mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-10-03 18:23:47 +10:00
Keep manual preparation available without provider credentials. Share bounded search and reading across Applications and the assistant with one selected Firecrawl, Tavily, or Exa connection. Backfill encrypted Firecrawl credentials without decrypting or removing legacy rows. Add nullable posting-source metadata to applications.
167 lines
6.4 KiB
Bash
167 lines
6.4 KiB
Bash
# --- Application ---
|
|
# Public port used by the production server and the Vite web server in local development.
|
|
PORT="3000"
|
|
|
|
# Port used by the Hono server in local development. Vite proxies API requests to this port.
|
|
SERVER_PORT="3001"
|
|
|
|
# Public URL where the app is served. Used for auth callbacks, OAuth issuer URLs,
|
|
# OpenGraph metadata, and absolute upload URLs.
|
|
APP_URL="http://localhost:3000"
|
|
|
|
# Optional: serve one already-public resume at /. Use the ID from /builder/<id>.
|
|
# Unset or blank keeps the marketing home. Restart after changes.
|
|
# ROOT_RESUME_ID=
|
|
|
|
# Vercel: APP_URL can be omitted; production uses VERCEL_PROJECT_PRODUCTION_URL.
|
|
|
|
# --- Database (PostgreSQL) ---
|
|
# PostgreSQL connection URL. In Docker Compose, the hostname is usually `postgres`;
|
|
# when running directly on your machine, `localhost` is typical.
|
|
DATABASE_URL="postgresql://postgres:postgres@postgres:5432/postgres"
|
|
|
|
# Optional direct connection for migrations (Neon: DATABASE_URL_UNPOOLED alias).
|
|
# DATABASE_MIGRATION_URL=""
|
|
# DATABASE_POOL_MAX="10"
|
|
|
|
# When "true", the server refuses to boot if the live database schema has drifted from
|
|
# the migration ledger (e.g. a table dropped outside migrations). Default "false" logs
|
|
# the drift loudly at startup and continues.
|
|
STRICT_SCHEMA_CHECK="false"
|
|
|
|
# --- Authentication ---
|
|
# Generated using `openssl rand -hex 32`
|
|
AUTH_SECRET="change-me-to-a-secure-secret-key-in-production"
|
|
|
|
# Better Auth Dashboard (optional)
|
|
# Enables the Better Auth Dashboard plugin when set, you probably don't need this.
|
|
BETTER_AUTH_API_KEY=""
|
|
|
|
# Social Auth (Google, optional)
|
|
# Set both values to enable Google sign-in.
|
|
GOOGLE_CLIENT_ID=""
|
|
GOOGLE_CLIENT_SECRET=""
|
|
|
|
# Social Auth (GitHub, optional)
|
|
# Set both values to enable GitHub sign-in.
|
|
GITHUB_CLIENT_ID=""
|
|
GITHUB_CLIENT_SECRET=""
|
|
|
|
# Social Auth (LinkedIn, optional)
|
|
# Set both values to enable LinkedIn sign-in.
|
|
LINKEDIN_CLIENT_ID=""
|
|
LINKEDIN_CLIENT_SECRET=""
|
|
|
|
# Custom OAuth Provider (optional)
|
|
# Set OAUTH_CLIENT_ID and OAUTH_CLIENT_SECRET plus either OAUTH_DISCOVERY_URL or
|
|
# the three manual endpoint URLs below.
|
|
OAUTH_PROVIDER_NAME=""
|
|
OAUTH_CLIENT_ID=""
|
|
OAUTH_CLIENT_SECRET=""
|
|
OAUTH_DISCOVERY_URL=""
|
|
OAUTH_AUTHORIZATION_URL=""
|
|
OAUTH_TOKEN_URL=""
|
|
OAUTH_USER_INFO_URL=""
|
|
|
|
# Space-separated scopes requested from the custom OAuth provider.
|
|
OAUTH_SCOPES="openid profile email"
|
|
|
|
# --- Email (optional) ---
|
|
# If SMTP_HOST, SMTP_USER, SMTP_PASS, or SMTP_FROM is missing, the app logs the
|
|
# email to the console instead.
|
|
SMTP_HOST=""
|
|
SMTP_PORT=""
|
|
SMTP_USER=""
|
|
SMTP_PASS=""
|
|
SMTP_FROM="Reactive Resume <noreply@rxresu.me>"
|
|
SMTP_SECURE="false"
