One process owns this database — the image has run a single uvicorn worker for that reason since the four-engines bug — so a file beside the flows is the honest shape for it, and it is what lets `fluksio serve` need no infrastructure at all. Live values, node execution and the work queue never came here anyway; what does is a rollup a minute at a time, a row per cascade and the run history, and WAL keeps the readers going while that one writer works. DATA_DIR is now the one setting that moves everything an installation keeps; the rest derive from it and the images still spell theirs out. The schema is prepared in-process at startup, so the prestart service is gone, and the ten Postgres-only revisions collapse into one portable baseline. Three things only worked because psycopg was casting for us: a token's subject arriving as a string where the column is a UUID, `greatest`, and `date_bin`. The timestamps needed a column type of their own — SQLite stores no offset, and a naive datetime read back either raises against an aware `now` or serialises as local time. Postgres stays in the stack only for Umami, behind the analytics profile. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
60 lines
1.9 KiB
Bash
60 lines
1.9 KiB
Bash
# Template for the app stack's .env. The workspace root's scripts/setup.sh copies
|
|
# this file to .env on first run and then keeps the shared keys in sync with the
|
|
# root .env. Secrets stay as `changethis` here and are generated locally.
|
|
|
|
# Domain Traefik routes on and acquires TLS certificates for.
|
|
DOMAIN=localhost
|
|
|
|
# Used by the backend to build links in outgoing emails.
|
|
FRONTEND_HOST=http://localhost:5173
|
|
|
|
# local, staging, production
|
|
ENVIRONMENT=local
|
|
|
|
PROJECT_NAME="Fluksio"
|
|
STACK_NAME=fluksio-app
|
|
|
|
# Backend
|
|
# `http://frontend` is the compose-network origin the Playwright job loads the
|
|
# SPA from (docker/compose.ci.yml); without it every spec fails CORS at login.
|
|
BACKEND_CORS_ORIGINS="http://localhost,http://localhost:5173,http://app.localhost,https://localhost,https://localhost:5173,http://frontend"
|
|
SECRET_KEY=changethis
|
|
FIRST_SUPERUSER=admin@fluksio.com
|
|
FIRST_SUPERUSER_PASSWORD=changethis
|
|
|
|
# Emails
|
|
SMTP_HOST=
|
|
SMTP_USER=
|
|
SMTP_PASSWORD=
|
|
EMAILS_FROM_EMAIL=info@fluksio.com
|
|
SMTP_TLS=True
|
|
SMTP_SSL=False
|
|
SMTP_PORT=587
|
|
|
|
# Where this installation keeps everything: the database, flows, secrets,
|
|
# artifacts and the user venv. The compose stack sets it to the /data volume.
|
|
DATA_DIR=flow-data
|
|
# Any SQLAlchemy URL. Empty means SQLite in the data directory, which is what
|
|
# the engine is designed around — one process owns this database.
|
|
DATABASE_URL=
|
|
|
|
# The Postgres the optional Umami analytics profile runs on. Nothing else uses
|
|
# it; `make umami` provisions a least-privilege role inside it.
|
|
POSTGRES_DB=app
|
|
POSTGRES_USER=postgres
|
|
POSTGRES_PASSWORD=changethis
|
|
|
|
# Redis — flow engine state. Empty keeps the state in memory; the compose stack
|
|
# points the backend at its own `redis` service.
|
|
REDIS_HOST=
|
|
REDIS_PORT=6379
|
|
|
|
SENTRY_DSN=
|
|
|
|
# Docker registry images
|
|
DOCKER_IMAGE_BACKEND=fluksio-backend
|
|
DOCKER_IMAGE_FRONTEND=fluksio-frontend
|
|
|
|
# The MCP endpoint agents connect to, and the OAuth server behind it.
|
|
MCP_ENABLED=true
|