4a90ad910c
Add root Dockerfile (standalone Next output, multi-stage pnpm build), drop in-stack caddy in favor of publishing web's port for an external traefik LXC (file-provider dynamic config included), and document the portainer deploy flow. Also fixes issues that blocked any production build: a bad auth-client type cast, the ai SDK's mimeType->mediaType rename, an implicit-any callback param, and push.ts eagerly calling webpush.setVapidDetails at module import time (which crashed page-data collection whenever VAPID env vars weren't present at build) — now lazily configured on first send. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
69 lines
2.0 KiB
Bash
69 lines
2.0 KiB
Bash
# Database
|
|
DATABASE_URL=postgresql://epicure:epicure@localhost:5432/epicure
|
|
|
|
# Redis
|
|
REDIS_URL=redis://localhost:6379
|
|
|
|
# Storage (MinIO / S3-compatible)
|
|
STORAGE_ENDPOINT=http://localhost:9000
|
|
STORAGE_ACCESS_KEY=minioadmin
|
|
STORAGE_SECRET_KEY=minioadmin
|
|
STORAGE_BUCKET=epicure-uploads
|
|
STORAGE_REGION=us-east-1
|
|
|
|
# Auth (generate with: openssl rand -base64 32)
|
|
BETTER_AUTH_SECRET=
|
|
BETTER_AUTH_URL=http://localhost:3000
|
|
|
|
# Encryption key for BYOK AI keys stored in DB (generate with: openssl rand -base64 32)
|
|
# Separate from BETTER_AUTH_SECRET for key separation. Falls back to BETTER_AUTH_SECRET if unset.
|
|
ENCRYPTION_SECRET=
|
|
|
|
# OAuth — Google (always available)
|
|
GOOGLE_CLIENT_ID=
|
|
GOOGLE_CLIENT_SECRET=
|
|
|
|
# OAuth — GitHub (optional; set NEXT_PUBLIC_GITHUB_ENABLED=true to show button in UI)
|
|
GITHUB_CLIENT_ID=
|
|
GITHUB_CLIENT_SECRET=
|
|
NEXT_PUBLIC_GITHUB_ENABLED=
|
|
|
|
# OAuth — Discord (optional; set NEXT_PUBLIC_DISCORD_ENABLED=true to show button in UI)
|
|
DISCORD_CLIENT_ID=
|
|
DISCORD_CLIENT_SECRET=
|
|
NEXT_PUBLIC_DISCORD_ENABLED=
|
|
|
|
# OIDC — Authentik (or any OIDC provider)
|
|
# AUTHENTIK_BASE_URL: base URL including application slug, e.g.
|
|
# https://auth.example.com/application/o/epicure
|
|
# The discovery document is fetched from $AUTHENTIK_BASE_URL/.well-known/openid-configuration
|
|
# In authentik: create an OAuth2/OpenID provider, set redirect URI to
|
|
# $BETTER_AUTH_URL/api/auth/callback/authentik
|
|
AUTHENTIK_CLIENT_ID=
|
|
AUTHENTIK_CLIENT_SECRET=
|
|
AUTHENTIK_BASE_URL=
|
|
# Set to true to show Authentik login button in UI
|
|
NEXT_PUBLIC_AUTHENTIK_ENABLED=
|
|
|
|
# SMTP (leave blank to log emails to console in dev)
|
|
SMTP_HOST=
|
|
SMTP_PORT=587
|
|
SMTP_SECURE=false
|
|
SMTP_USER=
|
|
SMTP_PASS=
|
|
SMTP_FROM=Epicure <noreply@epicure.app>
|
|
|
|
# Web push (generate with: npx web-push generate-vapid-keys)
|
|
NEXT_PUBLIC_VAPID_PUBLIC_KEY=
|
|
VAPID_PRIVATE_KEY=
|
|
|
|
# Stripe (optional — webhook stub only)
|
|
STRIPE_WEBHOOK_SECRET=
|
|
|
|
# AI Providers (configure at least one)
|
|
OPENROUTER_API_KEY=
|
|
OPENROUTER_DEFAULT_MODEL=google/gemini-flash-1.5
|
|
OPENAI_API_KEY=
|
|
ANTHROPIC_API_KEY=
|
|
OLLAMA_BASE_URL=http://localhost:11434
|