Signed media URLs are fetched by <img>/<video> tags without an Authorization header, so they were charged to the anonymous 120/min bucket: past that, galleries and the fish-greeting download got 429 JSON instead of image bytes. The raw/thumbnail/staged-file/similarity-file actions are now exempt, and THROTTLE_ENABLED=false removes the general anon+user limits for private/tailnet deployments (login/register/proxy guards stay). The SPA's e621 client also stops self-throttling so hard: 1s gap between browsing calls (2.5s for the stricter IQDB endpoint) and a 15s cooldown instead of 60s when e621 answers 429.
81 lines
3.2 KiB
Bash
81 lines
3.2 KiB
Bash
# J621 deployment environment — copy to deploy/.env and fill in.
|
|
#
|
|
# Compose reads this file for variable substitution AND passes it to the
|
|
# backend container (env_file), so everything here is visible to Django.
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Tailscale
|
|
# ---------------------------------------------------------------------------
|
|
# Reusable, untagged auth key (Settings -> Keys -> Generate auth key,
|
|
# Reusable = on, Tags = none). Auto-approves the device.
|
|
TS_AUTHKEY=
|
|
|
|
# Hostname this deployment gets on the tailnet; the funnel URL becomes
|
|
# https://<TS_HOSTNAME>.<tailnet>.ts.net. Use distinct names per compose.
|
|
TS_HOSTNAME=j621
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Django
|
|
# ---------------------------------------------------------------------------
|
|
# Long random string. Signs media URLs and encrypts stored e621 API keys —
|
|
# rotating it invalidates both, so users re-enter their e621 key.
|
|
SECRET_KEY=change-me-to-a-long-random-string
|
|
DEBUG=False
|
|
|
|
# Hosts Django may be reached on, comma separated, no scheme. Add the tailnet
|
|
# hostname of every compose that talks to this backend (and keep localhost /
|
|
# 127.0.0.1 for container health checks).
|
|
ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Cross-origin access (needed for the separate frontend + backend deploys)
|
|
# ---------------------------------------------------------------------------
|
|
# The origin the SPA is served from for split deploys, e.g.
|
|
# https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
|
|
# desktop shell's app://j621 origin into the line below (and keeps existing
|
|
# entries on --update).
|
|
# CORS_ALLOWED_ORIGINS=
|
|
# CSRF_TRUSTED_ORIGINS=
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Database (created by the compose files; change the password)
|
|
# ---------------------------------------------------------------------------
|
|
DB_NAME=j621
|
|
DB_USER=j621
|
|
DB_PASSWORD=j621
|
|
DB_ROOT_PASSWORD=j621root
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Optional overrides
|
|
# ---------------------------------------------------------------------------
|
|
# GUNICORN_WORKERS=2
|
|
# GUNICORN_THREADS=4
|
|
# GUNICORN_TIMEOUT=120
|
|
|
|
# Scheduler intervals in seconds (the "scheduler" service runs the periodic
|
|
# management commands; see deploy/README.md)
|
|
# J621_SYNC_EVERY=1800
|
|
# J621_CLEAN_EVERY=3600
|
|
# J621_BLACKLIST_EVERY=86400
|
|
|
|
# Rate limits (per IP anonymous, per account signed in)
|
|
# THROTTLE_ANON=120/min
|
|
# THROTTLE_USER=600/min
|
|
# THROTTLE_LOGIN=5/min
|
|
# THROTTLE_REGISTER=20/hour
|
|
# THROTTLE_E621_PROXY=60/hour
|
|
# Tailnet-only / private deployments can drop the general limits entirely.
|
|
# Signed media URLs (<img>/<video>) and the login/register/proxy guards are
|
|
# exempt from this switch either way.
|
|
# THROTTLE_ENABLED=false
|
|
|
|
# e621 media hosts the backend may fetch from (downloads, proxies)
|
|
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
|
|
|
|
# Ephemeral similarity-check lifetime in minutes
|
|
# SIMILARITY_TTL_MINUTES=30
|
|
|
|
# Registry/tag used by the compose files and push scripts
|
|
# J621_REGISTRY=gitea.rainbow-herring.ts.net/jakebreath
|
|
# J621_TAG=latest
|