Adds the live database, DigitalOcean Spaces and Google CSE settings supplied by the repo owner, so the container needs nothing set in the Dokploy UI. Three deliberate departures from the development .env this came from: AUTH_ALLOW_ANY_LOGIN is false, not true. In development it is a convenience - the password field is not checked, so any username signs in and `admin` reaches the admin pages. On a host published to the internet it means anyone who finds mcp.nearle.ai.in becomes admin by typing anything at all. The development file's own comment says to turn it off before the backend leaves the laptop. The auth secrets are the freshly generated ones, not the development values. Those hashes are for the passwords DevAdmin!2026 and DevUser!2026, which sit in plaintext in test_login_fix.py in this same repository - committing them would have published working admin credentials alongside the hash that accepts them. Verified: DevAdmin!2026 is now rejected with a 401. USE_OLLAMA is false. The development value http://localhost:11434 cannot work from inside a container, where localhost is the container rather than the VPS host. Left on with nothing listening, /api/chat fails and every healthcheck takes ~3s longer, because the health handler probes Ollama with a 3s timeout. Enable it by pointing OLLAMA_BASE_URL at something the container can reach. DB_NAME is stated explicitly rather than relying on settings.py's default, which is what the development file was leaning on. Verified booting from this file alone, with no environment variables: binds 3000 and 8000, mounts MCP, correct password returns a token, and both the any-password bypass and the old development password return 401. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
114 lines
4.8 KiB
Bash
114 lines
4.8 KiB
Bash
# Deployment configuration for mcp.nearle.ai.in.
|
|
#
|
|
# Committed at the repo owner's instruction so the deploy does not depend on
|
|
# re-entering config in the Dokploy UI. Everything needed to boot is here; no
|
|
# environment variables are required in Dokploy any more.
|
|
#
|
|
# A real environment variable still overrides anything set here - settings.py
|
|
# calls load_dotenv() without override=True, so the process environment wins.
|
|
# That is the escape hatch for changing a value without a commit.
|
|
#
|
|
# WHAT IS IN THIS FILE: live database, S3 and Google credentials, and the key
|
|
# that signs every access token. Anyone with read access to this repository has
|
|
# all of it, and git history keeps it after any rotation.
|
|
|
|
# --- Ports -----------------------------------------------------------------
|
|
# Dokploy routes the domain to 3000; 8000 is kept for the vite dev proxy and
|
|
# docker-compose. serve.py binds both.
|
|
PORTS=3000,8000
|
|
|
|
# --- CORS ------------------------------------------------------------------
|
|
# The FRONTEND's origin, not this API's. Wrong value = the browser blocks every
|
|
# response while the server logs healthy 200s.
|
|
API_CORS_ORIGINS=https://catalogue.nearle.ai.in
|
|
|
|
# --- Authentication --------------------------------------------------------
|
|
AUTH_ENABLED=true
|
|
|
|
# Freshly generated for this deployment - deliberately NOT the values from the
|
|
# development .env. Those hashes are for the passwords DevAdmin!2026 and
|
|
# DevUser!2026, which are sitting in plaintext in test_login_fix.py in this very
|
|
# repository: shipping them would publish working admin credentials.
|
|
# Sign-in passwords for the hashes below are in SIGNIN_PASSWORDS.txt (ignored).
|
|
AUTH_SECRET_KEY=4Kmyr4Cjf_kdUIq_4EGxo5vFHfCT5_uKVR3eouszB8Le6F0n45m7eDY94_KJoqSz
|
|
AUTH_ADMIN_USERNAME=admin
|
|
AUTH_ADMIN_PASSWORD_HASH=pbkdf2_sha256$600000$Xa07unPO4LeTU4bz04eh7Q==$KmZ2ZBrclJ0z0sDiCoKOrfTO2UK8e7hjsZZ6HB2PY9o=
|
|
AUTH_USER_USERNAME=user
|
|
AUTH_USER_PASSWORD_HASH=pbkdf2_sha256$600000$65VMpqwUSyFzCqnhlwBqgQ==$sMVnar+Hnp5ZmXcObFNI3jJMxqnVrW8naLZNFFh0KCw=
