# Copy to .env and fill in. .env is gitignored; this file is not. # Only hosted mode reads any of this -- serve.py and run_report.py ignore it entirely. # ─── Application ─────────────────────────────────────────────────── # The public origin. Verification and reset links in emails are built from this, # so if it is wrong every emailed link points somewhere unreachable. No trailing slash. APP_BASE_URL=http://localhost:8000 # python -c "import secrets; print(secrets.token_urlsafe(48))" # Rotating this signs everyone out and invalidates all pending email links. SECRET_KEY=change-me-to-at-least-32-random-characters # Leave false while serving plain HTTP. If this is true over http:// the browser # silently discards the session cookie: login appears to work and every later # request 401s. Blank means "derive it from APP_BASE_URL", which is usually right. COOKIE_SECURE=false ENV=prod LOG_LEVEL=INFO # ─── Database - MySQL ────────────────────────────────────────────── MYSQL_HOST=your-instance.rds.amazonaws.com MYSQL_PORT=3306 MYSQL_USER=your_user MYSQL_PASSWORD='your password; quote it if it has # or ? in it' MYSQL_DATABASE=your_database MYSQL_SLOW_QUERY_MS=500 MYSQL_POOL_SIZE=10 MYSQL_POOL_RECYCLE=3600 # ─── Default admin (seeded on startup) ───────────────────────────── # Created pre-verified on first boot. The password is NOT overwritten on later # boots, so rotating it in the app sticks. Set ADMIN_RESET_PASSWORD=true to force it. ADMIN_EMAIL=admin@example.com ADMIN_PASSWORD=change-me ADMIN_RESET_PASSWORD=false # ─── Email ───────────────────────────────────────────────────────── # "api" posts to EMAIL_ENDPOINT. "console" just logs the message and its link, # which is how you exercise signup/verify/reset locally without sending real mail. EMAIL_PROVIDER=api EMAIL_ENDPOINT=http://your-mail-host:8000/mail/send EMAIL_API_KEY=your-key EMAIL_FROM_NAME=PPC Dashboard # ─── Signup ──────────────────────────────────────────────────────── SIGNUP_ENABLED=true # Comma-separated. Blank means any domain may register. SIGNUP_ALLOWED_DOMAINS= # ─── Limits ──────────────────────────────────────────────────────── # Blank WORKSPACE_ROOT means the system temp dir. The container sets /srv/work. WORKSPACE_ROOT= MAX_CONCURRENT_ANALYSES=2