It was never used. The repository lives on a self-hosted Gitea, which Vercel's git integration cannot connect to at all — so the documented route amounted to "mirror to GitHub first", and nobody did. vercel.json is gone, and with it the branch in next.config.ts that switched off `output: "standalone"` when the VERCEL variable was present. That branch was the only functional trace; everything else was documentation and comments describing a second deployment path that did not exist. DEPLOYMENT.md loses its "two supported ways" framing and the whole Vercel section — about fifty lines. Several statements next to it were stale for a different reason and are corrected in the same pass: the outbound-firewall table still listed Supabase's pooler (the database is a container now, nothing leaves the server), the prerequisites still demanded an existing Supabase project, and the .env table still asked for a pooler connection string instead of the two new passwords. The nightly job is described as what it is — a container in docker-compose.yml — rather than as a replacement for Vercel Cron. Migrations keep their references: two comments from July mention Vercel Cron, and they describe what was true when they were written. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
66 lines
3.1 KiB
Plaintext
66 lines
3.1 KiB
Plaintext
# ── Datenbank ────────────────────────────────────────────────────────
|
|
#
|
|
# Die Datenbank läuft als eigener Container (Dienst `db` in
|
|
# docker-compose.yml). Diese drei Werte richten ihn ein:
|
|
#
|
|
# POSTGRES_PASSWORD das des Verwalters (postgres) — nur für Migrationen,
|
|
# Sicherungen und Wartung
|
|
# APP_DB_PASSWORD das der Anwendungsrolle alpenwerk_app
|
|
# POSTGRES_DB Name der Datenbank; Vorgabe alpenwerk
|
|
#
|
|
# Beide Passwörter selbst erzeugen: `openssl rand -base64 24`
|
|
#
|
|
# Sie werden nur beim **allerersten** Start ausgewertet, solange das
|
|
# Datenverzeichnis leer ist. Ein späterer Wechsel braucht ein
|
|
# `alter role … password …` in der laufenden Datenbank.
|
|
POSTGRES_PASSWORD=
|
|
APP_DB_PASSWORD=
|
|
POSTGRES_DB=alpenwerk
|
|
POSTGRES_USER=postgres
|
|
|
|
# Womit die Anwendung sich verbindet. Im Compose-Netz heisst die Datenbank
|
|
# `db`; von aussen ist sie nicht erreichbar, es gibt bewusst keinen Port.
|
|
#
|
|
# Die Rolle in diesem String darf KEIN BYPASSRLS haben: fehlt der
|
|
# Sitzungskontext, sollen die Policies nichts zurückgeben statt alles.
|
|
# `alpenwerk_app` wird in deploy/db-init genau so angelegt.
|
|
DATABASE_URL=postgresql://alpenwerk_app:<APP_DB_PASSWORD>@db:5432/alpenwerk
|
|
# Im Compose-Netz läuft Postgres ohne TLS — die Verbindung verlässt den
|
|
# Server nicht. Bei einer Datenbank ausserhalb diesen Wert entfernen.
|
|
DATABASE_SSL=false
|
|
# Verbindungen im Pool; Vorgabe 10.
|
|
DATABASE_POOL_MAX=
|
|
|
|
# Der **direkte** Zugang für Migrationen (scripts/migrate.mjs). Als Verwalter,
|
|
# weil Migrationen Schemaänderungen vornehmen, die die Anwendungsrolle nicht
|
|
# darf. Bei Betrieb über docker compose wird er nicht gebraucht — der Dienst
|
|
# `migrate` setzt ihn selbst aus POSTGRES_PASSWORD zusammen.
|
|
MIGRATE_DATABASE_URL=
|
|
|
|
# ── Anmeldung (Auth.js + Microsoft Entra ID) ─────────────────────────
|
|
# Schlüssel, mit dem das Sitzungscookie signiert und verschlüsselt wird.
|
|
# Erzeugen mit `npx auth secret` oder `openssl rand -base64 32`. Ein Wechsel
|
|
# meldet alle ab — was im Ernstfall genau das gewünschte Mittel ist.
|
|
AUTH_SECRET=
|
|
|
|
# Aus der Anwendungsregistrierung im Entra-Portal: Anwendungs-ID (Client),
|
|
# ein Geheimnis daraus, und der Aussteller mit der Verzeichnis-ID (Mandant).
|
|
#
|
|
# Der Aussteller darf NICHT auf /common/ stehen bleiben — sonst könnte sich
|
|
# jedes Microsoft-Konto anmelden, auch ein privates.
|
|
AUTH_MICROSOFT_ENTRA_ID_ID=
|
|
AUTH_MICROSOFT_ENTRA_ID_SECRET=
|
|
AUTH_MICROSOFT_ENTRA_ID_ISSUER=https://login.microsoftonline.com/<verzeichnis-id>/v2.0
|
|
|
|
# Nur nötig, wenn die Anwendung hinter einem Reverse Proxy unter einer
|
|
# anderen Adresse erreichbar ist, als sie selbst sieht. Ohne diesen Wert baut
|
|
# Auth.js die Rückruf-Adresse aus den Request-Headern.
|
|
AUTH_URL=
|
|
|
|
# Gemeinsames Geheimnis, mit dem sich der nächtliche Lauf ausweist: der
|
|
# `cron`-Container schickt es als `Authorization: Bearer <wert>` an
|
|
# /api/cron/apply-pending-changes. Ohne angemeldete Person gibt es keine
|
|
# Sitzung, an der die Route den Aufruf prüfen könnte.
|
|
# Erzeugen mit: openssl rand -hex 32
|
|
CRON_SECRET=
|