srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/crates
diff options
context:
space:
mode:
Diffstat (limited to 'crates')
-rw-r--r--crates/server/.env.example18
-rw-r--r--crates/server/src/main.rs9
2 files changed, 26 insertions, 1 deletions
diff --git a/crates/server/.env.example b/crates/server/.env.example
index 8485826..b7501a1 100644
--- a/crates/server/.env.example
+++ b/crates/server/.env.example
@@ -1,3 +1,11 @@
+# Copy this file to .env and fill it in. .env is gitignored and must never be
+# committed: it is the only place a password or a client secret belongs.
+#
+# In production, prefer real environment variables over a file. systemd units
+# take EnvironmentFile= with the file owned by root and mode 600; container
+# runtimes and hosting platforms have their own secret stores. The server reads
+# plain environment variables either way, so nothing here has to change.
+
# Postgres. Create the database and role first:
# sudo -u postgres createuser --pwprompt typerpunk
# sudo -u postgres createdb -O typerpunk typerpunk
@@ -13,6 +21,16 @@ FRONTEND_ORIGIN=http://localhost:4173
# texts.json in the process's working directory (the repo root, normally).
TEXTS_JSON_PATH=texts.json
+# The account promoted to administrator at startup. That account can appoint
+# moderators from the Contribute screen. Leave it unset once the roles are
+# assigned; it is only needed to create the first administrator, or to recover
+# if the last one is removed.
+TYPERPUNK_ADMIN_USERNAME=
+
+# Set to production to make the server refuse to start on an unsafe
+# configuration rather than warn about it.
+TYPERPUNK_ENV=
+
# Set to 1 behind TLS in production. Left off for local HTTP dev, where a
# Secure cookie would silently never be set by the browser.
COOKIE_SECURE=0
diff --git a/crates/server/src/main.rs b/crates/server/src/main.rs
index 22cd9cd..b291e64 100644
--- a/crates/server/src/main.rs
+++ b/crates/server/src/main.rs
@@ -102,7 +102,14 @@ fn build_app(app_state: Arc<AppState>) -> Router {
async fn main() -> anyhow::Result<()> {
// Ignored if absent - production deployments are expected to set real
// env vars directly rather than ship a .env file.
- let _ = dotenvy::dotenv();
+ // dotenvy searches upward from the working directory, so a plain call
+ // finds .env only when the server is started from crates/server. The
+ // usual thing is to run it from the repository root, so that location is
+ // tried too. Neither is required: every setting has a default or is read
+ // straight from the environment.
+ if dotenvy::dotenv().is_err() {
+ let _ = dotenvy::from_filename("crates/server/.env");
+ }
tracing_subscriber::fmt()
.with_env_filter(tracing_subscriber::EnvFilter::try_from_default_env().unwrap_or_else(|_| "info".into()))