# ─── Rem0te API — Environment Variables ────────────────────────────────────── # # Copy this file to .env and fill in your values. # For production installs, the automated installer writes these to # /etc/reboot-remote/api.env — you don't need to touch this file. # # Generate secrets with: openssl rand -hex 32 # ───────────────────────────────────────────────────────────────────────────── # ─── Application ───────────────────────────────────────────────────────────── NODE_ENV=production # Port the API listens on (Caddy proxies to this) PORT=3001 # Public URL of the web frontend — used for CORS and cookie domain FRONTEND_URL=https://your-domain.example.com # Public URL of the API — embedded in install scripts and enrollment links PUBLIC_API_URL=https://your-domain.example.com # Set to true when running behind HTTPS (enables Secure flag on cookies) COOKIE_SECURE=true # ─── Database ───────────────────────────────────────────────────────────────── # PostgreSQL connection string # Format: postgresql://USER:PASSWORD@HOST:PORT/DATABASE DATABASE_URL=postgresql://reboot:CHANGE_ME@localhost:5432/reboot_remote # ─── Redis ──────────────────────────────────────────────────────────────────── # Used for rate limiting and session state REDIS_URL=redis://localhost:6379 # ─── JWT ────────────────────────────────────────────────────────────────────── # Secret for signing user JWTs — generate with: openssl rand -hex 32 JWT_SECRET=CHANGE_ME_64_HEX_CHARS # Token lifetime (Go duration string) JWT_EXPIRES_IN=8h # Separate secret for the desktop launcher deep-link tokens (short-lived, single-use) LAUNCHER_TOKEN_SECRET=CHANGE_ME_64_HEX_CHARS # Launcher token TTL in seconds (default: 120) LAUNCHER_TOKEN_TTL_SECONDS=120 # ─── Encryption ─────────────────────────────────────────────────────────────── # AES-256-GCM key used to encrypt TOTP secrets in the database. # MUST be exactly 64 hex characters (32 bytes). # Generate with: openssl rand -hex 32 ENCRYPTION_KEY=CHANGE_ME_64_HEX_CHARS # ─── MFA ────────────────────────────────────────────────────────────────────── # Issuer name shown in authenticator apps (e.g. Google Authenticator) MFA_ISSUER=Rem0te # ─── Enrollment ─────────────────────────────────────────────────────────────── # How long enrollment link tokens stay valid (hours, default: 48) CLAIM_TOKEN_TTL_HOURS=48 # ─── Rate Limiting ──────────────────────────────────────────────────────────── # Global throttle window (seconds) and max requests per window THROTTLE_TTL_SECONDS=60 THROTTLE_LIMIT=100 # ─── AI Features (optional) ─────────────────────────────────────────────────── # Anthropic API key — enables AI-generated device timeline summaries on endpoint detail pages. # Get your key at: https://console.anthropic.com # Leave blank to disable AI timeline generation (the UI will show a notice). ANTHROPIC_API_KEY= # ─── Paths (production only) ────────────────────────────────────────────────── # Absolute path to version.json — only needed if the auto-detected path is wrong # Default in production: /opt/reboot-remote/version.json VERSION_FILE=/opt/reboot-remote/version.json # Absolute path to the project root — used for the self-update and the Windows installer binary # Default in production: /opt/reboot-remote PROJECT_ROOT=/opt/reboot-remote # ─── In-app updates (optional, OFF by default) ─────────────────────────────── # Updates are supply-chain critical: the server git-checkouts and builds code # fetched from GitHub. Opt in deliberately, and only if the release tags are # GPG-signed with a key in the service account's keyring — the updater refuses # an unsigned tag. # # SOURCE_DIR is the git CHECKOUT to build from. It is NOT PROJECT_ROOT: # PROJECT_ROOT is the deploy target and is intentionally not a git repository. # Leave SOURCE_DIR unset and the About page will say so instead of offering an # Update button that fails on its first command. # ALLOW_IN_APP_UPDATE=false # SOURCE_DIR=/srv/rem0te-src # ─── Initial Seed (first-run only) ──────────────────────────────────────────── # These are used once by `prisma db seed` to create the initial platform admin # and a demo technician. Safe to remove after first run. SEED_ADMIN_EMAIL=admin@your-domain.example.com SEED_ADMIN_PASSWORD=CHANGE_ME_STRONG_PASSWORD SEED_TECH_EMAIL=tech@your-domain.example.com SEED_TECH_PASSWORD=CHANGE_ME_STRONG_PASSWORD