forked from stampchain-io/stampchain.io
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.sample
More file actions
99 lines (85 loc) · 3.58 KB
/
Copy path.env.sample
File metadata and controls
99 lines (85 loc) · 3.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
# Database Configuration
DB_HOST=
DB_USER=
DB_PASSWORD=
DB_PORT=
DB_NAME=btc_stamps
DB_MAX_RETRIES=5
# API Configuration
API_BASE_URL=
# Quicknode Configuration
QUICKNODE_ENDPOINT=
QUICKNODE_API_KEY=
# Minting Service Configuration
MINTING_SERVICE_FEE_ADDRESS=
MINTING_SERVICE_FEE_FIXED_SATS=
MINTING_SERVICE_FEE_ENABLED=0 # 1 or 0
# Content Configuration
IMAGES_SRC_PATH=https://stampchain.io/stamps
# S3 Preview Storage (stamp preview PNGs and GIFs)
# Previews are stored in S3 alongside original stamp files, served via CloudFront.
# S3 path: s3://{bucket}/{image_dir}/previews/{stamp_number}.png|gif
AWS_S3_BUCKETNAME=stampchain.io
AWS_S3_IMAGE_DIR=stamps
PREVIEW_STORAGE=s3
CLOUDFRONT_PREVIEW_DOMAIN=stampchain.io
# MySQL TLS (required for MySQL 8.4 caching_sha2_password auth)
# TLS is enabled by default. Set to "false" only for local Docker MySQL.
# DB_ENABLE_TLS=true
# DB_CA_CERT_PATH=certs/rds-ca-bundle.pem
# Cache Configuration
CACHE=true # Set to true to enable caching
ELASTICACHE_ENDPOINT=
ELASITCACHE_PORT=6379
FORCE_REDIS_CONNECTION=false # Force Redis connection even in development
# Security Configuration
CSRF_SECRET_KEY=
OPENSTAMP_API_KEY=
CONNECTION_POOL_RESET_TOKEN=
# Internal API Security (Required for production)
INTERNAL_API_SECRET=your-secret-here # Configure CloudFlare to add X-Internal-Secret header
INTERNAL_API_KEY=your-api-key-here # Alternative: Direct API key authentication
APP_DOMAIN=stampchain.io # Primary domain for origin checks
ALLOWED_DOMAINS=stampchain.io,www.stampchain.io,*.cloudflare.com # Comma-separated allowed domains
# CloudFlare Access (Optional - if using CloudFlare Access)
CF_ACCESS_CLIENT_ID=
CF_ACCESS_CLIENT_SECRET=
# Cloudflare Browser Rendering Worker (for stamp preview generation)
# Deploy the worker from workers/preview-renderer/ with: cd workers/preview-renderer && wrangler deploy
# Set the secret with: wrangler secret put PREVIEW_AUTH_SECRET (must match CF_PREVIEW_WORKER_SECRET)
CF_PREVIEW_WORKER_URL=
CF_PREVIEW_WORKER_SECRET=
# Cloudflare API credentials (for wrangler deployments)
CLOUDFLARE_API_KEY=
CLOUDFLARE_EMAIL=
# OpenAPI Contract Testing (Always on by default for robust API validation)
# OPENAPI_VALIDATION_DISABLED=true # Uncomment only if you need to disable validation (e.g., performance testing)
# MARA Slipstream Integration Configuration
# MARA API endpoint for fee rate fetching and transaction submission
MARA_API_BASE_URL=https://slipstream.mara.com/rest-api
# Timeout for MARA API requests in milliseconds (default: 30000 = 30 seconds)
MARA_API_TIMEOUT=30000
# Service fee amount in satoshis when using MARA mode (required: 42000 sats)
MARA_SERVICE_FEE_SATS=12000
# Service fee address for MARA transactions (required MARA address)
MARA_SERVICE_FEE_ADDRESS=bc1qhhv6rmxvq5mj2fc3zne2gpjqduy45urapje64m
# AWS Deployment Configuration
AWS_REGION=us-east-1
AWS_ACCOUNT_ID=
AWS_PROJECT_NAME=stamps-app
AWS_ECR_REPO_NAME=btc-stamps-explorer
AWS_ECS_CLUSTER_NAME=stamps-app-prod
AWS_ECS_SERVICE_NAME=stamps-app-service
AWS_CODEBUILD_PROJECT_NAME=stamps-app-build
AWS_TASK_FAMILY=stamps-app-task
AWS_CONTAINER_NAME=stamps-app-service
AWS_CPU_UNITS=512
AWS_MEMORY=1024
AWS_DESIRED_COUNT=2
AWS_DOCKER_IMAGE_TAG=latest
# Network configuration - using public subnets with public IPs for cost-effectiveness
# This approach avoids NAT Gateway costs (~$32/month each) while enabling ECR connectivity
AWS_PUBLIC_SUBNET_1=subnet-xxxxxxxxxxxxxxxxx # Primary subnet for ECS tasks (MUST be public subnet with IGW)
AWS_PUBLIC_SUBNET_2=subnet-xxxxxxxxxxxxxxxxx # Secondary subnet (for high availability if needed)
AWS_ECS_SECURITY_GROUP=sg-xxxxxxxxxxxxxxxxx
DENO_ENV=production