|
|
|
|
AUTH_TOKEN_TTL_MINUTES=720
|
|
AUTH_MAX_LOGIN_ATTEMPTS=10
|
|
AUTH_LOCKOUT_SECONDS=300
|
|
|
|
# MUST stay false here. The development .env has this true, where it is a
|
|
# convenience: it skips the password check entirely, so any username signs in
|
|
# and `admin` gets the admin pages. On a host published to the internet it means
|
|
# anyone who finds mcp.nearle.ai.in signs in as admin by typing anything at all.
|
|
AUTH_ALLOW_ANY_LOGIN=false
|
|
|
|
# Machine consumers. Empty: MCP clients authenticate with a login token instead.
|
|
API_KEYS=
|
|
|
|
# --- Postgres / pgvector ---------------------------------------------------
|
|
# DB_NAME is not set in the development .env, so it falls back to settings.py's
|
|
# default. Stated explicitly here so the deployment does not depend on that
|
|
# default staying the same.
|
|
USE_PGVECTOR=true
|
|
DB_HOST=31.97.228.132
|
|
DB_PORT=6054
|
|
DB_NAME=pgvector
|
|
DB_USER=admin
|
|
DB_PASSWORD=Package@321#
|
|
|
|
# --- Embeddings ------------------------------------------------------------
|
|
USE_EMBEDDINGS=true
|
|
EMBEDDINGS_MODEL=sentence-transformers/all-MiniLM-L6-v2
|
|
EMBEDDINGS_DIM=384
|
|
|
|
# --- Ollama (local LLM, powers /api/chat) ----------------------------------
|
|
# Off, because the development value (http://localhost:11434) cannot work from
|
|
# inside a container: there, localhost is the container itself, not the VPS
|
|
# host. Left on with nothing listening, /api/chat fails AND every healthcheck
|
|
# takes ~3s longer, because the health handler probes Ollama with a 3s timeout.
|
|
#
|
|
# To enable: set USE_OLLAMA=true and point OLLAMA_BASE_URL at something the
|
|
# container can actually reach - http://host.docker.internal:11434 with a
|
|
# host-gateway mapping, the VPS's LAN IP, or an ollama service name.
|
|
USE_OLLAMA=false
|
|
OLLAMA_BASE_URL=http://host.docker.internal:11434
|
|
OLLAMA_MODEL_NAME=qwen2.5:1.5b
|
|
OLLAMA_TIMEOUT_SECONDS=120
|
|
|
|
# --- DigitalOcean Spaces (product image storage) ---------------------------
|
|
USE_S3=true
|
|
S3_ACCESS_KEY=DO801G8Q8JAZKF49U3WJ
|
|
S3_SECRET_KEY=lBQExYfkVqH+ybmGVmQH5MkThBbrIohA/VQLgcPUvug
|
|
S3_ENDPOINT=https://nearle.sgp1.digitaloceanspaces.com
|
|
S3_BUCKET=nearle
|
|
S3_REGION=sgp1
|
|
|
|
# --- Google Custom Search (optional image source) --------------------------
|
|
USE_GOOGLE_CSE=true
|
|
GOOGLE_API_KEY=AIzaSyBY4pIO_Fp5FCMqeVxDNcfalzdWNHJWVn0
|
|
GOOGLE_CSE_ID=9745cbd96dd164562
|
|
|
|
# --- Open-source image sources (no key needed) -----------------------------
|
|
USE_DDG_IMAGES=true
|
|
USE_OPEN_FACTS=true
|
|
USE_WIKIMEDIA=true
|
|
# The Playwright browser binary is NOT installed in the image (see Dockerfile),
|
|
# so this tier is skipped at runtime regardless. false stops it being attempted.
|
|
USE_PLAYWRIGHT_FALLBACK=false
|
|
|
|
MIN_IMAGE_BYTES=3000
|
|
|
|
# --- Product validation ----------------------------------------------------
|
|
ENABLE_PRODUCT_VALIDATION=true
|
|
VALIDATION_REJECT_THRESHOLD=0.35
|
|
VALIDATION_REVIEW_THRESHOLD=0.70
|
|
|
|
# --- RAG -------------------------------------------------------------------
|
|
RAG_DEFAULT_TOP_K=5
|
|
RAG_MAX_TOP_K=15
|
|
RAG_MAX_CONTEXT_CHARS=4000
|