At the repo owner's instruction, to stop the deploy depending on re-entering config in the Dokploy UI - which is how the container ended up exiting at startup on missing AUTH_SECRET_KEY and returning Bad Gateway. The two database secrets are deliberately NOT in the file. settings.py calls load_dotenv() without override=True, so a real environment variable wins over the file; DB_HOST and DB_PASSWORD are set in Dokploy and never enter git. Two fields to fill instead of seven. The auth secrets ARE committed, which is worth being explicit about: AUTH_SECRET_KEY signs every access token, so anyone with read access to this repository can mint a valid admin token, and git history retains it after any rotation. .gitignore records the same warning next to the exception that allows the file. Regenerate with scripts/make_auth_secrets.py and redeploy if that stops being an acceptable trade. The generated sign-in passwords are written to SIGNIN_PASSWORDS.txt, which stays ignored - only the PBKDF2 digests are in .env, and those cannot be reversed. Verified end to end: the app boots on 3000 and 8000 with DB_HOST/DB_PASSWORD supplied as environment variables, and a login with the generated admin password returns a token while a wrong password returns 401. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
33 lines
861 B
Plaintext
33 lines
861 B
Plaintext
# .env is committed deliberately, at the repo owner's instruction, so the
|
|
# deployment does not depend on re-entering config in the Dokploy UI.
|
|
#
|
|
# The two database secrets are NOT in it - they are set as Dokploy environment
|
|
# variables, which override the file (settings.py calls load_dotenv() without
|
|
# override=True, so the process environment wins).
|
|
#
|
|
# The auth secrets ARE in it. AUTH_SECRET_KEY signs every access token, so
|
|
# anyone with read access to this repository can mint an admin token, and git
|
|
# history keeps it after any rotation. Regenerate with
|
|
# `python scripts/make_auth_secrets.py` if that stops being acceptable.
|
|
!.env
|
|
|
|
# Local overrides and the generated sign-in passwords stay out of git.
|
|
.env.local
|
|
SIGNIN_PASSWORDS.txt
|
|
|
|
# Python
|
|
__pycache__/
|
|
*.pyc
|
|
*.pyo
|
|
.venv/
|
|
venv/
|
|
*.egg-info/
|
|
.pytest_cache/
|
|
|
|
# Logs
|
|
*.log
|
|
|
|
# OS
|
|
.DS_Store
|
|
Thumbs.db
|