# runicgateway.com — production environment. # # Copy to `.env` beside docker-compose.yml on the host and fill in the two # secrets. Everything else has a working default; this file exists so the # defaults are visible rather than discovered. # # cp .env.example .env # # Nothing here is a credential for another service. The site talks to no API, # sends no mail (D7) and has no database server — the only state it keeps is a # SQLite file on the ./data mount. # --------------------------------------------------------------------------------------- # Deployment # --------------------------------------------------------------------------------------- # Which published build runs. `latest` follows main; pin `sha-<7>` for a # reproducible deploy or to roll back — every merge publishes both tags. IMAGE_TAG=latest # Host port the container is published on. SITE_HOST_PORT=4321 # Which of the host's addresses that port is published on. The default is every # interface, so the site answers on the host's own address — http://:4321 # — which is what a proxy in another container, another machine, or a browser # elsewhere on the network needs. # # Narrow it if this host has a public address and you want only the proxy to # reach the container: 127.0.0.1 for a proxy on this same host, or one interface # address for the LAN but not a public NIC. Nothing else in the site changes. SITE_BIND_ADDR=0.0.0.0 # --------------------------------------------------------------------------------------- # The closed-beta signup (PLAN.md §8) # --------------------------------------------------------------------------------------- # # THE TWO BELOW ARE THE ONLY VALUES THAT REALLY WANT SETTING. Both default to a # random value generated per process, which is safe but forgetful: every restart # invalidates every rate-limit window and every rendered form. That is the right # default — a hard-coded salt shipped in a public repository would make every # deployment's ip_hash values identical and therefore reversible by anyone who # can read it — but it is not what you want on a host that restarts. # # Generate both once, keep them, and do not rotate them casually: changing the # salt orphans the rate-limit history of everyone already counted. # # openssl rand -hex 32 # Salts the ip_hash column. The raw IP address is never stored — /privacy says # so, and this is the mechanism that makes it true while still allowing a # per-connection limit. BETA_IP_SALT= # Signs the hidden form token, so a script has to fetch the page before it can # post. Rotating this only invalidates forms currently open in a browser. BETA_FORM_KEY= # Rows, across all time, above which the form closes and says so on the page. BETA_TOTAL_CAP=500 # What one connection may do, in a rolling hour and a rolling day. BETA_PER_HOUR=3 BETA_PER_DAY=24 # Seconds between the page rendering and the form posting. Below the minimum is # treated as a script; above the maximum the form is stale and re-rendered. # Twelve hours is the default maximum. BETA_MIN_SECONDS=2 BETA_MAX_SECONDS=43200