The backend only allows app://j621 through CORS_ALLOWED_ORIGINS, so gen_env.sh now always writes that origin (plus the split-deploy frontend when one is given) and --update keeps hand-added origins instead of overwriting the list.
77 lines
3.0 KiB
Bash
77 lines
3.0 KiB
Bash
# J621 deployment environment — copy to deploy/.env and fill in.
|
|
#
|
|
# Compose reads this file for variable substitution AND passes it to the
|
|
# backend container (env_file), so everything here is visible to Django.
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Tailscale
|
|
# ---------------------------------------------------------------------------
|
|
# Reusable, untagged auth key (Settings -> Keys -> Generate auth key,
|
|
# Reusable = on, Tags = none). Auto-approves the device.
|
|
TS_AUTHKEY=
|
|
|
|
# Hostname this deployment gets on the tailnet; the funnel URL becomes
|
|
# https://<TS_HOSTNAME>.<tailnet>.ts.net. Use distinct names per compose.
|
|
TS_HOSTNAME=j621
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Django
|
|
# ---------------------------------------------------------------------------
|
|
# Long random string. Signs media URLs and encrypts stored e621 API keys —
|
|
# rotating it invalidates both, so users re-enter their e621 key.
|
|
SECRET_KEY=change-me-to-a-long-random-string
|
|
DEBUG=False
|
|
|
|
# Hosts Django may be reached on, comma separated, no scheme. Add the tailnet
|
|
# hostname of every compose that talks to this backend (and keep localhost /
|
|
# 127.0.0.1 for container health checks).
|
|
ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Cross-origin access (needed for the separate frontend + backend deploys)
|
|
# ---------------------------------------------------------------------------
|
|
# The origin the SPA is served from for split deploys, e.g.
|
|
# https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
|
|
# desktop shell's app://j621 origin into the line below (and keeps existing
|
|
# entries on --update).
|
|
# CORS_ALLOWED_ORIGINS=
|
|
# CSRF_TRUSTED_ORIGINS=
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Database (created by the compose files; change the password)
|
|
# ---------------------------------------------------------------------------
|
|
DB_NAME=j621
|
|
DB_USER=j621
|
|
DB_PASSWORD=j621
|
|
DB_ROOT_PASSWORD=j621root
|
|
|
|
# ---------------------------------------------------------------------------
|
|
# Optional overrides
|
|
# ---------------------------------------------------------------------------
|
|
# GUNICORN_WORKERS=2
|
|
# GUNICORN_THREADS=4
|
|
# GUNICORN_TIMEOUT=120
|
|
|
|
# Scheduler intervals in seconds (the "scheduler" service runs the periodic
|
|
# management commands; see deploy/README.md)
|
|
# J621_SYNC_EVERY=1800
|
|
# J621_CLEAN_EVERY=3600
|
|
# J621_BLACKLIST_EVERY=86400
|
|
|
|
# Rate limits (per IP anonymous, per account signed in)
|
|
# THROTTLE_ANON=120/min
|
|
# THROTTLE_USER=600/min
|
|
# THROTTLE_LOGIN=5/min
|
|
# THROTTLE_REGISTER=20/hour
|
|
# THROTTLE_E621_PROXY=60/hour
|
|
|
|
# e621 media hosts the backend may fetch from (downloads, proxies)
|
|
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
|
|
|
|
# Ephemeral similarity-check lifetime in minutes
|
|
# SIMILARITY_TTL_MINUTES=30
|
|
|
|
# Registry/tag used by the compose files and push scripts
|
|
# J621_REGISTRY=gitea.rainbow-herring.ts.net/jakebreath
|
|
# J621_TAG=latest
|