-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathenv.example
More file actions
42 lines (34 loc) · 1.56 KB
/
Copy pathenv.example
File metadata and controls
42 lines (34 loc) · 1.56 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
# The starter example's environment. Copy to /etc/starter/env, owned by root
# and readable only by the service user:
#
# install -m 640 -o root -g starter Examples/deploy/env.example /etc/starter/env
#
# Every variable is read and checked once at start-up; `starter env` prints
# what it made of them, with the password taken out.
# production refuses guesses: no database URL, no signing key and no
# sslmode=disable are each an error rather than a default.
APP_ENV=production
# Required in production. sslmode=require means encrypted and verified;
# sslmode=prefer is refused, because falling back to plaintext when the server
# declines lets the network decide.
DATABASE_URL=postgres://starter:[email protected]:5432/starter?sslmode=require
# Required in production: what signs access tokens. A new key signs out every
# user, so keep it.
#
# openssl ecparam -genkey -name prime256v1 -noout -out /etc/starter/jwt.pem
# chown root:starter /etc/starter/jwt.pem && chmod 640 /etc/starter/jwt.pem
JWT_PRIVATE_KEY_FILE=/etc/starter/jwt.pem
# How long an access token lives. Nothing can take one back before it expires,
# which is why it is short.
ACCESS_TOKEN_SECONDS=900
# How long a refresh token may go unused, and how long a session lasts however
# often it is refreshed.
REFRESH_TOKEN_DAYS=14
SESSION_DAYS=90
# Per worker. 4 workers at 8 is 32 connections: check PostgreSQL's
# max_connections before raising it.
DATABASE_POOL_SIZE=8
# Whether anyone may create an account.
SIGNUPS_OPEN=false
# /docs serves Swagger UI and the OpenAPI document; off serves neither.
DOCS_PATH=off