# Database Credentials for all services # These are used by the 'postgres' service to initialize the database # These are used by 'backend' (Go) and 'sabredav' (PHP) POSTGRES_USER=myuser POSTGRES_PASSWORD=mypassword POSTGRES_DB=mydb # and to connect to the 'postgres' service on the Docker network POSTGRES_HOST=postgres POSTGRES_PORT=5432 JWT_SECRET_KEY="a-very-secret-key-that-should-be-in-env" # S3/R2 Configuration (for image storage) # Dev: Uses local Rustfs container (see compose.yml) # Prod: Use Cloudflare R2 credentials S3_ENDPOINT=http://localhost:9000 S3_PUBLIC_URL=http://192.168.1.135:9000 S3_ACCESS_KEY=rustfsadmin S3_SECRET_KEY=rustfsadmin S3_BUCKET=crussell S3_PROFILE_PICS_BUCKET=crussell-profile-pics AWS_REGION=eu-west-2 # Set DAV_SKIP_INIT=1 to skip CardDAV server initialization (e.g., in CI/test environments). DAV_SKIP_INIT=1 # Prod only: Cloudflare R2 (overrides S3_* vars in non-dev builds). # Local dev uses the S3_* vars above (from .env). Not needed for local builds. R2_ENDPOINT= # Required for production object storage — the prod S3 client (backend/internal/s3/s3.go, # via getEnv) reads all four below; not needed for local dev builds. R2_ACCESS_KEY= R2_SECRET_KEY= R2_BUCKET=crussell R2_PUBLIC_URL= # Square Payment Gateway SQUARE_ACCESS_TOKEN= SQUARE_LOCATION_ID= SQUARE_TERMINAL_DEVICE_ID= SQUARE_ENVIRONMENT=mock # Webhook config MUST exactly match the Square Dashboard webhook subscription # (URL + signature key). If SQUARE_WEBHOOK_NOTIFICATION_URL is left unset it # defaults to http://localhost:8080/webhooks/square, which is fail-closed (503 # without the signing key, 403 on missing/bad signature). Leave both empty if # you do not use webhooks. SQUARE_WEBHOOK_SIGNATURE_KEY= SQUARE_WEBHOOK_NOTIFICATION_URL= # Frontend (public — safe for the browser). Square Web Payments SDK: # VITE_SQUARE_APPLICATION_ID — client-side application ID (sandbox IDs start with "sandbox-") # VITE_SQUARE_LOCATION_ID — Square location ID # VITE_SQUARE_ENVIRONMENT — 'mock' | 'sandbox' | 'production'. Local dev: 'mock' renders the # frontend's built-in mock card form (tokens only; pairs with # SQUARE_ENVIRONMENT=mock above). NEVER set 'mock' in production. VITE_SQUARE_APPLICATION_ID= VITE_SQUARE_LOCATION_ID= VITE_SQUARE_ENVIRONMENT=mock # Test Database (separate from main DB) # Used by testutils/testdb for running tests without corrupting dev data TEST_DB_HOST=localhost TEST_DB_DSN= # Dev/CI mode — set to "true" to enable mock services # Disables zxcvbn password checks, skips artificial Square mock delays, # skips DAV sync, and relaxes production guardrails GO_TESTING= # CardDAV (SabreDAV) — profile photo sync DAV_BASE_URL=http://localhost:8080 DAV_ADMIN_PASSWORD=admin # Logging # Set to "true" to disable ANSI color escape sequences in log output NO_COLOR= # Frontend VITE_BACKEND_URL=http://localhost:8080 # Local S3 (Rustfs) — requires GO_TESTING=1 or dev build tag # These are dev-only overrides used by the dev S3 implementation RUSTFS_ENDPOINT=http://rustfs:9000 RUSTFS_ACCESS_KEY=rustfsadmin RUSTFS_SECRET_KEY=rustfsadmin RUSTFS_BUCKET=crussell