image: repository: who-need-help tag: local pullPolicy: IfNotPresent web: replicas: 2 poolSize: "4" worker: replicas: 2 poolSize: "2" maintenanceConcurrency: "2" pushConcurrency: "1" mailConcurrency: "1" service: type: ClusterIP port: 80 nodePort: null app: host: localhost scheme: https urlPort: "443" # Optional comma-separated HTTP(S) origins accepted by Phoenix for # LiveView/WebSocket connections. Leave empty to use the public URL above. checkOrigins: "" port: "4000" migratePoolSize: "2" # OTP otherwise derives this from the container nofile ulimit. Some # Kubernetes runtimes expose a value so large that each BEAM instance # preallocates a multi-gigabyte port table. erlangPortLimit: 65536 clusterInterface: eth0 codexSessionId: not-configured # Initial pilot product policy. Use exactly "{}" only for an isolated test # release that intentionally disables every shared counter. rateLimitPoliciesJson: '{"registration_email":{"limit":4,"window_seconds":3600},"registration_ip":{"limit":120,"window_seconds":3600},"magic_link_email":{"limit":4,"window_seconds":3600},"magic_link_ip":{"limit":120,"window_seconds":3600},"password_login_email":{"limit":10,"window_seconds":900},"password_login_ip":{"limit":300,"window_seconds":900},"email_change_email":{"limit":3,"window_seconds":86400},"email_change_ip":{"limit":60,"window_seconds":3600},"support_request":{"limit":5,"window_seconds":86400},"support_request_ip":{"limit":120,"window_seconds":3600},"content_removal_notice":{"limit":20,"window_seconds":86400},"content_removal_notice_ip":{"limit":120,"window_seconds":3600}}' publicContactVerificationMaxAgeSeconds: "86400" publicCaseAccessMaxAgeSeconds: "31536000" mapTileUrl: https://tile.openstreetmap.org/{z}/{x}/{y}.png emailDeliveryProvider: smtp smtpRelay: mailpit smtpPort: "1025" # Required. The Secret must contain DATABASE_URL, SECRET_KEY_BASE, # HANDOVER_SECRET, RELEASE_COOKIE, and METRICS_TOKEN. It may also contain both # GITHUB_OAUTH_CLIENT_ID and GITHUB_OAUTH_CLIENT_SECRET to enable verified # GitHub linking, and both GOOGLE_OAUTH_CLIENT_ID and # GOOGLE_OAUTH_CLIENT_SECRET to enable Google registration/sign-in. Optional # SUPPORT_INBOX_ADDRESS enables metadata-only operator alerts and Reply-To. # SUPPORT_INBOUND_RECIPIENT and SUPPORT_INBOUND_WEBHOOK_TOKEN optionally enable # authenticated inbound support-email ingestion; both keys must be present. # SMTP provider credentials can be kept in this Secret. # Push is # opt-in: provide PUSH_HTTP_ENDPOINT, # PUSH_HTTP_BEARER_TOKEN, PUSH_HTTP_MAX_ATTEMPTS, # PUSH_HTTP_RECEIVE_TIMEOUT_MS, PUSH_HTTP_CONNECT_TIMEOUT_MS, and # PUSH_HTTP_RETRY_DELAY_MS as one complete set. existingSecret: "" ingress: enabled: false className: "" annotations: {} hosts: - host: who-need-help.local paths: - path: / pathType: Prefix tls: [] networkPolicy: enabled: true podAnnotations: {} podLabels: {} nodeSelector: {} tolerations: [] affinity: {}