-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
25 lines (19 loc) · 915 Bytes
/
Copy path.env.example
File metadata and controls
25 lines (19 loc) · 915 Bytes
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
# Copy this file to .env and fill in real values.
# .env is gitignored — never commit it.
#
# Generate secrets with: openssl rand -hex 32
# PostgreSQL superuser password (used by Docker Compose and the app user)
POSTGRES_PASSWORD=
# Keycloak admin console password
KEYCLOAK_ADMIN_PASSWORD=
# Keycloak OIDC client secret — injected into both Keycloak (realm import) and the API
KEYCLOAK_CLIENT_SECRET=
# M2M ingestion (statement-generator) service-account secret. Leave blank to reuse
# KEYCLOAK_CLIENT_SECRET in local dev; set a distinct value in production.
KEYCLOAK_INGEST_CLIENT_SECRET=
# Download-token signing key (HS256) — minimum 32 characters
DOWNLOAD_TOKEN_SECRET=
# Field-encryption key for customer SA ID numbers (AES-256-GCM) — base64 of exactly 32 bytes.
# Generate with: openssl rand -base64 32
# WARNING: losing this key makes stored ID numbers unrecoverable.
FIELD_ENCRYPTION_KEY=