Files
J621/deploy/.env.example
T
JakeBreath e2697c0a78 Stop throttling signed media and ease the browser's e621 queue
Signed media URLs are fetched by <img>/<video> tags without an
Authorization header, so they were charged to the anonymous 120/min
bucket: past that, galleries and the fish-greeting download got 429 JSON
instead of image bytes. The raw/thumbnail/staged-file/similarity-file
actions are now exempt, and THROTTLE_ENABLED=false removes the general
anon+user limits for private/tailnet deployments (login/register/proxy
guards stay).

The SPA's e621 client also stops self-throttling so hard: 1s gap between
browsing calls (2.5s for the stricter IQDB endpoint) and a 15s cooldown
instead of 60s when e621 answers 429.
2026-09-22 22:32:37 -05:00

81 lines
3.2 KiB
Bash

# J621 deployment environment — copy to deploy/.env and fill in.
#
# Compose reads this file for variable substitution AND passes it to the
# backend container (env_file), so everything here is visible to Django.
# ---------------------------------------------------------------------------
# Tailscale
# ---------------------------------------------------------------------------
# Reusable, untagged auth key (Settings -> Keys -> Generate auth key,
# Reusable = on, Tags = none). Auto-approves the device.
TS_AUTHKEY=
# Hostname this deployment gets on the tailnet; the funnel URL becomes
# https://<TS_HOSTNAME>.<tailnet>.ts.net. Use distinct names per compose.
TS_HOSTNAME=j621
# ---------------------------------------------------------------------------
# Django
# ---------------------------------------------------------------------------
# Long random string. Signs media URLs and encrypts stored e621 API keys —
# rotating it invalidates both, so users re-enter their e621 key.
SECRET_KEY=change-me-to-a-long-random-string
DEBUG=False
# Hosts Django may be reached on, comma separated, no scheme. Add the tailnet
# hostname of every compose that talks to this backend (and keep localhost /
# 127.0.0.1 for container health checks).
ALLOWED_HOSTS=j621.rainbow-herring.ts.net,localhost,127.0.0.1
# ---------------------------------------------------------------------------
# Cross-origin access (needed for the separate frontend + backend deploys)
# ---------------------------------------------------------------------------
# The origin the SPA is served from for split deploys, e.g.
# https://j621-frontend.<tailnet>.ts.net. gen_env.sh writes this plus the
# desktop shell's app://j621 origin into the line below (and keeps existing
# entries on --update).
# CORS_ALLOWED_ORIGINS=
# CSRF_TRUSTED_ORIGINS=
# ---------------------------------------------------------------------------
# Database (created by the compose files; change the password)
# ---------------------------------------------------------------------------
DB_NAME=j621
DB_USER=j621
DB_PASSWORD=j621
DB_ROOT_PASSWORD=j621root
# ---------------------------------------------------------------------------
# Optional overrides
# ---------------------------------------------------------------------------
# GUNICORN_WORKERS=2
# GUNICORN_THREADS=4
# GUNICORN_TIMEOUT=120
# Scheduler intervals in seconds (the "scheduler" service runs the periodic
# management commands; see deploy/README.md)
# J621_SYNC_EVERY=1800
# J621_CLEAN_EVERY=3600
# J621_BLACKLIST_EVERY=86400
# Rate limits (per IP anonymous, per account signed in)
# THROTTLE_ANON=120/min
# THROTTLE_USER=600/min
# THROTTLE_LOGIN=5/min
# THROTTLE_REGISTER=20/hour
# THROTTLE_E621_PROXY=60/hour
# Tailnet-only / private deployments can drop the general limits entirely.
# Signed media URLs (<img>/<video>) and the login/register/proxy guards are
# exempt from this switch either way.
# THROTTLE_ENABLED=false
# e621 media hosts the backend may fetch from (downloads, proxies)
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
# Ephemeral similarity-check lifetime in minutes
# SIMILARITY_TTL_MINUTES=30
# Registry/tag used by the compose files and push scripts
# J621_REGISTRY=gitea.rainbow-herring.ts.net/jakebreath
# J621_TAG=latest