mirror of
https://github.com/AmruthPillai/Reactive-Resume.git
synced 2026-10-02 17:54:22 +10:00
* feat(deploy): support Vercel Hobby alongside Docker * fix(deploy): include PDFKit runtime font assets * docs(deploy): document Vercel and Docker setup * docs(deploy): record storage persistence checks * refactor(deploy): drop scheduled staging cleanup Staging uploads are deleted after finalization and expired ones are swept on each new upload, so the Vercel cron job, its route, and CRON_SECRET are no longer needed. The Deploy with Vercel wizard now asks for two secrets. * docs(deploy): restructure Vercel guides Split the Vercel page into a how-to with its environment reference, move the large RPC staging protocol to an API reference page, and move CI deployment checks to the contributing section. Point Deploy with Vercel buttons at main. * chore: remove agent planning records and fix web app description Delete superpowers plans/specs, ADRs, issue plans, execution briefs, domain context maps, and Europass research. Describe apps/web as a TanStack Router SPA served by apps/server. * refactor(deploy): simplify Vercel support code - Share one Redis client and key namespace through @reactive-resume/db/redis for API and auth instead of a second auth-only client. - Drop the auth seeding retry; the provider already treats concurrent inserts as no-ops and deployment preparation seeds before runtime. - Detect staging support from POST /api/storage/stage (404 on Docker) instead of a separate GET probe. - Read staged bodies directly; the signed upload already caps their size. - Close per-subscription Redis connections with disconnect() alone. - Check Blob health with one list call instead of write/read/delete. - Remove redundant tsdown onlyBundle list, dead namespace fallbacks, and the conditional spread in the health status. * fix(deploy): heal stopped runs with dead owners and keep auth up without Redis - Run owners refresh a Redis heartbeat until they release their claim. Stop requests reap the run immediately when the owner has stopped heartbeating, instead of leaving the thread blocked until the 15-minute TTL reaper. - Auth and oRPC rate limiters fall back to per-instance memory limits when Redis errors, instead of rejecting every login or failing requests. * ci: allow esbuild build for Vercel CLI and register deployment deps with knip pnpm 12 fails dlx installs with ignored build scripts, so allow esbuild explicitly. The server bundle keeps @vercel/blob, ioredis, and jose external, and api/index.mjs is the Vercel Function entry. * fix(web): send buffered RPC bodies instead of teed streams Reading a request clone turned the original body into a stream, which browsers send without inspectable request data and which needs duplex mode. Send the already buffered Blob for direct requests. * fix(web): send direct RPC bodies as bytes Blob request bodies are sent as data pipes, so browser tooling cannot inspect them. Buffer the original request as an ArrayBuffer and send those bytes; this restores the e2e save assertions that match on request data.
148 lines
5.5 KiB
Bash
148 lines
5.5 KiB
Bash
# --- Application ---
|
|
# Public port used by the production server and the Vite web server in local development.
|
|
PORT="3000"
|
|
|
|
# Port used by the Hono server in local development. Vite proxies API requests to this port.
|
|
SERVER_PORT="3001"
|
|
|
|
# Public URL where the app is served. Used for auth callbacks, OAuth issuer URLs,
|
|
# OpenGraph metadata, and absolute upload URLs.
|
|
APP_URL="http://localhost:3000"
|
|
|
|
# Optional: serve one already-public resume at /. Use the ID from /builder/<id>.
|
|
# Unset or blank keeps the marketing home. Restart after changes.
|
|
# ROOT_RESUME_ID=
|
|
|
|
# Vercel: APP_URL can be omitted; production uses VERCEL_PROJECT_PRODUCTION_URL.
|
|
|
|
# --- Database (PostgreSQL) ---
|
|
# PostgreSQL connection URL. In Docker Compose, the hostname is usually `postgres`;
|
|
# when running directly on your machine, `localhost` is typical.
|
|
DATABASE_URL="postgresql://postgres:postgres@postgres:5432/postgres"
|
|
|
|
# Optional direct connection for migrations (Neon: DATABASE_URL_UNPOOLED alias).
|
|
# DATABASE_MIGRATION_URL=""
|
|
# DATABASE_POOL_MAX="10"
|
|
|
|
# When "true", the server refuses to boot if the live database schema has drifted from
|
|
# the migration ledger (e.g. a table dropped outside migrations). Default "false" logs
|
|
# the drift loudly at startup and continues.
|
|
STRICT_SCHEMA_CHECK="false"
|
|
|
|
# --- Authentication ---
|
|
# Generated using `openssl rand -hex 32`
|
|
AUTH_SECRET="change-me-to-a-secure-secret-key-in-production"
|
|
|
|
# Better Auth Dashboard (optional)
|
|
# Enables the Better Auth Dashboard plugin when set, you probably don't need this.
|
|
BETTER_AUTH_API_KEY=""
|
|
|
|
# Social Auth (Google, optional)
|
|
# Set both values to enable Google sign-in.
|
|
GOOGLE_CLIENT_ID=""
|
|
GOOGLE_CLIENT_SECRET=""
|
|
|
|
# Social Auth (GitHub, optional)
|
|
# Set both values to enable GitHub sign-in.
|
|
GITHUB_CLIENT_ID=""
|
|
GITHUB_CLIENT_SECRET=""
