# J621 deployment environment — copy to deploy/.env and fill in. # # Compose reads this file for variable substitution AND passes it to the # backend container (env_file), so everything here is visible to Django. # --------------------------------------------------------------------------- # Tailscale # --------------------------------------------------------------------------- # Reusable, untagged auth key (Settings -> Keys -> Generate auth key, # Reusable = on, Tags = none). Auto-approves the device. TS_AUTHKEY= # Hostname this deployment gets on the tailnet; the funnel URL becomes # https://..ts.net. Use distinct names per compose. TS_HOSTNAME=j621 # --------------------------------------------------------------------------- # Django # --------------------------------------------------------------------------- # Long random string. Signs media URLs and encrypts stored e621 API keys — # rotating it invalidates both, so users re-enter their e621 key. SECRET_KEY=change-me-to-a-long-random-string DEBUG=False # Hosts Django may be reached on, comma separated, no scheme. Add the tailnet # hostname of every compose that talks to this backend (and keep localhost / # 127.0.0.1 for container health checks). ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1 # --------------------------------------------------------------------------- # Cross-origin access (needed for the separate frontend + backend deploys) # --------------------------------------------------------------------------- # The origin the SPA is served from for split deploys, e.g. # https://j621-frontend..ts.net. gen_env.sh writes this plus the # desktop shell's app://j621 origin into the line below (and keeps existing # entries on --update). # CORS_ALLOWED_ORIGINS= # CSRF_TRUSTED_ORIGINS= # --------------------------------------------------------------------------- # Database (created by the compose files; change the password) # --------------------------------------------------------------------------- DB_NAME=j621 DB_USER=j621 DB_PASSWORD=j621 DB_ROOT_PASSWORD=j621root # --------------------------------------------------------------------------- # Optional overrides # --------------------------------------------------------------------------- # GUNICORN_WORKERS=2 # GUNICORN_THREADS=4 # GUNICORN_TIMEOUT=120 # Scheduler intervals in seconds (the "scheduler" service runs the periodic # management commands; see deploy/README.md) # J621_SYNC_EVERY=1800 # J621_CLEAN_EVERY=3600 # J621_BLACKLIST_EVERY=86400 # Rate limits (per IP anonymous, per account signed in) # THROTTLE_ANON=120/min # THROTTLE_USER=600/min # THROTTLE_LOGIN=5/min # THROTTLE_REGISTER=20/hour # THROTTLE_E621_PROXY=60/hour # Tailnet-only / private deployments can drop the general limits entirely. # Signed media URLs (/