# EPPP configuration template — [E00-S04-T05] # # Copy this file to `.env` and fill in real values: # # cp .env.example .env # # Every value in this file is a PLACEHOLDER — the template intentionally ships # no real secrets. Real `.env` files stay git-ignored (`.env`, `.env.*` in # `.gitignore`), so a committed example can never leak a local secret. Never # commit a real `.env`. # --- Server configuration (read by @personal-blog/config, E00-S04-T04) ------- # Interface the HTTP server binds — a hostname or IPv4/IPv6 address. # Default: 0.0.0.0 (all interfaces — the container default). HOST=0.0.0.0 # Port the HTTP server listens on — an integer in the valid TCP range # (1-65535). Default: 3000. PORT=3000 # PostgreSQL connection string (optional). When unset, the app reports ready # immediately and skips the startup migration run (the local non-container # developer path). When set, the shape is: # postgres://:@:5432/ # (add your own credentials; a local no-credential default is shown below) DATABASE_URL=postgres://localhost:5432/eppp # Admin-session secret — REQUIRED and at least 32 characters (the config # schema's required field; Security-and-Operations §32/§26). Generate a fresh # one with `openssl rand -hex 32` and replace the placeholder below. The # placeholder is intentionally SHORTER than the 32-character minimum, so an # unedited `cp .env.example .env` is rejected at startup (fails closed) # instead of booting with a publicly known secret. EPPP_SESSION_SECRET=change-me # --- Docker Compose overrides (optional — compose.yaml has dev defaults) ------ # PostgreSQL database name / user / password and host port for the `db` # service (compose.yaml interpolates these with dev defaults). POSTGRES_DB=eppp POSTGRES_USER=eppp POSTGRES_PASSWORD=change-me-db-password POSTGRES_PORT=5432 # Host port for the `app` service. Default: 3000. APP_PORT=3000