# Local docker-compose overrides. Copy to .env (gitignored) for `docker compose # up` / `make up` on a laptop: cp .env.example .env # # Compose auto-reads a repo-root .env for ${VAR} interpolation in # docker-compose.yml. On the fleet (dev/beta/prod), these values live in each # environment's own rendered env file instead (/etc/thermograph.env, # /etc/thermograph-beta.env — see deploy/secrets/README.md), so this file is # only for a local, unmanaged run. # Database password. Compose uses it to initialize the postgres container AND to # build the app's THERMOGRAPH_DATABASE_URL. Change it before first `up`. POSTGRES_PASSWORD=change-me # OPTIONAL. Shared secret between the daemon service (Discord gateway + job # timers) and the backend's /internal/* routes. # # Leave it empty and both ends DERIVE the same token from THERMOGRAPH_AUTH_SECRET # (HMAC-SHA256 under a fixed label), which every environment already provisions — # so the daemon needs no new vault entry and no operator step. Set it only to # override that, e.g. to rotate this surface independently of the auth secret: # openssl rand -hex 32 # # With neither this nor THERMOGRAPH_AUTH_SECRET set, both ends fail closed: the # backend disables the internal routes and the daemon refuses to start. Never # routed publicly — Caddy only forwards /api/*, /digest and # /discord/interactions to the backend. THERMOGRAPH_INTERNAL_TOKEN= # --- Everything below is optional -- docker-compose.yml already defaults each # --- of these, so a plain `make up` works with none of it set. Uncomment to # --- override. # TimescaleDB image tag. Defaults to the floating latest-pg18 tag. Pin it to an # exact minor (e.g. 2.17.2-pg18) before any host of this stack could ever # replicate with another -- see docker-compose.yml's db service comment. # TIMESCALEDB_TAG=latest-pg18 # Postgres sizing. Only meaningful for an environment that runs its OWN db # service — dev's compose stack (this file) and prod's Swarm stack, which # sizes the ONE shared TimescaleDB instance on vps2 (see # deploy/secrets/prod.yaml, currently DB_MEMORY=16g). Beta shares that same # instance rather than running a second one, so a DB_MEMORY/DB_CPUS value in # beta's own vault file no longer sizes anything — don't be misled by its # presence there. Local/dev default to 8g / 2 CPUs. # DB_MEMORY=8g # DB_CPUS=2 # Backend uvicorn worker count and CPU cap. Terraform raises these on bigger # hosts; defaults keep a plain `docker compose up` identical to before. # WORKERS=4 # APP_CPUS=4 # Frontend CPU cap. # FRONTEND_CPUS=2 # Registry + per-service image path/tag. Local dev normally builds each image # in its own app repo (thermograph-backend / thermograph-frontend) tagged # :local, which is the default here -- only set these to pull a specific # published build instead of building locally. # REGISTRY_HOST=git.thermograph.org # BACKEND_IMAGE_PATH=admin_emi/thermograph-backend/app # BACKEND_IMAGE_TAG=local # FRONTEND_IMAGE_PATH=admin_emi/thermograph-frontend/app # FRONTEND_IMAGE_TAG=local