* HH-439: harden production artifact pipeline * fix(HH-439): address production compose review * fix(HH-439): preserve previous JWT secrets in production --------- Co-authored-by: Rogee <rogee@ipao.vip>
39 lines
831 B
YAML
39 lines
831 B
YAML
# GoChat production overrides. Secrets and public origins must come from the environment.
|
|
server:
|
|
mode: "release"
|
|
cors:
|
|
allowed_origins: ["https://CHANGE_ME.example.com"]
|
|
allow_credentials: true
|
|
|
|
database:
|
|
dsn: "postgres://gochat:CHANGE_ME@postgres:5432/gochat_production?sslmode=disable"
|
|
run_migrations: true
|
|
migrations_path: "/app/migrations"
|
|
|
|
redis:
|
|
dsn: "redis://:CHANGE_ME@redis:6379"
|
|
|
|
jwt:
|
|
secret: "CHANGE_ME"
|
|
allow_insecure_header_auth: false
|
|
|
|
search:
|
|
engine: "meilisearch"
|
|
host: "http://meilisearch:7700"
|
|
api_key: "CHANGE_ME"
|
|
|
|
log:
|
|
level: "info"
|
|
format: "json"
|
|
|
|
worker:
|
|
concurrency: 10
|
|
redis_stream_prefix: "gochat:jobs"
|
|
redis_consumer_group: "gochat-workers"
|
|
redis_block_timeout_s: 5
|
|
redis_sweep_interval_s: 30
|
|
|
|
storage:
|
|
provider: "local"
|
|
local_path: "/app/storage/uploads"
|