|
|
|
|
# --- Storage (optional) ---
|
|
# Backend defaults to S3 when all credentials are present, otherwise local.
|
|
# Vercel defaults to private Blob. Explicit selection: local, s3, blob.
|
|
# STORAGE_BACKEND="local"
|
|
# BLOB_READ_WRITE_TOKEN=""
|
|
# BLOB_STORE_ID=""
|
|
# DEPLOYMENT_NAMESPACE="default"
|
|
# Vercel previews need isolated resources before setting ALLOW_PREVIEW_MIGRATIONS=true.
|
|
|
|
# If all S3 keys are disabled, Docker uses local filesystem storage instead.
|
|
# Make sure to mount this directory to a volume or the host filesystem to ensure data integrity.
|
|
# LOCAL_STORAGE_PATH overrides where local uploads/cache are written.
|
|
# Defaults to /app/data in the official Docker image; in dev, defaults to <workspace>/data.
|
|
# LOCAL_STORAGE_PATH="/app/data"
|
|
|
|
# Seaweedfs
|
|
S3_ACCESS_KEY_ID="seaweedfs"
|
|
S3_SECRET_ACCESS_KEY="seaweedfs"
|
|
S3_REGION="us-east-1"
|
|
S3_ENDPOINT="http://seaweedfs:8333"
|
|
S3_BUCKET="reactive-resume"
|
|
S3_FORCE_PATH_STYLE="true"
|
|
|
|
# --- AI Agent Workspace (optional) ---
|
|
# ENCRYPTION_SECRET is required for saved AI providers and the assistant.
|
|
# Redis is optional on a single server. Providers and conversations persist in PostgreSQL.
|
|
# Redis shares rate limits, resume events, cancellation and view deduplication, and resumes reply streams.
|
|
# Vercel Upstash KV_URL is accepted as an alias for REDIS_URL.
|
|
REDIS_URL="redis://redis:6379"
|
|
ENCRYPTION_SECRET="change-me-to-a-secure-agent-secret-in-production"
|
|
|
|
# --- Web access (optional) ---
|
|
# One shared connection supplies search and enhanced reading: firecrawl, tavily or exa.
|
|
# Leave unset to use the built-in reader and let users connect a personal key (requires ENCRYPTION_SECRET).
|
|
# WEB_ACCESS_PROVIDER="tavily"
|
|
# WEB_ACCESS_API_KEY=""
|
|
# Optional custom Firecrawl service, without /v2; may be keyless. Other providers use fixed cloud endpoints.
|
|
# WEB_ACCESS_PROVIDER="firecrawl"
|
|
# WEB_ACCESS_API_URL="http://localhost:3102"
|
|
# Legacy aliases still work when all WEB_ACCESS_* variables are unset.
|
|
# FIRECRAWL_API_URL="http://localhost:3102"
|
|
# FIRECRAWL_API_KEY=""
|
|
|
|
# Optional shared AI provider. When set, personal AI providers are disabled.
|
|
# AI_PROVIDER="openai"
|
|
# AI_MODEL="gpt-5-mini"
|
|
# AI_API_KEY=""
|
|
# AI_BASE_URL=""
|
|
|
|
# --- Feature Flags ---
|
|
# This flag disables new signups, both on the web app and the server.
|
|
FLAG_DISABLE_SIGNUPS="false"
|
|
|
|
# This flag disables email/password login. Disables email verification, forgot password, and reset password flows.
|
|
# Users can still sign up via social auth (Google/GitHub/Custom OAuth), unless FLAG_DISABLE_SIGNUPS is also set to true.
|
|
FLAG_DISABLE_EMAIL_AUTH="false"
|
|
|
|
# This flag disables the image processing.
|
|
# This is useful if you are using a machine with limited resources, like a Raspberry Pi.
|
|
FLAG_DISABLE_IMAGE_PROCESSING="false"
|
|
|
|
# This flag disables API and authentication rate limiting, including PDF export and AI requests.
|
|
# Rate limiting is enabled by default in production to prevent abuse.
|
|
FLAG_DISABLE_API_RATE_LIMIT="false"
|
|
|
|
|
|
# Allows dynamic OAuth client registration to use any parseable redirect URI,
|
|
# including custom schemes, private hosts, and non-loopback http:// URLs.
|
|
# WARNING: Enabling this on a public or multi-tenant deployment can enable phishing
|
|
# or token exfiltration. Only enable this on a trusted, self-hosted instance.
|
|
FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI="false"
|
|
|
|
# Allows AI providers to be configured with any base URL, including http:// and
|
|
# private/loopback addresses (e.g. http://localhost:11434 for a local Ollama instance).
|
|
# WARNING: Enabling this on a multi-tenant deployment is a Server-Side Request Forgery (SSRF)
|
|
# risk. Only enable this on a trusted, single-tenant self-hosted instance.
|
|
FLAG_ALLOW_UNSAFE_AI_BASE_URL="false"
|
|
|
|
# --- Others ---
|
|
# Google Cloud API Key (optional)
|
|
# For font-list generation tooling.
|
|
# Requires "Google Fonts Developer API" to be enabled.
|
|
GOOGLE_CLOUD_API_KEY=""
|
|
|
|
# Crowdin (optional)
|
|
# For translation tooling.
|
|
CROWDIN_PROJECT_ID=""
|
|
CROWDIN_API_TOKEN=""
|