Files
SBC/.env.example
T
Claude 3f35ea584f Prérègle les secrets : déploiement sans configuration (Portainer)
- docker-compose : valeurs par défaut pour POSTGRES_PASSWORD,
  APP_DB_PASSWORD et les mots de passe initiaux (admin SlucAdmin2026!,
  membres SlucMembre2026!) — surchargeables par variables d'environnement
- JWT_SECRET devient optionnel : l'application génère un secret aléatoire
  au démarrage s'il est absent (les sessions expirent alors au redémarrage
  du conteneur), aucun secret de signature n'est committé
- .env.example et README mis à jour (démarrage clé en main, consignes de
  surcharge pour la production)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
2026-07-10 20:02:55 +00:00

36 lines
1.4 KiB
Bash

# OPTIONAL: the stack starts without any .env thanks to preconfigured
# defaults in docker-compose.yml. For production, copy this file to .env
# (or set the variables in Portainer) and override everything below.
# openssl rand -hex 32 # use for JWT_SECRET
# openssl rand -hex 24 # use for each DB password
# PostgreSQL superuser password (used only inside the db container)
POSTGRES_PASSWORD=change-me-postgres-superuser
# Password of the restricted application role (sbc_app) the API connects with
APP_DB_PASSWORD=change-me-app-db-password
# Secret used to sign session tokens (JWT), at least 32 characters.
# If unset, the app generates a random one at startup (sessions are then
# invalidated whenever the container restarts).
JWT_SECRET=change-me-64-hex-chars-min
# Initial password of the admin account (admin@sluc-businessclub.fr).
# Applied/updated at API startup. Change it after first login.
ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026!
# Initial password given to every seeded member account (demo data only)
MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026!
# Set to "true" when serving over HTTPS (adds Secure flag on cookies)
COOKIE_SECURE=false
# Set to "true" only when running behind a reverse proxy (TLS termination)
TRUST_PROXY=false
# Uncommon ports to avoid collisions with other services
# Application (public web port)
APP_PORT=8321
# PostgreSQL, bound to 127.0.0.1 only (local admin access)
DB_PORT=56432