chore: move deployment settings into environment
This commit is contained in:
parent
7f56484527
commit
7a0138fffd
27
.env.example
27
.env.example
|
|
@ -1,18 +1,41 @@
|
||||||
# Local Compose defaults work without this file. Replace every value before a public deployment.
|
# Copy this file to .env. Compose intentionally refuses to start without the
|
||||||
|
# required values. Replace every credential before any public deployment.
|
||||||
HTTP_PORT=4010
|
HTTP_PORT=4010
|
||||||
MAILPIT_PORT=8027
|
MAILPIT_PORT=8027
|
||||||
PHX_HOST=localhost
|
PHX_HOST=localhost
|
||||||
|
PHX_SCHEME=http
|
||||||
|
PHX_URL_PORT=4010
|
||||||
# Android debug builds compile this origin into BuildConfig. The Docker
|
# Android debug builds compile this origin into BuildConfig. The Docker
|
||||||
# emulator uses adb reverse to expose the local Compose proxy on loopback.
|
# emulator uses adb reverse to expose the local Compose proxy on loopback.
|
||||||
WNH_DEBUG_BASE_URL=http://localhost:4010
|
WNH_DEBUG_BASE_URL=http://localhost:4010
|
||||||
|
# Release builds require a public HTTPS origin.
|
||||||
|
WNH_BASE_URL=https://whoneedhelp.imalto.site
|
||||||
# Public raster tile template used by MapLibre. Use a provider whose policy and
|
# Public raster tile template used by MapLibre. Use a provider whose policy and
|
||||||
# capacity match the deployment before a public launch.
|
# capacity match the deployment before a public launch.
|
||||||
MAP_TILE_URL=https://tile.openstreetmap.org/{z}/{x}/{y}.png
|
MAP_TILE_URL=https://tile.openstreetmap.org/{z}/{x}/{y}.png
|
||||||
# Compose derives PHX_URL_PORT from HTTP_PORT and uses HTTP for local development.
|
|
||||||
|
POSTGRES_DB=who_need_help
|
||||||
|
POSTGRES_USER=postgres
|
||||||
|
POSTGRES_PASSWORD=replace-with-a-local-or-deployment-secret
|
||||||
|
DATABASE_URL=ecto://postgres:replace-with-url-encoded-password@db/who_need_help
|
||||||
|
|
||||||
POOL_SIZE=10
|
POOL_SIZE=10
|
||||||
SECRET_KEY_BASE=generate-with-mix-phx-gen-secret
|
SECRET_KEY_BASE=generate-with-mix-phx-gen-secret
|
||||||
HANDOVER_SECRET=generate-an-independent-random-secret
|
HANDOVER_SECRET=generate-an-independent-random-secret
|
||||||
RELEASE_COOKIE=generate-an-independent-beam-cluster-cookie
|
RELEASE_COOKIE=generate-an-independent-beam-cluster-cookie
|
||||||
|
|
||||||
|
# Mailpit settings for local development. Replace these with the selected SMTP
|
||||||
|
# provider for public registration and magic links.
|
||||||
|
SMTP_RELAY=mailpit
|
||||||
|
SMTP_PORT=1025
|
||||||
|
SMTP_USERNAME=
|
||||||
|
SMTP_PASSWORD=
|
||||||
|
SMTP_AUTH=never
|
||||||
|
SMTP_TLS=never
|
||||||
|
SMTP_SSL=false
|
||||||
|
EMAIL_FROM_NAME=Who Need Help
|
||||||
|
EMAIL_FROM_ADDRESS=contact@example.com
|
||||||
|
|
||||||
CODEX_SESSION_ID=copy-the-main-local-codex-session-id
|
CODEX_SESSION_ID=copy-the-main-local-codex-session-id
|
||||||
# Optional shared PostgreSQL-backed policies. Keep {} until product thresholds are approved.
|
# Optional shared PostgreSQL-backed policies. Keep {} until product thresholds are approved.
|
||||||
# Shape: {"action_name":{"limit":POSITIVE_INTEGER,"window_seconds":POSITIVE_INTEGER}}
|
# Shape: {"action_name":{"limit":POSITIVE_INTEGER,"window_seconds":POSITIVE_INTEGER}}
|
||||||
|
|
|
||||||
35
compose.yaml
35
compose.yaml
|
|
@ -2,18 +2,25 @@ name: who_need_help
|
||||||
|
|
||||||
x-app-environment: &app-environment
|
x-app-environment: &app-environment
|
||||||
APP_ROLE: web
|
APP_ROLE: web
|
