Files
buzz-sheet/.env.example
T

61 lines
2.2 KiB
Bash

# Public site origin used for SEO metadata, sitemap, and robots.txt.
BASE_URL=https://guide.sudloh.com
# Public AdSense publisher client ID. Leave unset to disable ads locally.
NEXT_PUBLIC_GOOGLE_ADSENSE_CLIENT_ID=ca-pub-9687404323559597
# PostgreSQL
DATABASE_URL=postgresql://buzz_sheet:[email protected]:5432/buzz_sheet?sslmode=require
DATABASE_POOL_SIZE=10
# Better Auth email/password administrator login
BETTER_AUTH_URL=http://localhost:3000
BETTER_AUTH_SECRET=replace-with-at-least-32-random-bytes
# Separate trusted browser origins with commas for local development or proxies.
BETTER_AUTH_TRUSTED_ORIGINS=http://localhost:3000
# Cloudflare Turnstile administrator login protection
TURNSTILE_SITE_KEY=replace-with-turnstile-site-key
TURNSTILE_SECRET_KEY=replace-with-turnstile-secret-key
# Redis remote cache, event transport, and outbox worker
REDIS_URL=rediss://default:[email protected]:6379
REDIS_CACHE_PREFIX=buzz:next-cache
REDIS_EVENT_PREFIX=buzz:events
REDIS_PRESENCE_PREFIX=buzz:presence
REDIS_SECURITY_PREFIX=buzz:security
REDIS_CACHE_MAX_ENTRY_BYTES=5242880
OUTBOX_BATCH_SIZE=20
OUTBOX_POLL_MS=1000
OUTBOX_LEASE_MS=30000
CATALOG_SYNC_CONCURRENCY=12
# Discord-triggered Lunaris catalog sync
DISCORD_BOT_TOKEN=replace-with-discord-bot-token
DISCORD_CHANNEL_ID=replace-with-private-channel-id
DISCORD_LOG_CHANNEL_ID=1547193755772125184
# S3-compatible media storage; direct guide uploads use public CDN objects.
S3_ENDPOINT=https://s3.example.internal
S3_PUBLIC_URL=https://buzz-cdn.astrxl.dev
S3_REGION=auto
S3_BUCKET=buzz-sheet-media
S3_ACCESS_KEY_ID=replace-with-access-key
S3_SECRET_ACCESS_KEY=replace-with-secret-key
S3_VIRTUAL_HOSTED_STYLE=false
# Stable across replicas. Generate once and store only in the external secret.
NEXT_SERVER_ACTIONS_ENCRYPTION_KEY=replace-with-a-stable-32-byte-base64-key
# Set to the immutable image revision for version-skew protection.
NEXT_DEPLOYMENT_ID=local-development
# Shared with CI to authenticate deployment lifecycle notifications.
DEPLOYMENT_WEBHOOK_SECRET=replace-with-a-strong-random-secret
# Readiness dependency timeout.
HEALTHCHECK_TIMEOUT_MS=2500
# Set only when Traefik overwrites this header and direct pod ingress is denied.
TRUSTED_CLIENT_IP_HEADER=