# See apps/api/.env.example for the full annotated API configuration reference. # See docs/setup.md for the complete installation guide. # ─── API ───────────────────────────────────────────────────────────────────── NODE_ENV=production PORT=3001 FRONTEND_URL=https://your-domain.example.com PUBLIC_API_URL=https://your-domain.example.com COOKIE_SECURE=true # ─── Database ──────────────────────────────────────────────────────────────── DATABASE_URL=postgresql://reboot:CHANGE_ME@localhost:5432/reboot_remote # ─── Redis ─────────────────────────────────────────────────────────────────── REDIS_URL=redis://localhost:6379 # ─── JWT Secrets (generate with: openssl rand -hex 32) ─────────────────────── JWT_SECRET=CHANGE_ME_64_HEX_CHARS JWT_EXPIRES_IN=8h LAUNCHER_TOKEN_SECRET=CHANGE_ME_64_HEX_CHARS # ─── Encryption (AES-256-GCM key — must be exactly 64 hex chars / 32 bytes) ── ENCRYPTION_KEY=CHANGE_ME_64_HEX_CHARS # ─── Paths ─────────────────────────────────────────────────────────────────── VERSION_FILE=/opt/reboot-remote/version.json PROJECT_ROOT=/opt/reboot-remote # ─── In-app updates (optional, OFF by default) ─────────────────────────────── # Updates are supply-chain critical: the server git-checkouts and builds code # fetched from GitHub. Opt in deliberately, and only if the release tags are # GPG-signed with a key in the service account's keyring — the updater refuses # an unsigned tag. # # SOURCE_DIR is the git CHECKOUT to build from. It is NOT PROJECT_ROOT: # PROJECT_ROOT is the deploy target and is intentionally not a git repository. # Leave SOURCE_DIR unset and the About page will say so instead of offering an # Update button that fails on its first command. # ALLOW_IN_APP_UPDATE=false # SOURCE_DIR=/srv/rem0te-src # ─── Seeding (first run only) ──────────────────────────────────────────────── SEED_ADMIN_EMAIL=admin@your-domain.example.com SEED_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD SEED_TECH_EMAIL=tech@your-domain.example.com SEED_TECH_PASSWORD=CHANGE_ME_STRONG_PASSWORD