# OPTIONAL: the stack starts without any .env thanks to preconfigured # defaults in docker-compose.yml. For production, copy this file to .env # (or set the variables in Portainer) and override everything below. # openssl rand -hex 32 # use for JWT_SECRET # openssl rand -hex 24 # use for each DB password # PostgreSQL superuser password (used only inside the db container) POSTGRES_PASSWORD=change-me-postgres-superuser # Password of the restricted application role (sbc_app) the API connects with APP_DB_PASSWORD=change-me-app-db-password # Secret used to sign session tokens (JWT), at least 32 characters. # If unset, the app generates a random one at startup (sessions are then # invalidated whenever the container restarts). JWT_SECRET=change-me-64-hex-chars-min # Initial password of the admin account (admin@sluc-businessclub.fr). # Applied/updated at API startup. Change it after first login. ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026! # Initial password given to every seeded member account (demo data only) MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026! # --- HTTPS (production) ----------------------------------------------- # In production, serve the site over HTTPS through your reverse proxy and # set the three flags below to "true". The proxy must forward the headers # X-Forwarded-Proto and X-Forwarded-Host to the app. # Adds the Secure flag on the session cookie (cookie sent over HTTPS only) COOKIE_SECURE=false # Trusts the single reverse-proxy hop so the app records the real client IP TRUST_PROXY=true # Redirects any plain-HTTP request (through the proxy) to HTTPS FORCE_HTTPS=false # Uncommon ports to avoid collisions with other services # Application (public web port) APP_PORT=8321 # PostgreSQL, bound to 127.0.0.1 only (local admin access) DB_PORT=58412