-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.env.example
More file actions
40 lines (33 loc) · 1.89 KB
/
Copy path.env.example
File metadata and controls
40 lines (33 loc) · 1.89 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
# easyTree environment template (EYT-43).
# Copy to .env and fill in real values locally. NEVER commit real credentials.
# Validated by @easytree/config (strict schema: unknown variables are rejected).
# development | test | production
NODE_ENV=development
# Postgres connection string (local Supabase stack default port 54322).
# SECRET in real environments: connection strings may embed credentials.
#
# Connect as easytree_app, NOT as postgres (EYT-45). postgres is a superuser and
# superusers bypass Row Level Security entirely, which would make every policy in
# supabase/migrations ineffective for the application (ADR-001 line 85). The API
# and the worker verify this at startup and refuse to boot as a superuser.
#
# The role is created by migration 0003_app_role; its password is provisioned
# out of band - locally with:
# psql "…user=postgres…" -c "alter role easytree_app password '<local>';"
DATABASE_URL=postgresql://easytree_app:replace-with-your-local-password@localhost:54322/postgres
# Supabase API URL (local stack default port 54321).
SUPABASE_URL=http://localhost:54321
# SECRET: Supabase anon key. Placeholder only — take the real value from
# `supabase start` output locally, or from your secret manager.
SUPABASE_ANON_KEY=replace-with-your-supabase-anon-key
# HTTP port of the NestJS API (1-65535).
API_PORT=3001
# SECRET: PostgreSQL root certificate (PEM) for TLS chain verification.
# REQUIRED in production, optional in development/test (the local Supabase
# container speaks plain TCP). Source: Supabase Dashboard -> Project Settings
# -> Database -> SSL Configuration -> Download certificate. Accepted formats:
# raw multi-line PEM, PEM with literal \n, or base64-encoded PEM.
# NEVER put a real certificate in this file or anywhere else in the repo.
# DATABASE_SSL_ROOT_CERT=replace-with-supabase-root-ca-pem
# fatal | error | warn | info | debug | trace (default: info)
LOG_LEVEL=info