From 2e2aba11af00d83e9ddb871b48eb3dd694405c47 Mon Sep 17 00:00:00 2001 From: openhands Date: Tue, 28 Jul 2026 18:23:51 +0200 Subject: [PATCH] Configure environment for Epicnextcms with Redis and Arcturus --- .env.example | 77 ++++++++++++++++------------------------------------ 1 file changed, 23 insertions(+), 54 deletions(-) diff --git a/.env.example b/.env.example index f3391aa4..88160ac8 100644 --- a/.env.example +++ b/.env.example @@ -1,95 +1,64 @@ -# Connection to the LIVE/COPY emulator MySQL/MariaDB database. -# The schema is owned by the Arcturus emulator — this app reads/writes data, -# it does NOT own or migrate the emulator tables. Format: -DATABASE_URL=mysql://user:password@127.0.0.1:3306/atomcms +# ============================================================================== +# Epicnextcms — Environment Configuration +# Focus: Epicnextcms & Autonomy / Rest Optimization +# ============================================================================== -# Optional pool tuning (defaults shown) +# --- DATABASE CONNECTION (Arcturus Emulator LIVE/COPY Database) --- +DATABASE_URL=mysql://user:password@127.0.0.1:3306/atomcms DATABASE_POOL_SIZE=10 DATABASE_IDLE_TIMEOUT_MS=300000 DATABASE_CONNECT_TIMEOUT_MS=10000 -# Redis for rate limits, site-settings cache, and JWT invalidation -# REDIS_URL=redis://localhost:6379 +# --- REDIS CACHE & RATE LIMITING (Required for production stability) --- +REDIS_URL=redis://127.0.0.1:6379 -# Used by SSO ticket generation ({HOTEL_NAME}-{uuid}) -HOTEL_NAME=Atom +# --- APPLICATION URLS & HOTEL SETTINGS --- +HOTEL_NAME=EPIC WEB CONTROL APP_URL=http://localhost:3000 -# NEXT_PUBLIC_APP_URL=https://yourdomain.com +NEXT_PUBLIC_APP_URL=http://localhost:3000 AUTH_URL=http://localhost:3000 -# NextAuth — required in production (>=32 chars). Optional in development. -# Laravel APP_KEY (base64:...) for existing 2FA secrets. -AUTH_SECRET= +# --- SECURITY & AUTHENTICATION --- +# Ensure AUTH_SECRET is at least 32 characters long in production +AUTH_SECRET=your-super-secret-auth-key-change-this-min-32-chars APP_KEY= CONVERT_PASSWORDS=false - -# Password hashing for NEW/upgraded passwords: "bcrypt" (default; 60-char $2y$, -# fits a varchar(64) users.password) or "argon2id" (~97 chars, needs a wider -# column). Existing accounts in either format still verify on login. PASSWORD_HASH=bcrypt -# Filesystem directory the badge uploader (/admin/badges) writes .gif into -# — the emulator's badge image folder (e.g. .../assets/c_images/album1584). -# Leave unset to disable badge uploads. +# --- ASSETS & EMULATOR INTEGRATION --- BADGE_UPLOAD_DIR= - -# Emulator JAR backup job (jobs-worker, runs host-side). When both are set, the -# worker copies the JAR daily into the backup dir, keeping the newest N. EMULATOR_JAR_PATH= EMULATOR_BACKUP_DIR= EMULATOR_BACKUP_KEEP=7 -# RCON link to the Arcturus emulator +# --- RCON CONNECTION --- RCON_HOST=127.0.0.1 RCON_PORT=3001 +NEXT_PUBLIC_IMAGER_URL=http://localhost:3000/imaging -# Public imager URL — overrides the default /imaging relative path. -# Falls back to NEXT_PUBLIC_APP_URL/imaging when only the app URL is set. -# NEXT_PUBLIC_IMAGER_URL=https://epicnabbo.nl/imaging - -# Preferred email provider (HTTP API). Used before SMTP when set. +# --- EMAIL & NOTIFICATIONS --- RESEND_API_KEY= - -# Optional SMTP fallback (password reset / alert emails) SMTP_HOST= SMTP_PORT=587 -SMTP_USER= -SMTP_PASSWORD= +SMTP_USER=SMTP_PASSWORD= SMTP_FROM= -# Optional alerting (jobs worker / alert service) +# --- ALERTING & MONITORING --- DISCORD_WEBHOOK_URL= ALERT_EMAIL= -# Optional AI content moderation (user comments / guestbook). -# When set, posts are checked against the OpenAI Moderations endpoint in -# addition to the website_wordfilter blocklist. Fail-open if unset/erroring. +# --- MODERATION & PAYMENTS --- OPENAI_API_KEY= - -# Optional PayPal top-up (sandbox by default) PAYPAL_CLIENT_ID= PAYPAL_SECRET= PAYPAL_API=https://api-m.sandbox.paypal.com -# Redis — REQUIRED for production (shared rate limits, site-settings cache, -# JWT session invalidation cache). Without REDIS_URL the app falls back to -# in-process memory: limits reset on restart and do not work across instances. -# Deploy logs a loud warning when this is unset in production. -REDIS_URL=redis://127.0.0.1:6379 - -# Logging level (debug | info | warn | error). Defaults to 'info' in production, -# 'debug' in development. Production logs use structured JSON via pino. +# --- LOGGING & ERROR TRACKING (Sentry) --- LOG_LEVEL=info - -# Optional Sentry error monitoring (no-op when unset). -# Server/edge use SENTRY_DSN; browser uses NEXT_PUBLIC_SENTRY_DSN. SENTRY_DSN= NEXT_PUBLIC_SENTRY_DSN= -# Optional source-map upload during CI builds (requires SENTRY_AUTH_TOKEN). SENTRY_ORG= SENTRY_PROJECT= SENTRY_AUTH_TOKEN= -# Optional release tag shown in Sentry (e.g. git sha). -# Deploy sets APP_VERSION + NEXT_PUBLIC_APP_VERSION from git sha. APP_VERSION= -NEXT_PUBLIC_APP_VERSION= +NEXT_PUBLIC_APP_VERSION= \ No newline at end of file