Files
Crussell/.env.example
T
popertots 91fe5ea399 Fix compose backend env file; document R2 and Square webhook variables
compose.yml backend service now reads the root ./.env (which README instructs users to create) instead of the nonexistent backend/.env. Promote R2_ACCESS_KEY/R2_SECRET_KEY/R2_BUCKET/R2_PUBLIC_URL to active vars (prod S3 reads all four via getEnv) and document the webhook URL/signature-key exact-match requirement with fail-closed (503/403) wording.
2026-08-22 00:34:49 +01:00

89 lines
3.1 KiB
Bash

# Database Credentials for all services
# These are used by the 'postgres' service to initialize the database
# These are used by 'backend' (Go) and 'sabredav' (PHP)
POSTGRES_USER=myuser
POSTGRES_PASSWORD=mypassword
POSTGRES_DB=mydb
# and to connect to the 'postgres' service on the Docker network
POSTGRES_HOST=postgres
POSTGRES_PORT=5432
JWT_SECRET_KEY="a-very-secret-key-that-should-be-in-env"
# S3/R2 Configuration (for image storage)
# Dev: Uses local Rustfs container (see compose.yml)
# Prod: Use Cloudflare R2 credentials
S3_ENDPOINT=http://localhost:9000
S3_PUBLIC_URL=http://192.168.1.135:9000
S3_ACCESS_KEY=rustfsadmin
S3_SECRET_KEY=rustfsadmin
S3_BUCKET=crussell
S3_PROFILE_PICS_BUCKET=crussell-profile-pics
AWS_REGION=eu-west-2
# Set DAV_SKIP_INIT=1 to skip CardDAV server initialization (e.g., in CI/test environments).
DAV_SKIP_INIT=1
# Prod only: Cloudflare R2 (overrides S3_* vars in non-dev builds).
# Local dev uses the S3_* vars above (from .env). Not needed for local builds.
R2_ENDPOINT=
# Required for production object storage — the prod S3 client (backend/internal/s3/s3.go,
# via getEnv) reads all four below; not needed for local dev builds.
R2_ACCESS_KEY=
R2_SECRET_KEY=
R2_BUCKET=crussell
R2_PUBLIC_URL=
# Square Payment Gateway
SQUARE_ACCESS_TOKEN=
SQUARE_LOCATION_ID=
SQUARE_TERMINAL_DEVICE_ID=
SQUARE_ENVIRONMENT=mock
# Webhook config MUST exactly match the Square Dashboard webhook subscription
# (URL + signature key). If SQUARE_WEBHOOK_NOTIFICATION_URL is left unset it
# defaults to http://localhost:8080/webhooks/square, which is fail-closed (503
# without the signing key, 403 on missing/bad signature). Leave both empty if
# you do not use webhooks.
SQUARE_WEBHOOK_SIGNATURE_KEY=
SQUARE_WEBHOOK_NOTIFICATION_URL=
# Frontend (public — safe for the browser). Square Web Payments SDK:
# VITE_SQUARE_APPLICATION_ID — client-side application ID (sandbox IDs start with "sandbox-")
# VITE_SQUARE_LOCATION_ID — Square location ID
# VITE_SQUARE_ENVIRONMENT — 'mock' | 'sandbox' | 'production'. Local dev: 'mock' renders the
# frontend's built-in mock card form (tokens only; pairs with
# SQUARE_ENVIRONMENT=mock above). NEVER set 'mock' in production.
VITE_SQUARE_APPLICATION_ID=
VITE_SQUARE_LOCATION_ID=
VITE_SQUARE_ENVIRONMENT=mock
# Test Database (separate from main DB)
# Used by testutils/testdb for running tests without corrupting dev data
TEST_DB_HOST=localhost
TEST_DB_DSN=
# Dev/CI mode — set to "true" to enable mock services
# Disables zxcvbn password checks, skips artificial Square mock delays,
# skips DAV sync, and relaxes production guardrails
GO_TESTING=
# CardDAV (SabreDAV) — profile photo sync
DAV_BASE_URL=http://localhost:8080
DAV_ADMIN_PASSWORD=admin
# Logging
# Set to "true" to disable ANSI color escape sequences in log output
NO_COLOR=
# Frontend
VITE_BACKEND_URL=http://localhost:8080
# Local S3 (Rustfs) — requires GO_TESTING=1 or dev build tag
# These are dev-only overrides used by the dev S3 implementation
RUSTFS_ENDPOINT=http://rustfs:9000
RUSTFS_ACCESS_KEY=rustfsadmin
RUSTFS_SECRET_KEY=rustfsadmin
RUSTFS_BUCKET=crussell