
||||||
|
REDIS_USER=
|
||||||
|
REDIS_DB=0
|
||||||
|
|
||||||
|
# ── Auth ────────────────────────────────────────────────────────────────────
|
||||||
|
JWT_SECRET_KEY=
|
||||||
|
USER_CONTEXT_KEY=
|
||||||
68
.env.local
Normal file
68
.env.local
Normal file
@@ -0,0 +1,68 @@
|
|||||||
|
# Fiesta — LOCAL configuration (docker-compose.local.yml).
|
||||||
|
#
|
||||||
|
# This is the file you get by default: APP_ENV unset means `.env.local`.
|
||||||
|
# Production values live in `.env.production` and are only loaded by asking:
|
||||||
|
# APP_ENV=production ./nearle
|
||||||
|
#
|
||||||
|
# Keep every host here pointing at localhost. The whole point of the split is
|
||||||
|
# that running the server locally cannot reach live data by accident.
|
||||||
|
#
|
||||||
|
# `.env`, `.env.local` and `.env.production` are all gitignored (`.env.example`
|
||||||
|
# is the one exception) — and for a reason: this repository's history already
|
||||||
|
# contains a committed `.env` from before 2026-08-03, so those credentials are
|
||||||
|
# in the history and should be rotated. Do not add another.
|
||||||
|
#
|
||||||
|
# `loadEnv()` in main.go reads `.env.$APP_ENV` from the working directory, so
|
||||||
|
# `go run .` from this folder picks this file up with no flags.
|
||||||
|
|
||||||
|
# ── Where it listens ────────────────────────────────────────────────────────
|
||||||
|
# Production serves on 1009 (see .env.production). Change this locally to run
|
||||||
|
# beside something else; the console then points at the same number.
|
||||||
|
APP_PORT=1122
|
||||||
|
|
||||||
|
ENV=development
|
||||||
|
|
||||||
|
# ── The main database (nearledb) ────────────────────────────────────────────
|
||||||
|
#
|
||||||
|
# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION.
