Files
backend_fiesta/.env.local
Suriyakumarvijayanayagam 4474479735 Load .env.<APP_ENV>, validate config at boot, keep secrets out of the image
`main.go` only ever loaded `.env`; the `APP_ENV` switch described in
`.env.local` / `.env.production` did not exist, and a missing variable
surfaced one restart at a time as a log.Fatalf inside db.Connect.

config.Load now picks `.env.<APP_ENV>` (default local) then `.env`, with
real environment winning, reads every setting into one typed Config and
reports everything missing in one message. Production insists on a POS
signing secret; local warns when DB_HOST is not a local address. db,
redis and the image store take the Config instead of reading env
themselves.

Also:
- livehub read MQTT_USERNAME while everything else uses MQTT_USER, so the
  console stream connected to the broker unauthenticated. Both accepted.
- .dockerignore: `COPY . .` was baking .env.production into the image.
  Dockerfile sets APP_ENV=production.
- Drop utils/config.go (dead viper loader) and create_table.go (unused,
  hardcoded production DSN); go mod tidy removes viper.
- .env.example lists every variable the code reads; docs/ENVIRONMENT.md.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-15 17:04:33 +05:30

69 lines
3.4 KiB
Plaintext

# Fiesta — LOCAL configuration (docker-compose.local.yml).
#
# This is the file you get by default: APP_ENV unset means `.env.local`.
# Production values live in `.env.production` and are only loaded by asking:
# APP_ENV=production ./nearle
#
# Keep every host here pointing at localhost. The whole point of the split is
# that running the server locally cannot reach live data by accident.
#
# `config.Load()` reads `.env.$APP_ENV` and then `.env` from the working
# directory, so `go run .` from this folder picks this file up with no flags.
# A real environment variable always wins over either file. The full list of
# settings is in `.env.example`.
# ── Where it listens ────────────────────────────────────────────────────────
# Production serves on 1009 (see .env.production). Change this locally to run
# beside something else; the console then points at the same number.
APP_PORT=1122
ENV=development
# ── The main database (nearledb) ────────────────────────────────────────────
#
# ⚠️ POINTING THIS AT PRODUCTION MAKES LOCAL TESTING WRITE TO PRODUCTION.
#
# There is no "local mode" that protects you: `go run .` against the live host
# creates real tenants, real logins and real stock movements, and main.go runs
# schema migrations on boot. If the point of running locally is to try a change
# before it is deployed, a local Postgres with a dump restored into it is the
# only version that actually does that.
# These match docker-compose.local.yml, so `docker compose -f
# docker-compose.local.yml up -d` and `go run .` work together with no edits.
DB_HOST=localhost
DB_PORT=5433
DB_NAME=nearledb
DB_USER=nearle
DB_PASSWORD=localdev
# ── The catalogue database (pgvector) ───────────────────────────────────────
#
# A separate connection on purpose, so catalogue work never touches nearledb.
# Leave blank to start without it: catalogue endpoints then fail at query time
# rather than at boot, which is fine for testing anything else.
# 5434, not 5432: a developer machine usually has something on 5432 already,
# and a silent connection to the wrong database is worse than a refused one.
CATALOGUE_DB_HOST=localhost
CATALOGUE_DB_PORT=5434
CATALOGUE_DB_NAME=cataloguedb
CATALOGUE_DB_USER=nearle
CATALOGUE_DB_PASSWORD=localdev
# ── Redis — POS terminal presence, under a TTL ──────────────────────────────
#
# Optional. Losing the health board is an inconvenience; losing a sale is not,
# so the API runs without it.
# Set to enable POS terminal presence. The local compose publishes redis on
# 6379, so localhost is all it needs; leave blank to run without it.
REDIS_HOST=localhost
REDIS_PORT=6379
REDIS_USER=
REDIS_DB=0
# ── Auth ────────────────────────────────────────────────────────────────────
# Signs POS terminal sessions (16+ characters). A throwaway value so a till can
# sign in against the local stack; production sets its own in the platform.
POS_TOKEN_SECRET=local-dev-signing-secret-not-real
JWT_SECRET_KEY=
USER_CONTEXT_KEY=