Files
buzz-sheet/.env.example
T
gunshiz 1339dd43e6
CI / Verify (push) Successful in 1m36s
CI / Build immutable images and deploy (push) Successful in 1m45s
fix(auth) : pause Sudloh sign-in for local login
2026-10-06 18:19:44 +07:00

87 lines
3.5 KiB
Bash

# Public site origin used for SEO metadata, sitemap, and robots.txt.
BASE_URL=https://guide.sudloh.com
# Public AdSense publisher client ID. Leave unset to disable ads locally.
NEXT_PUBLIC_GOOGLE_ADSENSE_CLIENT_ID=ca-pub-9687404323559597
# PostgreSQL
DATABASE_URL=postgresql://buzz_sheet:[email protected]:5432/buzz_sheet?sslmode=require
DATABASE_POOL_SIZE=10
# Better Auth email/password administrator and customer login
BETTER_AUTH_URL=http://localhost:3000
BETTER_AUTH_SECRET=replace-with-at-least-32-random-bytes
# Separate trusted browser origins with commas for local development or proxies.
BETTER_AUTH_TRUSTED_ORIGINS=http://localhost:3000
# Optional Sudloh Account sign-in. A verified Sudloh administrator registers the
# exact HTTPS callback at https://account.sudloh.com/account → OIDC clients.
SUDLOH_OIDC_ISSUER=https://account.sudloh.com/api/auth
SUDLOH_OIDC_CLIENT_ID=
SUDLOH_OIDC_CLIENT_SECRET=
SUDLOH_OIDC_REDIRECT_URI=
# Set after linking existing Guide accounts to require Sudloh sign-in.
SUDLOH_OIDC_ONLY=false
SUDLOH_OIDC_PAUSED=false
# Resend sending key; verify sudloh.com before sending from [email protected].
RESEND_API_KEY=replace-with-resend-sending-key
# Cloudflare Turnstile login and public registration protection
TURNSTILE_SITE_KEY=replace-with-turnstile-site-key
TURNSTILE_SECRET_KEY=replace-with-turnstile-secret-key
# Redis remote cache, event transport, and outbox worker
REDIS_URL=rediss://default:[email protected]:6379
REDIS_CACHE_PREFIX=buzz:next-cache
REDIS_EVENT_PREFIX=buzz:events
REDIS_PRESENCE_PREFIX=buzz:presence
REDIS_SECURITY_PREFIX=buzz:security
REDIS_CACHE_MAX_ENTRY_BYTES=5242880
OUTBOX_BATCH_SIZE=20
OUTBOX_POLL_MS=1000
OUTBOX_LEASE_MS=30000
CATALOG_SYNC_CONCURRENCY=12
# Discord-triggered Lunaris catalog sync
DISCORD_BOT_TOKEN=replace-with-discord-bot-token
DISCORD_CHANNEL_ID=replace-with-private-channel-id
DISCORD_LOG_CHANNEL_ID=1547193755772125184
COMMISSION_DISCORD_WEBHOOK_URL=replace-with-commission-discord-webhook-url
# Generate a stable pair with: bunx web-push generate-vapid-keys --json
WEB_PUSH_PUBLIC_KEY=replace-with-vapid-public-key
WEB_PUSH_PRIVATE_KEY=replace-with-vapid-private-key
WEB_PUSH_SUBJECT=mailto:[email protected]
# S3-compatible media storage; guide and commission uploads use public CDN objects.
S3_ENDPOINT=https://s3.example.internal
S3_PUBLIC_URL=https://buzz-cdn.astrxl.dev
S3_REGION=auto
S3_BUCKET=buzz-sheet-media
S3_ACCESS_KEY_ID=replace-with-access-key
S3_SECRET_ACCESS_KEY=replace-with-secret-key
S3_VIRTUAL_HOSTED_STYLE=false
# Commission payment. Use the recipient number format accepted by Slip2Go.
COMMISSION_PROMPTPAY_TYPE=mobile
COMMISSION_PROMPTPAY_VALUE=0812345678
COMMISSION_RECEIVER_ACCOUNT_NUMBER=0812345678
# Use the complete verification URL supplied by your Slip2Go API Connect account.
SLIP2GO_VERIFY_URL=https://your-slip2go-api-host/api/verify-slip/qr-image/info
SLIP2GO_API_SECRET=replace-with-slip2go-secret
# Stable across replicas. Generate once and store only in the external secret.
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=replace-with-a-stable-32-byte-base64-key
# Set to the immutable image revision for version-skew protection.
NEXT_DEPLOYMENT_ID=local-development
# Shared with CI to authenticate deployment lifecycle notifications.
DEPLOYMENT_WEBHOOK_SECRET=replace-with-a-strong-random-secret
# Readiness dependency timeout.
HEALTHCHECK_TIMEOUT_MS=2500
# Set only when the trusted ingress sanitizes this header and direct pod ingress is denied.
TRUSTED_CLIENT_IP_HEADER=