Prérègle les secrets : déploiement sans configuration (Portainer)
- docker-compose : valeurs par défaut pour POSTGRES_PASSWORD, APP_DB_PASSWORD et les mots de passe initiaux (admin SlucAdmin2026!, membres SlucMembre2026!) — surchargeables par variables d'environnement - JWT_SECRET devient optionnel : l'application génère un secret aléatoire au démarrage s'il est absent (les sessions expirent alors au redémarrage du conteneur), aucun secret de signature n'est committé - .env.example et README mis à jour (démarrage clé en main, consignes de surcharge pour la production) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
This commit is contained in:
4 files changed
+55
-33
No files matched your search
+6
-3
@@ -1,5 +1,6 @@
|
||||
# Copy this file to .env and fill in strong secrets before running.
|
||||
# cp .env.example .env
|
||||
# OPTIONAL: the stack starts without any .env thanks to preconfigured
|
||||
# defaults in docker-compose.yml. For production, copy this file to .env
|
||||
# (or set the variables in Portainer) and override everything below.
|
||||
# openssl rand -hex 32 # use for JWT_SECRET
|
||||
# openssl rand -hex 24 # use for each DB password
|
||||
|
||||
@@ -9,7 +10,9 @@ POSTGRES_PASSWORD=change-me-postgres-superuser
|
||||
# Password of the restricted application role (sbc_app) the API connects with
|
||||
APP_DB_PASSWORD=change-me-app-db-password
|
||||
|
||||
# Secret used to sign session tokens (JWT). MUST be long and random.
|
||||
# Secret used to sign session tokens (JWT), at least 32 characters.
|
||||
# If unset, the app generates a random one at startup (sessions are then
|
||||
# invalidated whenever the container restarts).
|
||||
JWT_SECRET=change-me-64-hex-chars-min
|
||||
|
||||
# Initial password of the admin account (admin@sluc-businessclub.fr).
|
||||
|
||||
Reference in new issue
Block a user