Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
123 lines (112 loc) · 6.18 KB
/
Copy path.env.example
File metadata and controls
123 lines (112 loc) · 6.18 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
# CUDly local development env template
#
# Copy this file to `.env.local` (already in .gitignore) and fill in
# the placeholders. Loaded by: load-env.sh / your IDE / `direnv` —
# CUDly itself reads these via os.Getenv at runtime.
#
# All values here are PLACEHOLDERS. Never commit real secrets to .env*
# files; the .gitignore at the repo root already excludes everything
# matching `.env*` except this template.
# ---------------------------------------------------------------------
# Required: secrets resolver
# ---------------------------------------------------------------------
# SECRET_PROVIDER selects which secret store the resolver fetches from.
# aws | gcp | azure — production: real Secrets Manager / Key Vault
# env — local dev: resolve secret names to env vars
# In `env` mode, every secret-ref var (ADMIN_PASSWORD_SECRET,
# API_KEY_SECRET_ARN, etc.) holds the NAME of another env var whose
# value is the actual secret. See `internal/secrets/env_resolver.go`.
# Pairs with EMAIL_ENABLED=false so the email factory's no-op sender
# kicks in (see PR #333) — otherwise `env` is not a recognised email
# backend and the factory would fail dispatch.
SECRET_PROVIDER=env
# ---------------------------------------------------------------------
# Required: scheduled-task auth mode (no default — must be explicit)
# ---------------------------------------------------------------------
# Selects how the internal /api/scheduled/* endpoints authenticate.
# oidc — production: verify Google-issued OIDC ID tokens
# bearer — shared-secret token in Authorization header
# disabled — local dev: no auth check
# Required by `internal/server/scheduledauth/config.go`; app refuses
# to start when unset.
SCHEDULED_TASK_AUTH_MODE=disabled
# ---------------------------------------------------------------------
# Required: email gate (factory short-circuit, see PR #333)
# ---------------------------------------------------------------------
# When `false`, internal/email/factory.go returns a no-op sender that
# logs each invocation at debug level instead of dispatching to a
# cloud-specific backend. Pair with SECRET_PROVIDER=env for local dev.
EMAIL_ENABLED=false
# ---------------------------------------------------------------------
# Required: credential encryption key
# ---------------------------------------------------------------------
# In production exactly ONE of the per-cloud secret refs is set; the
# Go side reads them in priority order (ARN → NAME → ID → raw KEY).
# For local dev set CREDENTIAL_ENCRYPTION_ALLOW_DEV_KEY=1 to use the
# all-zero dev key without touching a Secrets Manager / Key Vault.
CREDENTIAL_ENCRYPTION_ALLOW_DEV_KEY=1
# CREDENTIAL_ENCRYPTION_KEY_SECRET_ARN=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-cred-enc-key-PLACEHOLDER
# CREDENTIAL_ENCRYPTION_KEY_SECRET_NAME=cudly-credential-encryption-key
# CREDENTIAL_ENCRYPTION_KEY_SECRET_ID=cudly-credential-encryption-key
# CREDENTIAL_ENCRYPTION_KEY=<64-hex-chars>
# ---------------------------------------------------------------------
# Required: admin auth + API
# ---------------------------------------------------------------------
# With SECRET_PROVIDER=env, the *_SECRET / *_SECRET_ARN vars hold the
# NAME of another env var whose value is the actual secret. The matched
# env var must then be defined below. Two reasons for the indirection:
# (1) production uses the same var name pointing at a real ARN/name;
# (2) the dev value is co-located with its lookup key so future readers
# can trace the chain in one file.
ADMIN_EMAIL=admin@cudly.local
ADMIN_PASSWORD_SECRET=ADMIN_PASSWORD_DEV
ADMIN_PASSWORD_DEV=LocalDev!Pass123
API_KEY_SECRET_ARN=ADMIN_API_KEY_DEV
ADMIN_API_KEY_DEV=cudly-local-dev-api-key-not-for-prod
# Required for signed one-click notification unsubscribe links. Generate a
# unique value for every environment (for example: openssl rand -hex 32).
NOTIFICATION_MUTE_SECRET=
# Production examples (override SECRET_PROVIDER and these):
# ADMIN_PASSWORD_SECRET=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-admin-password-PLACEHOLDER
# API_KEY_SECRET_ARN=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-api-key-PLACEHOLDER
# ---------------------------------------------------------------------
# Optional: web frontend / CORS / dashboard
# ---------------------------------------------------------------------
CORS_ALLOWED_ORIGIN=http://localhost:3000
DASHBOARD_URL=http://localhost:3000
# ENABLE_DASHBOARD=true
# DASHBOARD_BUCKET=cudly-dashboard-PLACEHOLDER
# ---------------------------------------------------------------------
# Optional: PostgreSQL (lazy — unset to skip)
# ---------------------------------------------------------------------
# DB_HOST=localhost
# DB_PORT=5432
# DB_USER=cudly
# DB_NAME=cudly
# DB_PASSWORD_SECRET=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-db-PLACEHOLDER
# CUDLY_MIGRATION_TIMEOUT=2m
# ---------------------------------------------------------------------
# Optional: cloud-provider profiles for multi-cloud onboarding
# ---------------------------------------------------------------------
# AWS_CONFIG_FILE=$HOME/.aws/config
# AZURE_TENANT_ID=00000000-0000-0000-0000-000000000000
# AZURE_CLIENT_ID=00000000-0000-0000-0000-000000000000
# AZURE_SUBSCRIPTION_ID=00000000-0000-0000-0000-000000000000
# AZURE_KEY_VAULT_URL=https://cudly-vault-placeholder.vault.azure.net/
# GCP_PROJECT_ID=cudly-placeholder
# AWS_REGION=us-east-1
# ---------------------------------------------------------------------
# Optional: SES / Azure ACS / SendGrid email config
# ---------------------------------------------------------------------
# EMAIL_ADDRESS=noreply@cudly.example
# AZURE_SMTP_HOST=smtp.azurecomm.net
# AZURE_SMTP_USERNAME_SECRET=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-smtp-user-PLACEHOLDER
# AZURE_SMTP_PASSWORD_SECRET=arn:aws:secretsmanager:us-east-1:000000000000:secret:cudly-smtp-pass-PLACEHOLDER
# ---------------------------------------------------------------------
# Optional: tunables
# ---------------------------------------------------------------------
# CUDLY_RECOMMENDATION_CACHE_TTL=15m
# CUDLY_MAX_ACCOUNT_PARALLELISM=8
# DEFAULT_PAYMENT_OPTION=no-upfront
# DEFAULT_RAMP_SCHEDULE=quarterly
# ENVIRONMENT=local