||||||
DATABASE_URL: ecto://postgres:postgres@db/who_need_help
|
DATABASE_URL: ${DATABASE_URL:?Set DATABASE_URL in .env}
|
||||||
SECRET_KEY_BASE: ${SECRET_KEY_BASE:-h0rJQH8xgH9vV1cS7gVw6M2oI0Kp3Lx9uA5fE4bD8nR7qT2yW6zC1sP9mN3kF5jH}
|
SECRET_KEY_BASE: ${SECRET_KEY_BASE:?Set SECRET_KEY_BASE in .env}
|
||||||
HANDOVER_SECRET: ${HANDOVER_SECRET:-local-compose-handover-secret-change-before-public-use}
|
HANDOVER_SECRET: ${HANDOVER_SECRET:?Set HANDOVER_SECRET in .env}
|
||||||
RELEASE_COOKIE: ${RELEASE_COOKIE:-local-compose-beam-cookie-change-before-public-use}
|
RELEASE_COOKIE: ${RELEASE_COOKIE:?Set RELEASE_COOKIE in .env}
|
||||||
DNS_CLUSTER_QUERY: web
|
DNS_CLUSTER_QUERY: web
|
||||||
PHX_HOST: ${PHX_HOST:-localhost}
|
PHX_HOST: ${PHX_HOST:?Set PHX_HOST in .env}
|
||||||
PHX_SCHEME: http
|
PHX_SCHEME: ${PHX_SCHEME:?Set PHX_SCHEME in .env}
|
||||||
PHX_URL_PORT: ${HTTP_PORT:-4010}
|
PHX_URL_PORT: ${PHX_URL_PORT:?Set PHX_URL_PORT in .env}
|
||||||
PORT: "4000"
|
PORT: "4000"
|
||||||
POOL_SIZE: ${POOL_SIZE:-10}
|
POOL_SIZE: ${POOL_SIZE:?Set POOL_SIZE in .env after measuring the target profile}
|
||||||
SMTP_RELAY: mailpit
|
SMTP_RELAY: ${SMTP_RELAY:?Set SMTP_RELAY in .env}
|
||||||
SMTP_PORT: "1025"
|
SMTP_PORT: ${SMTP_PORT:?Set SMTP_PORT in .env}
|
||||||
|
SMTP_USERNAME: ${SMTP_USERNAME:-}
|
||||||
|
SMTP_PASSWORD: ${SMTP_PASSWORD:-}
|
||||||
|
SMTP_AUTH: ${SMTP_AUTH:?Set SMTP_AUTH in .env}
|
||||||
|
SMTP_TLS: ${SMTP_TLS:?Set SMTP_TLS in .env}
|
||||||
|
SMTP_SSL: ${SMTP_SSL:?Set SMTP_SSL in .env}
|
||||||
|
EMAIL_FROM_NAME: ${EMAIL_FROM_NAME:?Set EMAIL_FROM_NAME in .env}
|
||||||
|
EMAIL_FROM_ADDRESS: ${EMAIL_FROM_ADDRESS:?Set EMAIL_FROM_ADDRESS in .env}
|
||||||
CODEX_SESSION_ID: ${CODEX_SESSION_ID:-not-configured}
|
CODEX_SESSION_ID: ${CODEX_SESSION_ID:-not-configured}
|
||||||
RATE_LIMIT_POLICIES_JSON: ${RATE_LIMIT_POLICIES_JSON:-{}}
|
RATE_LIMIT_POLICIES_JSON: ${RATE_LIMIT_POLICIES_JSON:-{}}
|
||||||
MAP_TILE_URL: ${MAP_TILE_URL:-https://tile.openstreetmap.org/{z}/{x}/{y}.png}
|
MAP_TILE_URL: ${MAP_TILE_URL:-https://tile.openstreetmap.org/{z}/{x}/{y}.png}
|
||||||
|
|
@ -36,11 +43,11 @@ services:
|
||||||
db:
|
db:
|
||||||
image: postgis/postgis:18-3.6-alpine
|
image: postgis/postgis:18-3.6-alpine
|
||||||
environment:
|
environment:
|
||||||
POSTGRES_DB: who_need_help
|
POSTGRES_DB: ${POSTGRES_DB:?Set POSTGRES_DB in .env}
|
||||||
POSTGRES_USER: postgres
|
POSTGRES_USER: ${POSTGRES_USER:?Set POSTGRES_USER in .env}
|
||||||
POSTGRES_PASSWORD: postgres
|
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env}
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "pg_isready -U postgres -d who_need_help"]
|
test: ["CMD-SHELL", "pg_isready -U $$POSTGRES_USER -d $$POSTGRES_DB"]
|
||||||
interval: 3s
|
interval: 3s
|
||||||
timeout: 3s
|
timeout: 3s
|
||||||
retries: 20
|
retries: 20
|
||||||
|
|
|
||||||
|
|
@ -7,6 +7,10 @@
|
||||||
# General application configuration
|
# General application configuration
|
||||||
import Config
|
import Config
|
||||||
|
|
||||||
|
config :who_need_help, :mailer_from,
|
||||||
|
name: "Who Need Help",
|
||||||
|
address: "contact@example.com"
|
||||||
|
|
||||||
config :who_need_help, :scopes,
|
config :who_need_help, :scopes,
|
||||||
user: [
|
user: [
|
||||||
default: true,
|
default: true,
|
||||||
|
|
|
||||||
|
|
@ -114,15 +114,58 @@ if config_env() == :prod do
|
||||||
default_url_port = if scheme == "https", do: "443", else: "80"
|
default_url_port = if scheme == "https", do: "443", else: "80"
