This commit is contained in:
2026-09-15 12:49:34 +05:30
parent 1b2cc77063
commit be47435547
4 changed files with 210 additions and 3 deletions

63
.env Normal file
View File

@@ -0,0 +1,63 @@
# Fiesta configuration.
#
# Copy to `.env` and fill in. `.env` and `.env.*` are gitignored (the one
# exception is this file) — and they are gitignored for a reason: this
# repository's history already contains a committed `.env` from before
# 2026-08-03, so those database credentials are in the history and should be
# rotated. Do not add another.
#
# `godotenv.Load()` in main.go reads `.env` from the working directory, so
# `go run .` from this folder picks it up with no flags.
# ── Where it listens ────────────────────────────────────────────────────────
# 1122 is what production serves on. Change it locally to run a second copy
# beside something else; the console then points at the same number.
APP_PORT=1122
ENV=development
# ── The main database (nearledb) ────────────────────────────────────────────
#
# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION.
#
# There is no "local mode" that protects you: `go run .` against the live host
# creates real tenants, real logins and real stock movements, and main.go runs
# schema migrations on boot. If the point of running locally is to try a change
# before it is deployed, a local Postgres with a dump restored into it is the
# only version that actually does that.
# These match docker-compose.local.yml, so `docker compose -f
# docker-compose.local.yml up -d` and `go run .` work together with no edits.
DB_HOST=localhost
DB_PORT=5433
DB_NAME=nearledb
DB_USER=nearle
DB_PASSWORD=localdev
# ── The catalogue database (pgvector) ───────────────────────────────────────
#
# A separate connection on purpose, so catalogue work never touches nearledb.
# Leave blank to start without it: catalogue endpoints then fail at query time
# rather than at boot, which is fine for testing anything else.
# 5434, not 5432: a developer machine usually has something on 5432 already,
# and a silent connection to the wrong database is worse than a refused one.
CATALOGUE_DB_HOST=localhost
CATALOGUE_DB_PORT=5434
CATALOGUE_DB_NAME=cataloguedb
CATALOGUE_DB_USER=nearle
CATALOGUE_DB_PASSWORD=localdev
# ── Redis — POS terminal presence, under a TTL ──────────────────────────────
#
# Optional. Losing the health board is an inconvenience; losing a sale is not,
# so the API runs without it.
# Set to enable POS terminal presence. The local compose publishes redis on
# 6379, so localhost is all it needs; leave blank to run without it.
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_USER=
REDIS_DB=0
# ── Auth ────────────────────────────────────────────────────────────────────
JWT_SECRET_KEY=
USER_CONTEXT_KEY=

68
.env.local Normal file
View File

@@ -0,0 +1,68 @@
# Fiesta — LOCAL configuration (docker-compose.local.yml).
#
# This is the file you get by default: APP_ENV unset means `.env.local`.
# Production values live in `.env.production` and are only loaded by asking:
# APP_ENV=production ./nearle
#
# Keep every host here pointing at localhost. The whole point of the split is
# that running the server locally cannot reach live data by accident.
#
# `.env`, `.env.local` and `.env.production` are all gitignored (`.env.example`
# is the one exception) — and for a reason: this repository's history already
# contains a committed `.env` from before 2026-08-03, so those credentials are
# in the history and should be rotated. Do not add another.
#
# `loadEnv()` in main.go reads `.env.$APP_ENV` from the working directory, so
# `go run .` from this folder picks this file up with no flags.
# ── Where it listens ────────────────────────────────────────────────────────
# Production serves on 1009 (see .env.production). Change this locally to run
# beside something else; the console then points at the same number.
APP_PORT=1122
ENV=development
# ── The main database (nearledb) ────────────────────────────────────────────
#
# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION.
#
# There is no "local mode" that protects you: `go run .` against the live host
# creates real tenants, real logins and real stock movements, and main.go runs
# schema migrations on boot. If the point of running locally is to try a change
# before it is deployed, a local Postgres with a dump restored into it is the
# only version that actually does that.
# These match docker-compose.local.yml, so `docker compose -f
# docker-compose.local.yml up -d` and `go run .` work together with no edits.
DB_HOST=localhost
DB_PORT=5433
DB_NAME=nearledb
DB_USER=nearle
DB_PASSWORD=localdev
# ── The catalogue database (pgvector) ───────────────────────────────────────
#
# A separate connection on purpose, so catalogue work never touches nearledb.
# Leave blank to start without it: catalogue endpoints then fail at query time
# rather than at boot, which is fine for testing anything else.
# 5434, not 5432: a developer machine usually has something on 5432 already,
# and a silent connection to the wrong database is worse than a refused one.
CATALOGUE_DB_HOST=localhost
CATALOGUE_DB_PORT=5434
CATALOGUE_DB_NAME=cataloguedb
CATALOGUE_DB_USER=nearle
CATALOGUE_DB_PASSWORD=localdev
# ── Redis — POS terminal presence, under a TTL ──────────────────────────────
#
# Optional. Losing the health board is an inconvenience; losing a sale is not,
# so the API runs without it.
# Set to enable POS terminal presence. The local compose publishes redis on
# 6379, so localhost is all it needs; leave blank to run without it.
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_USER=
REDIS_DB=0
# ── Auth ────────────────────────────────────────────────────────────────────
JWT_SECRET_KEY=
USER_CONTEXT_KEY=

