Repository navigation
Expand file tree
/
Copy path.env.example
More file actions
92 lines (76 loc) · 3.43 KB
/
Copy path.env.example
File metadata and controls
92 lines (76 loc) · 3.43 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
# ============================================================
# Humanly Self-Hosted Environment Variables
# Copy to .env and adapt these values for your own deployment tooling.
# The one-command local quickstart generates its own development configuration.
# ============================================================
# ── Public domain ────────────────────────────────────────────────────────────
DOMAIN=yourdomain.com
# ── PostgreSQL ───────────────────────────────────────────────────────────────
POSTGRES_DB=humanly_dev
POSTGRES_USER=humanly_user
POSTGRES_PASSWORD=CHANGEME_strong_db_password
# ── Backend ──────────────────────────────────────────────────────────────────
NODE_ENV=production
PORT=3001
# Use Docker service names — NOT localhost
DATABASE_URL=postgresql://humanly_user:CHANGEME_strong_db_password@postgres:5432/humanly_dev
REDIS_URL=redis://redis:6379
DATABASE_POOL_MIN=5
DATABASE_POOL_MAX=20
DATABASE_SSL=false
# JWT — generate with: openssl rand -hex 32
JWT_SECRET=CHANGEME_run_openssl_rand_hex_32_here
JWT_ACCESS_EXPIRES=15m
JWT_REFRESH_EXPIRES=7d
# CORS — must match the public URL(s) the frontends are served from
CORS_ORIGIN=https://yourdomain.com,https://www.yourdomain.com
# Used to build certificate verification and auth email links
FRONTEND_ADMIN_URL=https://admin.yourdomain.com
FRONTEND_USER_URL=https://yourdomain.com
# Email (set EMAIL_SERVICE=sendgrid or smtp for real emails)
EMAIL_SERVICE=console
EMAIL_FROM=noreply@yourdomain.com
EMAIL_API_KEY=
EMAIL_HOST=
EMAIL_PORT=587
EMAIL_USER=
EMAIL_PASSWORD=
# Rate limiting
RATE_LIMIT_ENABLED=true
# PDF storage
# Use local for development or gcs for production Google Cloud Storage.
FILE_STORAGE_PROVIDER=local
UPLOAD_DIR=./storage
GCS_BUCKET_NAME=
GCS_BUCKET_REGION=
GCS_PROJECT_ID=
GCS_KEY_FILENAME=
FILE_STORAGE_KEY_PREFIX=files
GCS_SIGNED_URLS_ENABLED=true
GCS_SIGNED_URL_TTL_SECONDS=900
# GOOGLE_APPLICATION_CREDENTIALS can also be used by Google auth libraries.
# GCS example:
# FILE_STORAGE_PROVIDER=gcs
# GCS_BUCKET_NAME=your-humanly-pdf-bucket
# GCS_BUCKET_REGION=US
# GCS_PROJECT_ID=your-gcp-project
# Logging
LOG_LEVEL=info
# AI runtime guardrails. Provider API keys are stored per user, not in backend env.
AI_AGENT_MAX_TOOL_CALLS=60
AI_PROVIDER_TIMEOUT_MS=180000
# generate with: openssl rand -hex 32
AI_ENCRYPTION_KEY=CHANGEME_run_openssl_rand_hex_32_here
# Certificate integrity seal (optional).
# If omitted, Humanly derives a local Ed25519 signing key from JWT_SECRET.
# For production, set a stable PEM private key and expose the matching public key.
CERTIFICATE_ED25519_PRIVATE_KEY=
CERTIFICATE_ED25519_PUBLIC_KEY=
CERTIFICATE_ED25519_KEY_ID=humanly-ed25519-v1
# ── Frontend build-time variables (baked into JS bundle at build time) ────────
# Set these before building the frontend images.
NEXT_PUBLIC_API_URL=https://yourdomain.com/api/v1
NEXT_PUBLIC_WS_URL=wss://yourdomain.com
NEXT_PUBLIC_TRACKER_URL=https://yourdomain.com/tracker/humanly-tracker.min.js
# Publisher Portal is served at /admin (set as basePath in next.config.js at build time)
NEXT_PUBLIC_BASE_PATH=/admin