forked from datadrivenconstruction/OpenConstructionERP
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
126 lines (114 loc) · 6.86 KB
/
Copy path.env.example
File metadata and controls
126 lines (114 loc) · 6.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
# OpenConstructionERP Configuration
# Copy to .env and adjust values
# ── App ──────────────────────────────────────────────────────────
APP_ENV=development
APP_DEBUG=true
# Dev only: field magic-link request returns the plaintext token and PIN.
# Ignored when APP_ENV=production. Never set this on a server people reach.
# EXPOSE_DEV_AUTH_SECRETS=false
# Peers allowed to set X-Forwarded-For (IPs or CIDRs). Default: loopback and
# private ranges, i.e. a reverse proxy on the same host or docker network.
# TRUSTED_PROXIES=127.0.0.0/8,::1/128,10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,fc00::/7
LOG_LEVEL=INFO
ALLOWED_ORIGINS=http://localhost:5173
# ── Database (required) ─────────────────────────────────────────
DATABASE_URL=postgresql+asyncpg://oe:oe@localhost:5432/openestimate
DATABASE_SYNC_URL=postgresql://oe:oe@localhost:5432/openestimate
# ── Redis (optional — falls back to in-memory) ──────────────────
REDIS_URL=redis://localhost:6379/0
# ── Storage ─────────────────────────────────────────────────────
S3_ENDPOINT=http://localhost:9000
S3_ACCESS_KEY=minioadmin
S3_SECRET_KEY=minioadmin
S3_BUCKET=openestimate
# ── Auth ────────────────────────────────────────────────────────
# JWT_SECRET MUST be a random 32+ character string in production.
# Generate with `openssl rand -hex 32`
# (or `python -c "import secrets;print(secrets.token_urlsafe(32))"`).
# The backend refuses to boot in staging/production with a value shorter
# than 32 chars or matching any well-known default ("change-me",
# "secret", "jwt-secret", "openestimate-local-dev-key", etc.).
# Left unset on purpose: any literal here is a secret published in a public
# repository, so the useful ones are the ones nobody can copy. Unset, the
# backend refuses to boot outside development and tells you to generate one,
# and scripts/install.sh writes a fresh random value into .env.
# JWT_SECRET=
# ── Demo accounts ───────────────────────────────────────────────
# When set, the seeded demo users (demo@/estimator@/manager@openconstructionerp.com)
# use these passwords on every boot. If unset, a random password is generated
# per-installation and written to ~/.openestimator/.demo_credentials.json.
# DEMO_USER_PASSWORD=DemoPass1234!
# DEMO_ESTIMATOR_PASSWORD=DemoPass1234!
# DEMO_MANAGER_PASSWORD=DemoPass1234!
# Self-registration policy. ``open`` (default) = anyone can register,
# accounts active immediately. ``admin-approve`` = new accounts arrive
# is_active=False and need an admin to flip them active before login
# works. ``email-verify`` = same as admin-approve until the verify-email
# flow lands. ``closed`` = self-registration rejected with 403 (admins
# create users via API). Bootstrap path (no admin in DB) bypasses the
# gate so a fresh install can be initialised.
# OE_REGISTRATION_MODE=open
# In-app "Apply update" runs `pip install --upgrade` in the environment the
# server runs from. Off unless set to true, and always refused to the demo
# accounts. Switch it on only for a single-user pip install; Docker images
# and the desktop app are upgraded by replacing them, not by pip.
# ALLOW_RUNTIME_UPGRADE=false
# ── Punch list ──────────────────────────────────────────────────
# Who may verify a punch item. ``different_user`` (default) = four eyes:
# the verifier holds punchlist.verify and did not resolve the item.
# ``verify_permission`` = anyone holding punchlist.verify, even the resolver.
# OE_PUNCHLIST_VERIFY_POLICY=different_user
# ── Rate Limiting (requests per minute) ─────────────────────────
# API_RATE_LIMIT=100
# LOGIN_RATE_LIMIT=10
# AI_RATE_LIMIT=10
# ── AI (optional — features degrade gracefully) ────────────────
# QDRANT_URL=http://localhost:6333
# Fetch the semantic-search encoder weights in the background. Defaults to on
# for a desktop or local install and off for a server deploy; set it to
# override either way. Nothing waits for the download and nothing breaks
# without it. See backend/.env.example for the full note.
# OE_DOWNLOAD_EMBEDDING_MODEL=1
# Every provider key the app looks for in the environment. A key set in
# Settings > AI takes precedence; these are the fallback for headless and
# container deployments where nobody opens the settings page.
# OPENAI_API_KEY=
# ANTHROPIC_API_KEY=
# GEMINI_API_KEY=
# OPENROUTER_API_KEY=
# MISTRAL_API_KEY=
# GROQ_API_KEY=
# DEEPSEEK_API_KEY=
# Self-hosted AI endpoints (Ollama / vLLM) are fetched server-side. Loopback and
# private are allowed so a local runtime works; link-local and cloud metadata
# are always blocked. Set a comma-separated allowlist (hostnames and/or CIDRs)
# to restrict AI provider URLs to a known set.
# OE_AI_PROVIDER_ALLOWLIST=ollama.internal,10.20.0.0/16
# ── SMTP / email (used by the marketing-site forms API on :8891) ─
# The standalone marketing-site/demo-register-api.py service uses these
# to send confirmations + admin pings for:
# /register, /verify, /license-request, /inquiry, /subscribe,
# /partners-apply
# Empty SMTP_HOST = degrade gracefully (lead is still persisted to JSONL
# under /root/clawd/*.jsonl, but no email is sent and the service logs a
# warning). On VPS we use our hosting provider's SMTP relay — never a
# third-party form service (Formspree, FormSubmit, etc.).
# These names are bare, and in a source checkout the ERP loads this same file
# (config.py looks for backend/.env, then the repo-root .env), so the values
# bind its settings as well. They do nothing on their own: the ERP picks its
# transport with EMAIL_BACKEND, which defaults to "console" and prints instead
# of sending. To make the ERP send through this relay, set EMAIL_BACKEND=smtp
# and mind one name that does not carry across - the ERP setting is
# smtp_password, so it binds SMTP_PASSWORD, while the forms API above reads
# SMTP_PASS. It logs in only when user and password are both set, so a block
# filled in without SMTP_PASSWORD connects with no auth and the relay refuses.
# SMTP_HOST=
# SMTP_PORT=587
# SMTP_USER=
# SMTP_PASS=
# SMTP_PASSWORD=
# SMTP_FROM=info@datadrivenconstruction.io
# EMAIL_BACKEND=console # console | smtp | noop | memory
# ADMIN_EMAIL=info@datadrivenconstruction.io
# BASE_URL=https://openconstructionerp.com
# RESEND_API_KEY= # Optional alternative to SMTP