Some checks failed
CD / Build and push images (push) Successful in 3m16s
CI / Lint, typecheck, test (push) Successful in 3m5s
CD / Deploy to Test (push) Successful in 13s
CD / Smoke tests against Test (push) Failing after 3m35s
CD / Promote to Int (push) Has been skipped
CI / Auth e2e pack (push) Successful in 5m6s
CI / Import/export fidelity gate (push) Successful in 43s
CI / Build container images (push) Has been skipped
When the api runs against a database without the setup.completedAt marker, a global SetupGuard answers every non-exempt route with 503 setup_required; only /setup/*, health probes, and the session routes stay reachable. The wizard steps (POST /setup/admin|instance|smtp| registration|complete) write straight to their production homes; the Site Admin step signs its creator in, later steps require that session. Completing sets the marker and locks every step permanently (410, also across restarts, and not reopenable via PATCH /admin/settings). SMTP entered in the wizard is verified with a live delivery test first (failure blocks the step with the transport error as detail) and then persisted to the new env-backed secret store: a mode-600 dotenv file on the new `secrets` volume (SECRETS_FILE). Explicit container env always wins over the store; empty compose-passed strings count as unset. The mail transport now resolves lazily through SmtpConfigService so wizard changes apply without a restart. SETUP_ADMIN_* env pre-seeds the whole wizard at boot for automated deploys; a backfill migration marks instances that already have a Site Admin as completed, and seed/vitest global-setup do the same for fixture databases. The setup e2e suite provisions its own fresh database (CREATE DATABASE + migrate deploy) per run. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
63 lines
2.7 KiB
Plaintext
63 lines
2.7 KiB
Plaintext
# Dorfteich stage configuration. Copy to `.env` (mode 600, never in git)
|
|
# next to docker-compose.yml and adjust the values.
|
|
|
|
# --- required ---------------------------------------------------------------
|
|
# PostgreSQL password for the `dorfteich` database user.
|
|
POSTGRES_PASSWORD=change-me
|
|
|
|
# Secret that signs/verifies the short-lived collaboration tokens (issue #34).
|
|
# The api and collab services share this one value; use a long random string
|
|
# (e.g. `openssl rand -base64 32`). Min length 16.
|
|
COLLAB_TOKEN_SECRET=change-me-to-a-long-random-string
|
|
|
|
# --- images -----------------------------------------------------------------
|
|
# Image name prefix. Stages pull from the Gitea registry, e.g.
|
|
# gitea.101010.cloud/stwaidele/dorfteich — local builds use the default.
|
|
IMAGE_PREFIX=dorfteich
|
|
# Image tag to run: a git SHA, `test`, `int`, or a release tag like v1.2.0.
|
|
TAG=latest
|
|
|
|
# --- ports (localhost only; the host reverse proxy routes to these) ---------
|
|
# Suggested per stage on the shared host (ONE): test 8100/8101/8102,
|
|
# int 8110/8111/8112, prod 8120/8121/8122 (web/api/collab).
|
|
WEB_PORT=8100
|
|
API_PORT=8101
|
|
# collab (Hocuspocus) WebSocket server; the proxy routes /collab here.
|
|
COLLAB_PORT=8102
|
|
|
|
# --- behavior ----------------------------------------------------------------
|
|
# pino log level: fatal|error|warn|info|debug|trace
|
|
LOG_LEVEL=info
|
|
|
|
# Compose project name; set per stage (dorfteich-test, dorfteich-int, …).
|
|
COMPOSE_PROJECT_NAME=dorfteich
|
|
|
|
# --- public URL + mail --------------------------------------------------------
|
|
# Public base URL of the stage (scheme + host). E-mail links and the CSRF
|
|
# origin check are derived from it — it must match what browsers use.
|
|
APP_BASE_URL=https://test.dorfteich.cloud
|
|
|
|
# SMTP relay for outgoing mail (verification, password reset). Optional:
|
|
# leave everything unset and configure the relay in the browser during the
|
|
# first-run setup wizard instead (stored on the `secrets` volume, issue #80).
|
|
# Values set here always win over wizard-stored ones.
|
|
SMTP_HOST=mail.example.com
|
|
SMTP_PORT=465
|
|
SMTP_SECURE=true
|
|
SMTP_USER=wiki@example.com
|
|
SMTP_PASS=change-me
|
|
SMTP_FROM=Dorfteich <wiki@example.com>
|
|
|
|
# --- first-run setup (optional pre-seeding, issue #80) ------------------------
|
|
# A fresh (empty) database makes the instance require the browser setup
|
|
# wizard. Automated deploys can skip it entirely by pre-seeding the Site
|
|
# Admin here; the wizard then completes and locks itself at first boot.
|
|
# All three SETUP_ADMIN_* values are required for pre-seeding to trigger.
|
|
#SETUP_ADMIN_USERNAME=admin
|
|
#SETUP_ADMIN_EMAIL=admin@example.com
|
|
#SETUP_ADMIN_PASSWORD=change-me-please
|
|
#SETUP_ADMIN_DISPLAY_NAME=Admin
|
|
#SETUP_INSTANCE_NAME=Dorfteich
|
|
#SETUP_DEFAULT_LOCALE=en
|
|
#SETUP_REGISTRATION_MODE=open
|