Files
EpicNext-Cms/.env.example
T
SimoandCursor c46dadeda4
Deploy / release (push) Skipped
Deploy / deploy (push) Successful in 1m39s
chore: harden deps, env validation, admin errors, and redis warnings
Align nodemailer with Auth.js peers, bump patch deps, validate env on deploy builds, add admin error boundary, and warn when Redis is missing in production.

Co-authored-by: Cursor <[email protected]>
2026-07-21 20:19:05 +02:00

98 lines
3.3 KiB
Bash

# Connection to the LIVE/COPY emulator MySQL/MariaDB database.
# The schema is owned by the Arcturus emulator — this app reads/writes data,
# it does NOT own or migrate the emulator tables. Format:
DATABASE_URL=mysql://user:[email protected]:3306/atomcms
# Optional pool tuning (defaults shown)
DATABASE_POOL_SIZE=40
DATABASE_IDLE_TIMEOUT_MS=300000
DATABASE_CONNECT_TIMEOUT_MS=10000
# Used by SSO ticket generation ({HOTEL_NAME}-{uuid})
HOTEL_NAME=Atom
APP_URL=http://localhost:3000
# NEXT_PUBLIC_APP_URL=https://yourdomain.com
AUTH_URL=http://localhost:3000
# NextAuth — required in production (>=32 chars). Optional in development.
# Laravel APP_KEY (base64:...) for existing 2FA secrets.
AUTH_SECRET=
APP_KEY=
CONVERT_PASSWORDS=false
# Password hashing for NEW/upgraded passwords: "bcrypt" (default; 60-char $2y$,
# fits a varchar(64) users.password) or "argon2id" (~97 chars, needs a wider
# column). Existing accounts in either format still verify on login.
PASSWORD_HASH=bcrypt
# Filesystem directory the badge uploader (/admin/badges) writes <code>.gif into
# — the emulator's badge image folder (e.g. .../assets/c_images/album1584).
# Leave unset to disable badge uploads.
BADGE_UPLOAD_DIR=
# Emulator JAR backup job (jobs-worker, runs host-side). When both are set, the
# worker copies the JAR daily into the backup dir, keeping the newest N.
EMULATOR_JAR_PATH=
EMULATOR_BACKUP_DIR=
EMULATOR_BACKUP_KEEP=7
# RCON link to the Arcturus emulator
RCON_HOST=127.0.0.1
RCON_PORT=3001
# Public imager URL — overrides the default /imaging relative path.
# Falls back to NEXT_PUBLIC_APP_URL/imaging when only the app URL is set.
# NEXT_PUBLIC_IMAGER_URL=https://epicnabbo.nl/imaging
# Optional OAuth (enabled when both id+secret are set)
DISCORD_CLIENT_ID=
DISCORD_CLIENT_SECRET=
GOOGLE_CLIENT_ID=
GOOGLE_CLIENT_SECRET=
# Preferred email provider (HTTP API). Used before SMTP when set.
RESEND_API_KEY=
# Optional SMTP fallback (password reset / alert emails)
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASSWORD=
SMTP_FROM=
# Optional alerting (jobs worker / alert service)
DISCORD_WEBHOOK_URL=
ALERT_EMAIL=
# Optional AI content moderation (user comments / guestbook).
# When set, posts are checked against the OpenAI Moderations endpoint in
# addition to the website_wordfilter blocklist. Fail-open if unset/erroring.
OPENAI_API_KEY=
# Optional PayPal top-up (sandbox by default)
PAYPAL_CLIENT_ID=
PAYPAL_SECRET=
PAYPAL_API=https://api-m.sandbox.paypal.com
# Redis — strongly recommended in production (required for multi-instance).
# Shared rate limiting + site-settings cache. Without it, limits are in-process
# only and do not hold across restarts or multiple app instances.
REDIS_URL=redis://127.0.0.1:6379
# Logging level (debug | info | warn | error). Defaults to 'info' in production,
# 'debug' in development. Production logs use structured JSON via pino.
LOG_LEVEL=info
# Optional Sentry error monitoring (no-op when unset).
# Server/edge use SENTRY_DSN; browser uses NEXT_PUBLIC_SENTRY_DSN.
SENTRY_DSN=
NEXT_PUBLIC_SENTRY_DSN=
# Optional source-map upload during CI builds (requires SENTRY_AUTH_TOKEN).
SENTRY_ORG=
SENTRY_PROJECT=
SENTRY_AUTH_TOKEN=
# Optional release tag shown in Sentry (e.g. git sha).
# Deploy sets APP_VERSION + NEXT_PUBLIC_APP_VERSION from git sha.
APP_VERSION=
NEXT_PUBLIC_APP_VERSION=