Files
jorgecuadros-platform/deploy/jorgecuadros-app.env.example
T
rmancinasandClaude Opus 5 a491ef3eed
Build and Push Images / Build jorgecuadros-web (push) Successful in 2m32s
Build and Push Images / Build jorgecuadros-api (push) Successful in 3m28s
feat(notificaciones): edit summary recipients in the UI
NOTIFICATION_ADMIN_EMAILS made "add Beto to the summaries" a redeploy —
the wrong unit of work for a list that changes when office staff change.

Adds `app_settings`, a key/value table for the configuration staff must
be able to change without a deploy, and `SettingsService`, which resolves
every key db -> env -> default and reports which of the three a value
came from. That ladder is what makes the move safe: a deployment behaves
exactly as before until somebody saves in the UI, and the screen can say
"this is still coming from the deployment" rather than implying somebody
chose it.

- new ability `setting:manage` (ADMIN) — deliberately above
  `notification:send`, since redirecting the audit summaries is how
  someone would quietly stop them being read
- GET/PUT /notifications/settings/admin-emails; read is open to any
  logged-in user so the UI can display the list, write is gated
- resolved per job, not cached at boot, or we would reintroduce exactly
  the restart-to-apply behaviour being removed
- a saved empty list means "nobody" and does NOT fall through to the env,
  or clearing the field would keep mailing the people just removed

Credentials stay in env — see the model doc for where the line is drawn.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-02 11:58:42 -07:00

64 lines
2.9 KiB
Bash

# Stack env for deploy/jorgecuadros-app.stack.yml (PROD).
# Paste these into the Portainer stack's "Environment variables" at deploy time.
# Do NOT commit real secrets — this file is a template only.
#
# HOST below = the swarm host the db/minio/app stacks publish on (cubex).
# Which built image tag to run. latest = default-branch build; or pin sha-<x> / vX.Y.Z.
APP_TAG=latest
# --- Public URLs (what the end user's BROWSER hits) ---------------------------
# API_ORIGIN is injected into the web app at runtime and used for browser fetches
# + document download links, so it must be browser-reachable (not swarm-internal).
# WEB_ORIGIN is the web app's own public origin; the API allows it via CORS.
API_ORIGIN=http://192.168.4.212:3001
WEB_ORIGIN=http://192.168.4.212:3000
# Published ports on the swarm host.
API_PORT=3001
WEB_PORT=3000
# --- Database (points at the jorgecuadros-prod-db stack) ----------------------
# prod db publishes 3306 on the host (see deploy/jorgecuadros-db.stack.yml).
DATABASE_URL=mysql://jorgecuadros:CHANGE_ME@192.168.4.212:3306/jorgecuadros
# --- Auth --------------------------------------------------------------------
# 64-hex random. Generate: openssl rand -hex 32
SESSION_SECRET=CHANGE_ME
# --- Object storage (points at the jorgecuadros-prod-minio stack) -------------
# Server-side only; prod minio API publishes 9000 on the host.
S3_ENDPOINT=http://192.168.4.212:9000
S3_BUCKET=jorgecuadros-documents
MINIO_ROOT_USER=jc_minio
MINIO_ROOT_PASSWORD=CHANGE_ME
# --- Outbound mail (Amazon SES) ----------------------------------------------
# NOTE: for the Portainer-deployed stacks these do NOT come from a file on the
# host — the deploy workflows build the stack env from Gitea repo secrets (see
# the `env_data` blocks in .gitea/workflows/deploy*.yml). This file documents
# the full variable set and is what you fill in for a hand-run stack.
#
# Either way they are RUNTIME config, read at container boot
# (apps/api/src/mail/mail.service.ts) — never baked into the image.
#
# The production image sets NODE_ENV=production, which turns OFF the stdout dev
# fallback. Leaving these blank does not silently swallow mail — every send
# fails with "El envío de correo no está configurado.", and the failure is
# recorded in the notification log. Fill them in before enabling any envío.
#
# SES_FROM must be a verified SES sending identity.
SES_REGION=us-west-2
SES_FROM=mail@jorgecuadros.com
SES_FROM_NAME=Information Server
SES_ACCESS_KEY=
SES_SECRET_KEY=
# Optional — only needed to publish bounce/complaint events.
SES_CONFIGURATION_SET=
# Recipients of the per-job summary email. NOW EDITABLE IN THE UI
# (/notificaciones > Servicios > "Destinatarios del resumen", ADMIN only), so
# this is only the fallback for a deployment where nobody has set it there.
# A saved value takes precedence and this var is ignored from then on.
NOTIFICATION_ADMIN_EMAILS=rmancinas@freakma.net,mpulido@freakma.net