Commit .env so the deployment carries its own configuration

At the repo owner's instruction, to stop the deploy depending on re-entering
config in the Dokploy UI - which is how the container ended up exiting at
startup on missing AUTH_SECRET_KEY and returning Bad Gateway.

The two database secrets are deliberately NOT in the file. settings.py calls
load_dotenv() without override=True, so a real environment variable wins over
the file; DB_HOST and DB_PASSWORD are set in Dokploy and never enter git. Two
fields to fill instead of seven.

The auth secrets ARE committed, which is worth being explicit about:
AUTH_SECRET_KEY signs every access token, so anyone with read access to this
repository can mint a valid admin token, and git history retains it after any
rotation. .gitignore records the same warning next to the exception that allows
the file. Regenerate with scripts/make_auth_secrets.py and redeploy if that
stops being an acceptable trade.

The generated sign-in passwords are written to SIGNIN_PASSWORDS.txt, which
stays ignored - only the PBKDF2 digests are in .env, and those cannot be
reversed.

Verified end to end: the app boots on 3000 and 8000 with DB_HOST/DB_PASSWORD
supplied as environment variables, and a login with the generated admin
password returns a token while a wrong password returns 401.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Suriyakumarvijayanayagam
2026-08-13 13:39:20 +05:30
parent 00216ae834
commit 56fdb82d0a
2 changed files with 103 additions and 2 deletions

87
.env Normal file
View File

@@ -0,0 +1,87 @@
# Deployment configuration for mcp.nearle.ai.in.
#
# ---------------------------------------------------------------------------
# SET THESE TWO IN DOKPLOY - they are NOT in this file:
#
# DB_HOST your Postgres host (the service name, if it is a Dokploy
# service - inside a container "localhost" is the container)
# DB_PASSWORD your Postgres password
#
# A real environment variable overrides anything set here: settings.py calls
# load_dotenv() without override=True, so the process environment wins. That is
# why the two database secrets are left as FILL-ME below - Dokploy supplies
# them, and they never enter git.
# ---------------------------------------------------------------------------
#
# Everything else is committed, including the auth secrets, at the repo owner's
# explicit instruction. Be aware of what that means: AUTH_SECRET_KEY signs every
# access token, so anyone who can read this repository can mint a valid admin
# token for the API. Rotating it later does not remove it from git history.
# Rotate with `python scripts/make_auth_secrets.py` and redeploy if that
# assumption ever stops holding.
# --- Ports -----------------------------------------------------------------
# Dokploy routes the domain to 3000; 8000 is kept for the vite dev proxy and
# docker-compose. serve.py binds both.
PORTS=3000,8000
# --- CORS ------------------------------------------------------------------
# The FRONTEND's origin, not this API's. If this is wrong the browser blocks
# every response while the server logs healthy 200s.
API_CORS_ORIGINS=https://catalogue.nearle.ai.in
# --- Authentication --------------------------------------------------------
AUTH_ENABLED=true
AUTH_SECRET_KEY=4Kmyr4Cjf_kdUIq_4EGxo5vFHfCT5_uKVR3eouszB8Le6F0n45m7eDY94_KJoqSz
AUTH_ADMIN_USERNAME=admin
AUTH_ADMIN_PASSWORD_HASH=pbkdf2_sha256$600000$Xa07unPO4LeTU4bz04eh7Q==$KmZ2ZBrclJ0z0sDiCoKOrfTO2UK8e7hjsZZ6HB2PY9o=
AUTH_USER_USERNAME=user
AUTH_USER_PASSWORD_HASH=pbkdf2_sha256$600000$65VMpqwUSyFzCqnhlwBqgQ==$sMVnar+Hnp5ZmXcObFNI3jJMxqnVrW8naLZNFFh0KCw=
AUTH_TOKEN_TTL_MINUTES=720
AUTH_MAX_LOGIN_ATTEMPTS=10
AUTH_LOCKOUT_SECONDS=300
AUTH_ALLOW_ANY_LOGIN=false
# Machine consumers. Empty: MCP clients authenticate with a login token instead.
API_KEYS=
# --- Postgres / pgvector ---------------------------------------------------
# Inside a container `localhost` is the container itself. If Postgres runs as
# another Dokploy service, DB_HOST is that service's name, not localhost.
USE_PGVECTOR=true
DB_HOST=FILL-ME-postgres-host
DB_PORT=5432
DB_NAME=pgvector
DB_USER=postgres
DB_PASSWORD=FILL-ME-postgres-password
# --- Embeddings ------------------------------------------------------------
USE_EMBEDDINGS=true
EMBEDDINGS_MODEL=sentence-transformers/all-MiniLM-L6-v2
EMBEDDINGS_DIM=384
# --- Ollama ----------------------------------------------------------------
# Off unless an Ollama host is reachable from the container. Leaving it on with
# nothing listening makes /api/chat fail and adds ~3s to every healthcheck,
# because the health handler probes it with a 3s timeout.
USE_OLLAMA=false
OLLAMA_BASE_URL=http://host.docker.internal:11434
OLLAMA_MODEL_NAME=qwen2.5:1.5b
OLLAMA_TIMEOUT_SECONDS=120
# --- Optional integrations -------------------------------------------------
USE_S3=false
USE_GOOGLE_CSE=false
# Image sources used during catalog ingestion.
USE_DDG_IMAGES=true
USE_OPEN_FACTS=true
USE_WIKIMEDIA=true
# Playwright's browser binary is not installed in the image, so this tier is
# skipped at runtime regardless; false keeps it from being attempted.
USE_PLAYWRIGHT_FALLBACK=false
# --- RAG -------------------------------------------------------------------
RAG_DEFAULT_TOP_K=5
RAG_MAX_TOP_K=15
RAG_MAX_CONTEXT_CHARS=4000

18
.gitignore vendored
View File

@@ -1,5 +1,19 @@
# Secrets - never commit
.env
# .env is committed deliberately, at the repo owner's instruction, so the
# deployment does not depend on re-entering config in the Dokploy UI.
#
# The two database secrets are NOT in it - they are set as Dokploy environment
# variables, which override the file (settings.py calls load_dotenv() without
# override=True, so the process environment wins).
#
# The auth secrets ARE in it. AUTH_SECRET_KEY signs every access token, so
# anyone with read access to this repository can mint an admin token, and git
# history keeps it after any rotation. Regenerate with
# `python scripts/make_auth_secrets.py` if that stops being acceptable.
!.env
# Local overrides and the generated sign-in passwords stay out of git.
.env.local
SIGNIN_PASSWORDS.txt
# Python
__pycache__/