-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
32 lines (27 loc) · 1.51 KB
/
Copy path.env.example
File metadata and controls
32 lines (27 loc) · 1.51 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
# Copy this file to .env and fill in real values.
# Never commit .env to version control.
# JWT signing key — REQUIRED. App fails to start if unset, empty, or
# shorter than 32 characters. The placeholder below is deliberately
# under the minimum length so the app refuses to boot until you
# replace it with a real high-entropy secret.
# Generate with: python -c "import secrets; print(secrets.token_urlsafe(48))"
JWT_SECRET_KEY=REPLACE_ME
# Fernet encryption key for credential storage at rest. REQUIRED. App
# fails to start if the value isn't a valid urlsafe-base64-encoded
# 32-byte Fernet key.
# Generate with: python -c "from cryptography.fernet import Fernet; print(Fernet.generate_key().decode())"
ENCRYPTION_KEY=
# Seeded admin account — REQUIRED. The app supports a single admin
# whose username and bcrypt password hash are supplied via env. There
# is no users table; rotating the credential means redeploying with a
# new ADMIN_PASSWORD_HASH.
# Generate the hash from backend/ with its environment activated. The prompt
# keeps the real password out of this file and your shell history:
# python -c "from getpass import getpass; from app.auth.hashing import hash_password; print(hash_password(getpass('Admin password: ')))"
ADMIN_USERNAME=
ADMIN_PASSWORD_HASH=
# Oracle thick mode is optional. This path enables the Linux x86-64 Instant
# Client bundled in the backend image; replace it with a blank value for thin.
ORACLE_CLIENT_LIB_DIR=/opt/oracle/instantclient_19_32
# Oracle XE (optional profile)
# ORACLE_PASSWORD=oracle