Files
gongxue-base/deploy.env.example
2026-07-12 19:26:57 +08:00

94 lines
3.7 KiB
Plaintext

# Copy this file to /opt/tiku-saas/shared/deploy.env on the server.
# Do not commit the real deploy.env.
APP_NAME=tiku-supabase
REPO_URL=https://git.gongxue100.com/chenhaogxjy/tiku-supabase.git
BRANCH=main
DEPLOY_ROOT=/opt/tiku-saas
KEEP_RELEASES=5
# Private Gitea repository access.
# Prefer a short-lived token with read-only repository scope.
# Do not put the token in REPO_URL.
# GIT_USERNAME=chenhaogxjy
# GITEA_TOKEN=replace-with-rotated-readonly-token
# Install/build/check gates.
NPM_INSTALL_COMMAND="npm ci --workspaces --include-workspace-root --include=dev"
# Audit metadata must come from an npm registry that implements the audit API.
# Keep this on the official registry even if package downloads use a mirror.
NPM_AUDIT_REGISTRY=https://registry.npmjs.org/
RUN_CHECKS=true
CHECK_COMMANDS="npm run check:api
npm run check:worker
npm run check:taro"
RUN_API_BUILD=true
RUN_WORKER_BUILD=true
RUN_TARO_H5_BUILD=true
RUN_SECURITY_REPO_SCAN=true
RUN_RUNTIME_AUDIT=true
# This audit covers dependencies that ship in the Taro H5/miniapp bundle.
RUN_TARO_SUPPLY_CHAIN_AUDIT=true
# Production gates.
# auto runs readiness:production when NODE_ENV=production.
NODE_ENV=production
RUN_PRODUCTION_READINESS=auto
RUN_DB_READINESS=true
# Database migrations are intentionally opt-in. Enable only after backup and rehearsal.
# When enabled, the deploy script runs readiness:production:db again after db push
# and before launch:gate; production refuses to disable that post-migration check.
RUN_DB_MIGRATIONS=false
# Do not assign this in the file; inject DATABASE_MIGRATION_URL for the standard
# migration role from a secret manager immediately before deployment.
DB_MIGRATION_COMMAND='supabase db push --db-url "$DATABASE_MIGRATION_URL"'
# H5 runtime configs stay in shared/ and are symlinked into each release dist.
# Production deployment blocks until these files exist and pass strict validation.
STRICT_H5_RUNTIME_CONFIG=true
RUN_H5_SMOKE=true
H5_STUDENT_RUNTIME_CONFIG=/opt/tiku-saas/shared/h5-student.runtime-config.json
H5_TENANT_RUNTIME_CONFIG=/opt/tiku-saas/shared/h5-tenant-admin.runtime-config.json
H5_PLATFORM_RUNTIME_CONFIG=/opt/tiku-saas/shared/h5-platform-admin.runtime-config.json
# Nginx serves /srv/tiku-saas/www/{student,tenant-admin,platform-admin}.
# The deployer stages versioned Web roots beside this path and atomically switches
# /srv/tiku-saas/www after all candidate checks pass.
WWW_ROOT=/srv/tiku-saas/www
WWW_RELEASES_DIR=/srv/tiku-saas/www-releases
# The bundled systemd units run from /opt/tiku-saas/repo. The deployer explicitly
# synchronizes the selected current release into this runtime directory before restart.
SERVICE_REPO_DIR=/opt/tiku-saas/repo
SYNC_SERVICE_REPO=true
# Real production evidence is generated out-of-band and stays in shared/, never in Git.
RUN_LAUNCH_GATE=true
PRODUCTION_LAUNCH_EVIDENCE=/opt/tiku-saas/shared/production-launch-evidence.json
# Production defaults are fail-closed: a real restart strategy and healthcheck are required.
SERVICE_MODE=systemd
SYSTEMD_UNITS="tiku-api.service tiku-workers.target"
# systemd example:
# SERVICE_MODE=systemd
# SYSTEMD_UNITS="tiku-api.service tiku-workers.target"
# pm2 example:
# SERVICE_MODE=pm2
# PM2_ECOSYSTEM=/opt/tiku-saas/current/ecosystem.config.cjs
# PM2_PROCESS_NAMES="tiku-api tiku-worker"
# docker compose example:
# SERVICE_MODE=compose
# COMPOSE_FILE=/opt/tiku-saas/current/docker-compose.api.yml
# Fully custom restart hook. Runs after current symlink switches.
# RESTART_COMMAND='systemctl restart tiku-api.service tiku-workers.target'
# Production refuses to report success without this healthcheck.
HEALTHCHECK_URL=http://127.0.0.1:8787/health
HEALTHCHECK_TIMEOUT_SECONDS=60
HEALTHCHECK_INTERVAL_SECONDS=2