|
||||||
url_port = String.to_integer(System.get_env("PHX_URL_PORT", default_url_port))
|
url_port = String.to_integer(System.get_env("PHX_URL_PORT", default_url_port))
|
||||||
|
|
||||||
config :who_need_help, :handover_secret, handover_secret
|
smtp_auth =
|
||||||
|
case System.get_env("SMTP_AUTH", "never") do
|
||||||
|
"always" -> :always
|
||||||
|
"never" -> :never
|
||||||
|
"if_available" -> :if_available
|
||||||
|
other -> raise "SMTP_AUTH must be always, never, or if_available; got #{inspect(other)}"
|
||||||
|
end
|
||||||
|
|
||||||
config :who_need_help, WhoNeedHelp.Mailer,
|
smtp_tls =
|
||||||
|
case System.get_env("SMTP_TLS", "never") do
|
||||||
|
"always" -> :always
|
||||||
|
"never" -> :never
|
||||||
|
"if_available" -> :if_available
|
||||||
|
other -> raise "SMTP_TLS must be always, never, or if_available; got #{inspect(other)}"
|
||||||
|
end
|
||||||
|
|
||||||
|
smtp_ssl =
|
||||||
|
case System.get_env("SMTP_SSL", "false") do
|
||||||
|
value when value in ["true", "1"] -> true
|
||||||
|
value when value in ["false", "0"] -> false
|
||||||
|
other -> raise "SMTP_SSL must be true, false, 1, or 0; got #{inspect(other)}"
|
||||||
|
end
|
||||||
|
|
||||||
|
smtp_config =
|
||||||
|
[
|
||||||
adapter: Swoosh.Adapters.SMTP,
|
adapter: Swoosh.Adapters.SMTP,
|
||||||
relay: System.get_env("SMTP_RELAY", "mailpit"),
|
relay: System.get_env("SMTP_RELAY", "mailpit"),
|
||||||
port: String.to_integer(System.get_env("SMTP_PORT", "1025")),
|
port: String.to_integer(System.get_env("SMTP_PORT", "1025")),
|
||||||
auth: :never,
|
auth: smtp_auth,
|
||||||
tls: :never,
|
tls: smtp_tls,
|
||||||
ssl: false
|
ssl: smtp_ssl
|
||||||
|
]
|
||||||
|
|> then(fn config ->
|
||||||
|
case System.get_env("SMTP_USERNAME") do
|
||||||
|
value when is_binary(value) and value != "" -> Keyword.put(config, :username, value)
|
||||||
|
_ -> config
|
||||||
|
end
|
||||||
|
end)
|
||||||
|
|> then(fn config ->
|
||||||
|
case System.get_env("SMTP_PASSWORD") do
|
||||||
|
value when is_binary(value) and value != "" -> Keyword.put(config, :password, value)
|
||||||
|
_ -> config
|
||||||
|
end
|
||||||
|
end)
|
||||||
|
|
||||||
|
config :who_need_help, :handover_secret, handover_secret
|
||||||
|
|
||||||
|
config :who_need_help, :mailer_from,
|
||||||
|
name: System.get_env("EMAIL_FROM_NAME", "Who Need Help"),
|
||||||
|
address: System.get_env("EMAIL_FROM_ADDRESS", "contact@example.com")
|
||||||
|
|
||||||
|
config :who_need_help, WhoNeedHelp.Mailer, smtp_config
|
||||||
|
|
||||||
config :who_need_help, WhoNeedHelpWeb.Endpoint,
|
config :who_need_help, WhoNeedHelpWeb.Endpoint,
|
||||||
url: [host: host, port: url_port, scheme: scheme],
|
url: [host: host, port: url_port, scheme: scheme],
|
||||||
|
|
|
||||||
|
|
@ -6,10 +6,12 @@ defmodule WhoNeedHelp.Accounts.UserNotifier do
|
||||||
|
|
||||||
# Delivers the email using the application mailer.
|
# Delivers the email using the application mailer.
|
||||||
defp deliver(recipient, subject, body) do
|
defp deliver(recipient, subject, body) do
|
||||||
|
from = Application.fetch_env!(:who_need_help, :mailer_from)
|
||||||
|
|
||||||
email =
|
email =
|
||||||
new()
|
new()
|
||||||
|> to(recipient)
|
|> to(recipient)
|
||||||
|> from({"WhoNeedHelp", "contact@example.com"})
|
|> from({from[:name], from[:address]})
|
||||||
|> subject(subject)
|
|> subject(subject)
|
||||||
|> text_body(body)
|
|> text_body(body)
|
||||||
|
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user