Files
J621/deploy/.env.example
T
JakeBreath cf129714be Add an Electron desktop shell for the SPA
desktop/ serves the normal frontend build over a privileged app://j621
scheme, so localStorage, OPFS, Web Workers, WebCodecs and history routing
behave exactly like Chrome. Development points at the Vite dev server;
`npm run smoke` runs headless Electron and checks the bundled app.

External links open in the system browser, and download navigations
(?download=1 or media URLs) are rerouted through webContents.downloadURL,
since preventing them cancels the download. The setup screen names the
shell's origin when the connection test fails, and the deploy docs list
app://j621 for CORS_ALLOWED_ORIGINS.
2026-09-20 17:07:22 -05:00

77 lines
3.1 KiB
Bash

# J621 deployment environment — copy to deploy/.env and fill in.
#
# Compose reads this file for variable substitution AND passes it to the
# backend container (env_file), so everything here is visible to Django.
# ---------------------------------------------------------------------------
# Tailscale
# ---------------------------------------------------------------------------
# Reusable, untagged auth key (Settings -> Keys -> Generate auth key,
# Reusable = on, Tags = none). Auto-approves the device.
TS_AUTHKEY=
# Hostname this deployment gets on the tailnet; the funnel URL becomes
# https://<TS_HOSTNAME>.<tailnet>.ts.net. Use distinct names per compose.
TS_HOSTNAME=j621
# ---------------------------------------------------------------------------
# Django
# ---------------------------------------------------------------------------
# Long random string. Signs media URLs and encrypts stored e621 API keys —
# rotating it invalidates both, so users re-enter their e621 key.
SECRET_KEY=change-me-to-a-long-random-string
DEBUG=False
# Hosts Django may be reached on, comma separated, no scheme. Add the tailnet
# hostname of every compose that talks to this backend (and keep localhost /
# 127.0.0.1 for container health checks).
ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
# ---------------------------------------------------------------------------
# Cross-origin access (needed for the separate frontend + backend deploys)
# ---------------------------------------------------------------------------
# The origin the SPA is served from, e.g. https://j621-frontend.<tailnet>.ts.net
# The desktop app (desktop/) is served from app://j621, so add that origin too
# when it should reach this backend:
# CORS_ALLOWED_ORIGINS=https://j621-frontend.<tailnet>.ts.net,app://j621
# CORS_ALLOWED_ORIGINS=
# CSRF_TRUSTED_ORIGINS=
# ---------------------------------------------------------------------------
# Database (created by the compose files; change the password)
# ---------------------------------------------------------------------------
DB_NAME=j621
DB_USER=j621
DB_PASSWORD=j621
DB_ROOT_PASSWORD=j621root
# ---------------------------------------------------------------------------
# Optional overrides
# ---------------------------------------------------------------------------
# GUNICORN_WORKERS=2
# GUNICORN_THREADS=4
# GUNICORN_TIMEOUT=120
# Scheduler intervals in seconds (the "scheduler" service runs the periodic
# management commands; see deploy/README.md)
# J621_SYNC_EVERY=1800
# J621_CLEAN_EVERY=3600
# J621_BLACKLIST_EVERY=86400
# Rate limits (per IP anonymous, per account signed in)
# THROTTLE_ANON=120/min
# THROTTLE_USER=600/min
# THROTTLE_LOGIN=5/min
# THROTTLE_REGISTER=20/hour
# THROTTLE_E621_PROXY=60/hour
# e621 media hosts the backend may fetch from (downloads, proxies)
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
# Ephemeral similarity-check lifetime in minutes
# SIMILARITY_TTL_MINUTES=30
# Registry/tag used by the compose files and push scripts
# J621_REGISTRY=gitea.rainbow-herring.ts.net/jakebreath
# J621_TAG=latest