diff options
Diffstat (limited to 'crates')
| -rw-r--r-- | crates/server/.env.example | 18 | ||||
| -rw-r--r-- | crates/server/src/main.rs | 9 |
2 files changed, 26 insertions, 1 deletions
diff --git a/crates/server/.env.example b/crates/server/.env.example index 8485826..b7501a1 100644 --- a/crates/server/.env.example +++ b/crates/server/.env.example @@ -1,3 +1,11 @@ +# Copy this file to .env and fill it in. .env is gitignored and must never be +# committed: it is the only place a password or a client secret belongs. +# +# In production, prefer real environment variables over a file. systemd units +# take EnvironmentFile= with the file owned by root and mode 600; container +# runtimes and hosting platforms have their own secret stores. The server reads +# plain environment variables either way, so nothing here has to change. + # Postgres. Create the database and role first: # sudo -u postgres createuser --pwprompt typerpunk # sudo -u postgres createdb -O typerpunk typerpunk @@ -13,6 +21,16 @@ FRONTEND_ORIGIN=http://localhost:4173 # texts.json in the process's working directory (the repo root, normally). TEXTS_JSON_PATH=texts.json +# The account promoted to administrator at startup. That account can appoint +# moderators from the Contribute screen. Leave it unset once the roles are +# assigned; it is only needed to create the first administrator, or to recover +# if the last one is removed. +TYPERPUNK_ADMIN_USERNAME= + +# Set to production to make the server refuse to start on an unsafe +# configuration rather than warn about it. +TYPERPUNK_ENV= + # Set to 1 behind TLS in production. Left off for local HTTP dev, where a # Secure cookie would silently never be set by the browser. COOKIE_SECURE=0 diff --git a/crates/server/src/main.rs b/crates/server/src/main.rs index 22cd9cd..b291e64 100644 --- a/crates/server/src/main.rs +++ b/crates/server/src/main.rs @@ -102,7 +102,14 @@ fn build_app(app_state: Arc<AppState>) -> Router { async fn main() -> anyhow::Result<()> { // Ignored if absent - production deployments are expected to set real // env vars directly rather than ship a .env file. - let _ = dotenvy::dotenv(); + // dotenvy searches upward from the working directory, so a plain call + // finds .env only when the server is started from crates/server. The + // usual thing is to run it from the repository root, so that location is + // tried too. Neither is required: every setting has a default or is read + // straight from the environment. + if dotenvy::dotenv().is_err() { + let _ = dotenvy::from_filename("crates/server/.env"); + } tracing_subscriber::fmt() .with_env_filter(tracing_subscriber::EnvFilter::try_from_default_env().unwrap_or_else(|_| "info".into())) |