|
|
|
|
# Social Auth (LinkedIn, optional)
|
|
# Set both values to enable LinkedIn sign-in.
|
|
LINKEDIN_CLIENT_ID=""
|
|
LINKEDIN_CLIENT_SECRET=""
|
|
|
|
# Custom OAuth Provider (optional)
|
|
# Set OAUTH_CLIENT_ID and OAUTH_CLIENT_SECRET plus either OAUTH_DISCOVERY_URL or
|
|
# the three manual endpoint URLs below.
|
|
OAUTH_PROVIDER_NAME=""
|
|
OAUTH_CLIENT_ID=""
|
|
OAUTH_CLIENT_SECRET=""
|
|
OAUTH_DISCOVERY_URL=""
|
|
OAUTH_AUTHORIZATION_URL=""
|
|
OAUTH_TOKEN_URL=""
|
|
OAUTH_USER_INFO_URL=""
|
|
|
|
# Space-separated scopes requested from the custom OAuth provider.
|
|
OAUTH_SCOPES="openid profile email"
|
|
|
|
# --- Email (optional) ---
|
|
# If SMTP_HOST, SMTP_USER, SMTP_PASS, or SMTP_FROM is missing, the app logs the
|
|
# email to the console instead.
|
|
SMTP_HOST=""
|
|
SMTP_PORT=""
|
|
SMTP_USER=""
|
|
SMTP_PASS=""
|
|
SMTP_FROM="Reactive Resume <noreply@rxresu.me>"
|
|
SMTP_SECURE="false"
|
|
|
|
# --- Storage (optional) ---
|
|
# Backend defaults to S3 when all credentials are present, otherwise local.
|
|
# Vercel defaults to private Blob. Explicit selection: local, s3, blob.
|
|
# STORAGE_BACKEND="local"
|
|
# BLOB_READ_WRITE_TOKEN=""
|
|
# BLOB_STORE_ID=""
|
|
# DEPLOYMENT_NAMESPACE="default"
|
|
# Vercel previews need isolated resources before setting ALLOW_PREVIEW_MIGRATIONS=true.
|
|
|
|
# If all S3 keys are disabled, Docker uses local filesystem storage instead.
|
|
# Make sure to mount this directory to a volume or the host filesystem to ensure data integrity.
|
|
# LOCAL_STORAGE_PATH overrides where local uploads/cache are written.
|
|
# Defaults to /app/data in the official Docker image; in dev, defaults to <workspace>/data.
|
|
# LOCAL_STORAGE_PATH="/app/data"
|
|
|
|
# Seaweedfs
|
|
S3_ACCESS_KEY_ID="seaweedfs"
|
|
S3_SECRET_ACCESS_KEY="seaweedfs"
|
|
S3_REGION="us-east-1"
|
|
S3_ENDPOINT="http://seaweedfs:8333"
|
|
S3_BUCKET="reactive-resume"
|
|
S3_FORCE_PATH_STYLE="true"
|
|
|
|
# --- AI Agent Workspace (optional) ---
|
|
# Required for the authenticated /agent workspace and saved AI providers.
|
|
# Redis also shares rate limits, resume events, cancellation and view deduplication.
|
|
# Vercel Upstash KV_URL is accepted as an alias for REDIS_URL.
|
|
REDIS_URL="redis://redis:6379"
|
|
ENCRYPTION_SECRET="change-me-to-a-secure-agent-secret-in-production"
|
|
|
|
# --- Feature Flags ---
|
|
# This flag disables new signups, both on the web app and the server.
|
|
FLAG_DISABLE_SIGNUPS="false"
|
|
|
|
# This flag disables email/password login. Disables email verification, forgot password, and reset password flows.
|
|
# Users can still sign up via social auth (Google/GitHub/Custom OAuth), unless FLAG_DISABLE_SIGNUPS is also set to true.
|
|
FLAG_DISABLE_EMAIL_AUTH="false"
|
|
|
|
# This flag disables the image processing.
|
|
# This is useful if you are using a machine with limited resources, like a Raspberry Pi.
|
|
FLAG_DISABLE_IMAGE_PROCESSING="false"
|
|
|
|
# This flag disables API rate limiting for authentication endpoints.
|
|
# Rate limiting is enabled by default in production to prevent abuse.
|
|
FLAG_DISABLE_API_RATE_LIMIT="false"
|
|
|
|
|
|
# Allows dynamic OAuth client registration to use any parseable redirect URI,
|
|
# including custom schemes, private hosts, and non-loopback http:// URLs.
|
|
# WARNING: Enabling this on a public or multi-tenant deployment can enable phishing
|
|
# or token exfiltration. Only enable this on a trusted, self-hosted instance.
|
|
FLAG_ALLOW_UNSAFE_OAUTH_REDIRECT_URI="false"
|
|
|
|
# Allows AI providers to be configured with any base URL, including http:// and
|
|
# private/loopback addresses (e.g. http://localhost:11434 for a local Ollama instance).
|
|
# WARNING: Enabling this on a multi-tenant deployment is a Server-Side Request Forgery (SSRF)
|
|
# risk. Only enable this on a trusted, single-tenant self-hosted instance.
|
|
FLAG_ALLOW_UNSAFE_AI_BASE_URL="false"
|
|
|
|
# --- Others ---
|
|
# Google Cloud API Key (optional)
|
|
# For font-list generation tooling.
|
|
# Requires "Google Fonts Developer API" to be enabled.
|
|
GOOGLE_CLOUD_API_KEY=""
|
|
|
|
# Crowdin (optional)
|
|
# For translation tooling.
|
|
CROWDIN_PROJECT_ID=""
|
|
CROWDIN_API_TOKEN=""
|