78
.env.production Normal file
View File

@@ -0,0 +1,78 @@
# Fiesta — PRODUCTION configuration.
#
# NOT loaded by default, on purpose. `go run .` and `./nearle` with no APP_ENV
# read `.env.local`; this file is reached only by asking for it:
#
# APP_ENV=production ./nearle
#
# ⚠️ Everything here is live. `db.Connect()` runs schema migrations on boot and
# every handler writes for real, so a process started with APP_ENV=production
# creates real tenants, real logins and real stock movements. There is no dry
# run. If the point is to try a change before it ships, use `.env.local` with a
# dump restored into the local Postgres — that is the only version that does.
#
# Gitignored by `.env.*`. Never commit it, and never paste it into a chat, an
# issue or a PR description: the credentials below have to be rotated if it
# leaves this machine.
#
# On the deployed host these values come from Dokploy's environment settings
# rather than from this file. Keep the two in step — a variable added here and
# not there is a variable that is unset in production.
# ── Where it listens ────────────────────────────────────────────────────────
APP_PORT=1009
ENV=production
# ── The main database (nearledb) ────────────────────────────────────────────
DB_HOST=66.116.207.225
DB_PORT=5433
DB_NAME=nearledb
DB_USER=admin
DB_PASSWORD="Package@123#"
# ── The catalogue database (pgvector) ───────────────────────────────────────
#
# Read-only integration, on its own connection so catalogue work never touches
# nearledb. Note the database is named `pgvector`, not `cataloguedb` as it is
# locally — `CATALOGUE_DB_NAME` is what reconciles the two.
CATALOGUE_DB_HOST=31.97.228.132
CATALOGUE_DB_PORT=6054
CATALOGUE_DB_NAME=pgvector
CATALOGUE_DB_USER=admin
CATALOGUE_DB_PASSWORD="'Package@321#'"
# ^ the single quotes are PART OF THE PASSWORD, not quoting. Verified against
# the live host: stripping them gives "password authentication failed".
# ── DigitalOcean Spaces (S3-compatible) — catalogue product images ──────────
USE_S3=true
S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ
S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug
S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com
S3_BUCKET=nearle
S3_REGION=sgp1
# ── POS terminals — the MQTT broker the in-store tills publish to ───────────
#
# A BLANK MQTT_URL MEANS THE INGEST DOES NOT START. The service comes up
# looking healthy and every till queues its bills silently. On startup you
# should see three lines reading "pos: subscribed to nearle/pos/+/+/...".
MQTT_URL=tcp://66.116.225.226:1883
MQTT_USER=pos_ingest
MQTT_PASSWORD=AXbEPrNDWnMLdp7T1tFETwyU
# Unique per replica: a second connection with the same id evicts the first.
MQTT_CLIENT_ID=nearle-pos-ingest
# ── POS presence — terminal heartbeats under a 90-second TTL ────────────────
#
# Shared with the express backend; POS keys are namespaced pos:* so they cannot
# collide with delivery:*, city:* or rider_*. Optional: without it the health
# board goes dark, but bills still arrive and commit. Losing presence is an
# inconvenience; losing a sale is not.
REDIS_HOST=66.116.226.255
REDIS_PORT=6379
REDIS_USER=default
REDIS_PASSWORD=Package@324969#
REDIS_DB=0
# ── Auth ────────────────────────────────────────────────────────────────────
POS_TOKEN_SECRET=XCYrH7J6pi0wGzufaYfIXialqRVzlLRslaTlDbhfqQQl

4
.gitignore vendored
View File

@@ -53,6 +53,4 @@ Thumbs.db
# credentials in this repository's history — removing it from the index stops
# that getting worse, but the existing history still has them and the password
# should be rotated.
.env
.env.*
!.env.example