# Fiesta — PRODUCTION configuration. # # NOT loaded by default, on purpose. `go run .` and `./nearle` with no APP_ENV # read `.env.local`; this file is reached only by asking for it: # # APP_ENV=production ./nearle # # ⚠️ Everything here is live. `db.Connect()` runs schema migrations on boot and # every handler writes for real, so a process started with APP_ENV=production # creates real tenants, real logins and real stock movements. There is no dry # run. If the point is to try a change before it ships, use `.env.local` with a # dump restored into the local Postgres — that is the only version that does. # # On the deployed host these values come from the platform's environment # settings (Dokploy / Kubernetes), never from this file: the image is built # without any `.env.*` (see .dockerignore). Keep the two in step — a variable # added here and not there is a variable that is unset in production, and # startup will refuse to boot on a missing required one. # # This file is currently committed to git, which means every credential in it # has to be treated as public: rotate them, and keep the new values out of # the repository. # ── Where it listens ──────────────────────────────────────────────────────── APP_PORT=1009 ENV=production # ── The main database (nearledb) ──────────────────────────────────────────── DB_HOST=66.116.207.225 DB_PORT=5433 DB_NAME=nearledb DB_USER=admin DB_PASSWORD="Package@123#" # ── The catalogue database (pgvector) ─────────────────────────────────────── # # Read-only integration, on its own connection so catalogue work never touches # nearledb. Note the database is named `pgvector`, not `cataloguedb` as it is # locally — `CATALOGUE_DB_NAME` is what reconciles the two. CATALOGUE_DB_HOST=31.97.228.132 CATALOGUE_DB_PORT=6054 CATALOGUE_DB_NAME=pgvector CATALOGUE_DB_USER=admin CATALOGUE_DB_PASSWORD="'Package@321#'" # ^ the single quotes are PART OF THE PASSWORD, not quoting. Verified against # the live host: stripping them gives "password authentication failed". # ── DigitalOcean Spaces (S3-compatible) — catalogue product images ────────── USE_S3=true S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com S3_BUCKET=nearle S3_REGION=sgp1 # ── POS terminals — the MQTT broker the in-store tills publish to ─────────── # # A BLANK MQTT_URL MEANS THE INGEST DOES NOT START. The service comes up # looking healthy and every till queues its bills silently. On startup you # should see three lines reading "pos: subscribed to nearle/pos/+/+/...". MQTT_URL=tcp://66.116.225.226:1883 MQTT_USER=pos_ingest MQTT_PASSWORD=AXbEPrNDWnMLdp7T1tFETwyU # Unique per replica: a second connection with the same id evicts the first. MQTT_CLIENT_ID=nearle-pos-ingest # ── POS presence — terminal heartbeats under a 90-second TTL ──────────────── # # Shared with the express backend; POS keys are namespaced pos:* so they cannot # collide with delivery:*, city:* or rider_*. Optional: without it the health # board goes dark, but bills still arrive and commit. Losing presence is an # inconvenience; losing a sale is not. REDIS_HOST=66.116.226.255 REDIS_PORT=6379 REDIS_USER=default REDIS_PASSWORD=Package@324969# REDIS_DB=0 # ── Auth ──────────────────────────────────────────────────────────────────── POS_TOKEN_SECRET=XCYrH7J6pi0wGzufaYfIXialqRVzlLRslaTlDbhfqQQl # ── Nearle Buddy ──────────────────────────────────────────────────────────── # One variable. Provider, endpoint and model are constants in config.go. ASSISTANT_API_KEY=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