-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.env.example
More file actions
126 lines (112 loc) · 8.04 KB
/
Copy path.env.example
File metadata and controls
126 lines (112 loc) · 8.04 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
# Root .env — consumed by docker-compose (the apps-machine stack).
# Copy to .env and fill in values. Never commit .env to git.
# Full apps-machine runbook: deploy/apps/README.md.
#
# On the apps machine the local auth runs verify-only, so it needs no Google
# secret; JWT_SECRET below is the only shared secret. (On a single all-in-one
# machine, set AUTH_VERIFY_ONLY=false and put Google creds in auth/.env.)
# ── Shared secret ──────────────────────────────────────────────────────────
# Signs the session cookie on the login box; validates it here. Must be
# IDENTICAL to the EC2 auth's JWT_SECRET, or every cookie is rejected.
# Generate once with: python -c "import secrets; print(secrets.token_hex(32))"
JWT_SECRET=replace-with-a-long-random-string
# ── Auth mode ───────────────────────────────────────────────────────────────
# true → this auth only validates cookies; login is delegated to AUTH_PUBLIC_URL
# (the EC2 login box). Needs only JWT_SECRET. Use this on the apps machine.
# false → full login node (Google OAuth); also fill in auth/.env.
AUTH_VERIFY_ONLY=true
# ── Domain ─────────────────────────────────────────────────────────────────
BASE_DOMAIN=starberkeley.org
# The central login box. Unauthenticated users are bounced here to sign in.
AUTH_PUBLIC_URL=https://auth.starberkeley.org
# Where the design tools fetch the team roster (everyone who has signed in) for
# their "share with" picker. Defaults to AUTH_PUBLIC_URL, which is right in the
# normal split: only the login box records logins, so the verify-only auth
# beside these apps has nothing to serve. Leave it unset unless the login node
# lives somewhere else. Unreachable or unset is not fatal -- the picker falls
# back to whoever already has designs on the shared volume.
# AUTH_USERS_URL=https://auth.starberkeley.org
# ── TLS ────────────────────────────────────────────────────────────────────
# https (default) → Caddy obtains Let's Encrypt certificates; needs ports 80
# and 443 reachable from the internet.
# http → Cloudflare terminates TLS and cloudflared reaches Caddy
# over plain HTTP. Use with `--profile tunnel`.
SCHEME=https
ACME_EMAIL=infra@starberkeley.org
# ── Image version ──────────────────────────────────────────────────────────
# Which tag of the ghcr.io/calstar/star-* images the stack runs. CI publishes
# two tags on every push to main: `latest` (moving) and `sha-<short>` (immutable,
# e.g. sha-abc1234).
# unset / latest → track the newest build on main (current default).
# sha-<short> → pin the whole stack to one build; roll back by editing this
# one line and re-running `docker compose … up -d`.
# Pin to a sha that CI actually published (check the repo's GHCR packages, or the
# short hash of a commit that ran the publish workflow). See deploy/apps/README.md.
STAR_IMAGE_TAG=latest
# Only needed with `--profile tunnel`. From the Cloudflare Zero Trust
# dashboard: Networks → Tunnels → your tunnel → install connector.
# CLOUDFLARE_TUNNEL_TOKEN=
# ── DAQ server ─────────────────────────────────────────────────────────────
# DAQ is not containerised — it runs natively on the test-stand machine because
# it needs the hardware. These tell Caddy where to reach it.
# host.docker.internal → the machine running this compose stack
# a hostname/IP → a separate test-stand box
DAQ_BACKEND=host.docker.internal:8081
DAQ_GUI=host.docker.internal:3000
# ── DAQ Run Viewer ─────────────────────────────────────────────────────────
# Read-only viewer for PAST Elodin runs (daq-viewer service). It reads the run
# DBs straight off this box, bind-mounted at /data/elodin. Point this at the
# real Elodin data dir on the machine — a wrong path silently bind-mounts an
# empty directory and the viewer just shows zero runs. (Runs on the same box
# that collects the data; that's the whole premise.) The mount is read-write,
# not :ro, because elodin-db opens each DB O_RDWR even to export it; the viewer
# itself never writes here and past runs are immutable, so this is safe.
ELODIN_DB_HOST_DIR=/home/aidan/.local/share/elodin
# CSV download bandwidth cap in bytes/sec, so a multi-GB export can't saturate
# the box uplink. Default 10 MB/s; raise or set 0 to disable.
# WEBVIEWER_MAX_DOWNLOAD_BPS=10485760
# ── P&ID Designer diagram versioning (S3) ──────────────────────────────────
# Per-user diagram history (microversions + releases) is stored in a versioned
# S3 bucket. Leave PID_S3_BUCKET empty to keep everything on the local userdata
# volume instead (no AWS). The apps machine is NOT on EC2, so authenticate with
# IAM access keys (not an instance role). See deploy/apps/app-s3-policy.json and
# deploy/apps/README.md for the one-time bucket + IAM setup.
# PID_S3_BUCKET=star-pid-designer
# PID_S3_PREFIX=pid
# AWS_DEFAULT_REGION=us-east-2
# AWS_ACCESS_KEY_ID=
# AWS_SECRET_ACCESS_KEY=
# ── Engine Design + STAR OpenRocket config versioning (S3) ─────────────────
# Same model as the P&ID versioning above: per-user design history
# (microversions + releases) in a versioned S3 bucket, or the local userdata
# volume when the bucket var is empty. Reuses the AWS_* credentials above. Give
# each app its own bucket (or one bucket with distinct prefixes). Configure a
# lifecycle rule to expire NONCURRENT versions of **/current.json; the immutable
# releases/ objects are current versions and are untouched by it. See
# deploy/apps/README.md.
# ENGINE_S3_BUCKET=star-engine-design
# ENGINE_S3_PREFIX=engine
# OPENROCKET_S3_BUCKET=star-openrocket
# OPENROCKET_S3_PREFIX=openrocket
# ── Onshape CM Viewer API key pair ─────────────────────────────────────────
# Leave empty and the stack still comes up -- cache-first endpoints work; only
# live Onshape calls (Search / refresh / build) fail until these are set. Get a
# key pair at https://dev-portal.onshape.com. After filling these in:
# docker compose up -d --force-recreate star-openrocket-api
# ONSHAPE_ACCESS_KEY=
# ONSHAPE_SECRET_KEY=
# ONSHAPE_BASE_URL= # optional; only for a non-default Onshape instance
# ── STAR Parts Hub (parts.starberkeley.org) ────────────────────────────────
# Setup runbook: parts-hub/DEPLOY.md. The app refuses to start until the four
# PARTS_* values below are set.
# PARTS_ONSHAPE_CLIENT_ID= # "STAR Parts" OAuth app, Enterprise settings -> Developer
# PARTS_ONSHAPE_CLIENT_SECRET=
# PARTS_LIBRARY_DOCUMENT_ID= # 24-char id of the "STAR Parts Library" document
# PARTS_SESSION_SECRET= # node -e "console.log(require('crypto').randomBytes(32).toString('base64url'))"
# Optional: a Read+Write key pair just for the hub. Falls back to ONSHAPE_ACCESS_KEY /
# ONSHAPE_SECRET_KEY above, which must then have Write scope too.
# PARTS_ONSHAPE_ACCESS_KEY=
# PARTS_ONSHAPE_SECRET_KEY=
# STARProject (the team task tracker) moved to the EC2 box — its service +
# Postgres and all STARPROJECT_* vars now live in deploy/ec2/ (see that
# .env.example and docker-compose.yml). It is not part of this apps stack.