- Un seul conteneur applicatif : Express sert l'API, le frontend React compilé (fallback SPA, cache immutable sur /assets) et les images /uploads (nosniff + CSP default-src 'none') - En-têtes de sécurité (CSP stricte, X-Frame-Options DENY, etc.) portés de nginx vers helmet, compression gzip ajoutée - Application exposée sur le port 8321 (APP_PORT), PostgreSQL sur 127.0.0.1:56432 (DB_PORT, loopback uniquement pour l'admin locale) - TRUST_PROXY pilote la confiance aux en-têtes X-Forwarded-* (désactivé par défaut hors reverse-proxy) - Dockerfile multi-étages unique à la racine (build React → deps → image finale non-root, fs en lecture seule) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01Fkg15RCxNgUys4ru73He2o
33 lines
1.2 KiB
Bash
33 lines
1.2 KiB
Bash
# Copy this file to .env and fill in strong secrets before running.
|
|
# cp .env.example .env
|
|
# openssl rand -hex 32 # use for JWT_SECRET
|
|
# openssl rand -hex 24 # use for each DB password
|
|
|
|
# PostgreSQL superuser password (used only inside the db container)
|
|
POSTGRES_PASSWORD=change-me-postgres-superuser
|
|
|
|
# Password of the restricted application role (sbc_app) the API connects with
|
|
APP_DB_PASSWORD=change-me-app-db-password
|
|
|
|
# Secret used to sign session tokens (JWT). MUST be long and random.
|
|
JWT_SECRET=change-me-64-hex-chars-min
|
|
|
|
# Initial password of the admin account (admin@sluc-businessclub.fr).
|
|
# Applied/updated at API startup. Change it after first login.
|
|
ADMIN_INITIAL_PASSWORD=ChangeMe-Admin-2026!
|
|
|
|
# Initial password given to every seeded member account (demo data only)
|
|
MEMBER_INITIAL_PASSWORD=ChangeMe-Membre-2026!
|
|
|
|
# Set to "true" when serving over HTTPS (adds Secure flag on cookies)
|
|
COOKIE_SECURE=false
|
|
|
|
# Set to "true" only when running behind a reverse proxy (TLS termination)
|
|
TRUST_PROXY=false
|
|
|
|
# Uncommon ports to avoid collisions with other services
|
|
# Application (public web port)
|
|
APP_PORT=8321
|
|
# PostgreSQL, bound to 127.0.0.1 only (local admin access)
|
|
DB_PORT=56432
|