|
||||||
|
#
|
||||||
|
# There is no "local mode" that protects you: `go run .` against the live host
|
||||||
|
# creates real tenants, real logins and real stock movements, and main.go runs
|
||||||
|
# schema migrations on boot. If the point of running locally is to try a change
|
||||||
|
# before it is deployed, a local Postgres with a dump restored into it is the
|
||||||
|
# only version that actually does that.
|
||||||
|
# These match docker-compose.local.yml, so `docker compose -f
|
||||||
|
# docker-compose.local.yml up -d` and `go run .` work together with no edits.
|
||||||
|
DB_HOST=localhost
|
||||||
|
DB_PORT=5433
|
||||||
|
DB_NAME=nearledb
|
||||||
|
DB_USER=nearle
|
||||||
|
DB_PASSWORD=localdev
|
||||||
|
|
||||||
|
# ── The catalogue database (pgvector) ───────────────────────────────────────
|
||||||
|
#
|
||||||
|
# A separate connection on purpose, so catalogue work never touches nearledb.
|
||||||
|
# Leave blank to start without it: catalogue endpoints then fail at query time
|
||||||
|
# rather than at boot, which is fine for testing anything else.
|
||||||
|
# 5434, not 5432: a developer machine usually has something on 5432 already,
|
||||||
|
# and a silent connection to the wrong database is worse than a refused one.
|
||||||
|
CATALOGUE_DB_HOST=localhost
|
||||||
|
CATALOGUE_DB_PORT=5434
|
||||||
|
CATALOGUE_DB_NAME=cataloguedb
|
||||||
|
CATALOGUE_DB_USER=nearle
|
||||||
|
CATALOGUE_DB_PASSWORD=localdev
|
||||||
|
|
||||||
|
# ── Redis — POS terminal presence, under a TTL ──────────────────────────────
|
||||||
|
#
|
||||||
|
# Optional. Losing the health board is an inconvenience; losing a sale is not,
|
||||||
|
# so the API runs without it.
|
||||||
|
# Set to enable POS terminal presence. The local compose publishes redis on
|
||||||
|
# 6379, so localhost is all it needs; leave blank to run without it.
|
||||||
|
REDIS_HOST=localhost
|
||||||
|
REDIS_PORT=6379
|
||||||
|
REDIS_USER=
|
||||||
|
REDIS_DB=0
|
||||||
|
|
||||||
|
# ── Auth ────────────────────────────────────────────────────────────────────
|
||||||
|
JWT_SECRET_KEY=
|
||||||
|
USER_CONTEXT_KEY=
|
||||||
78
.env.production
Normal file
78
.env.production
Normal file
@@ -0,0 +1,78 @@
|
|||||||
|
# Fiesta — PRODUCTION configuration.
|
||||||
|
#
|
||||||
|
# NOT loaded by default, on purpose. `go run .` and `./nearle` with no APP_ENV
|
||||||
|
# read `.env.local`; this file is reached only by asking for it:
|
||||||
|
#
|
||||||
|
# APP_ENV=production ./nearle
|
||||||
|
#
|
||||||
|
# ⚠️ Everything here is live. `db.Connect()` runs schema migrations on boot and
|
||||||
|
# every handler writes for real, so a process started with APP_ENV=production
|
||||||
|
# creates real tenants, real logins and real stock movements. There is no dry
|
||||||
|
# run. If the point is to try a change before it ships, use `.env.local` with a
|
||||||
|
# dump restored into the local Postgres — that is the only version that does.
|
||||||
|
#
|
||||||
|
# Gitignored by `.env.*`. Never commit it, and never paste it into a chat, an
|
||||||
|
# issue or a PR description: the credentials below have to be rotated if it
|
||||||
|
# leaves this machine.
|
||||||
|
#
|
||||||
|
# On the deployed host these values come from Dokploy's environment settings
|
||||||
|
# rather than from this file. Keep the two in step — a variable added here and
|
||||||
|
# not there is a variable that is unset in production.
|
||||||
|
|
||||||
|
# ── Where it listens ────────────────────────────────────────────────────────
|
||||||
|
APP_PORT=1009
|
||||||
|
ENV=production
|
||||||
|
|
||||||
|
# ── The main database (nearledb) ────────────────────────────────────────────
|
||||||
|
DB_HOST=66.116.207.225
|
||||||
|
DB_PORT=5433
|
||||||
|
DB_NAME=nearledb
|
||||||
|
DB_USER=admin
|
||||||
|
DB_PASSWORD="Package@123#"
|
||||||
|
|
||||||
|
# ── The catalogue database (pgvector) ───────────────────────────────────────
|
||||||
|
#
|
||||||
|
# Read-only integration, on its own connection so catalogue work never touches
|
||||||
|
# nearledb. Note the database is named `pgvector`, not `cataloguedb` as it is
|
||||||
|
# locally — `CATALOGUE_DB_NAME` is what reconciles the two.
|
||||||
|
CATALOGUE_DB_HOST=31.97.228.132
|
||||||
|
CATALOGUE_DB_PORT=6054
|
||||||
|
CATALOGUE_DB_NAME=pgvector
|
||||||
|
CATALOGUE_DB_USER=admin
|
||||||
|
CATALOGUE_DB_PASSWORD="'Package@321#'"
|
||||||
|
# ^ the single quotes are PART OF THE PASSWORD, not quoting. Verified against
|
||||||
|
# the live host: stripping them gives "password authentication failed".
|
||||||
|
|
||||||
|
# ── DigitalOcean Spaces (S3-compatible) — catalogue product images ──────────
|
||||||
|
USE_S3=true
|
||||||
|
S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ
|
||||||
|
S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug
|
||||||
|
S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com
|
||||||
|
S3_BUCKET=nearle
|
||||||
|
S3_REGION=sgp1
|
||||||
|
|
||||||
|
# ── POS terminals — the MQTT broker the in-store tills publish to ───────────
|
||||||
|
#
|
||||||
|
# A BLANK MQTT_URL MEANS THE INGEST DOES NOT START. The service comes up
|
||||||
|
# looking healthy and every till queues its bills silently. On startup you
|
||||||
|
# should see three lines reading "pos: subscribed to nearle/pos/+/+/...".
|
||||||
|
MQTT_URL=tcp://66.116.225.226:1883
|
||||||
|
MQTT_USER=pos_ingest
|
||||||
|
MQTT_PASSWORD=AXbEPrNDWnMLdp7T1tFETwyU
|
||||||
|
# Unique per replica: a second connection with the same id evicts the first.
|
||||||
|
MQTT_CLIENT_ID=nearle-pos-ingest
|
||||||
|
|
||||||
|
# ── POS presence — terminal heartbeats under a 90-second TTL ────────────────
|
||||||
|
#
|
||||||
|
# Shared with the express backend; POS keys are namespaced pos:* so they cannot
|
||||||
|
# collide with delivery:*, city:* or rider_*. Optional: without it the health
|
||||||
|
# board goes dark, but bills still arrive and commit. Losing presence is an
|
||||||
|
# inconvenience; losing a sale is not.
|
||||||
|
REDIS_HOST=66.116.226.255
|
||||||
|
REDIS_PORT=6379
|
||||||
|
REDIS_USER=default
|
||||||
|
REDIS_PASSWORD=Package@324969#
|
||||||
|
REDIS_DB=0
|
||||||
|
|
||||||
|
# ── Auth ────────────────────────────────────────────────────────────────────
|
||||||
|
POS_TOKEN_SECRET=XCYrH7J6pi0wGzufaYfIXialqRVzlLRslaTlDbhfqQQl
|
||||||
4
.gitignore
vendored
4
.gitignore
vendored
@@ -53,6 +53,4 @@ Thumbs.db
|
|||||||
# credentials in this repository's history — removing it from the index stops
|
# credentials in this repository's history — removing it from the index stops
|
||||||
# that getting worse, but the existing history still has them and the password
|
# that getting worse, but the existing history still has them and the password
|
||||||
# should be rotated.
|
# should be rotated.
|
||||||
.env
|
|
||||||
.env.*
|
|
||||||
!.env.example
|
|
||||||
|
|||||||
Reference in New Issue
Block a user