Something went wrong. Try again.
mirror your GitHub repos to tangled.org automatically synchub.to
mirror sync tangled github git
Something went wrong. Try again.
synchub.to .env.example
4.6 kB · 87 lines
at main
12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788# Copy to `.env` and fill in.# ---------------------------------------------------------------------------# Public URL the app is reachable at. For local dev this is the loopback host# (note: 127.0.0.1, not localhost — required by the AT Proto OAuth spec for# the synthetic dev `client_id`).# ---------------------------------------------------------------------------NUXT_PUBLIC_URL=http://127.0.0.1:3000# ---------------------------------------------------------------------------# Database. Get a connection string from https://neon.tech (free tier is fine).# Copy the "pooled" connection string for serverless workloads.# ---------------------------------------------------------------------------NUXT_DATABASE_URL=postgres://user:password@host.neon.tech/dbname?sslmode=require# ---------------------------------------------------------------------------# AT Proto OAuth client signing key (ES256 private JWK).## Generate with: pnpm gen:jwk# Paste the full JSON object on a single line below.# ---------------------------------------------------------------------------NUXT_ATPROTO_PRIVATE_JWK={"kty":"EC","kid":"...","crv":"P-256","x":"...","y":"...","d":"..."}# ---------------------------------------------------------------------------# Application encryption key (KEK) — wraps SSH private keys and AT Proto# session blobs at rest. Base64-encoded 32 bytes.## Generate with: pnpm gen:encryption-key# ---------------------------------------------------------------------------NUXT_ENCRYPTION_KEY=<base64-encoded 32 bytes># ---------------------------------------------------------------------------# Dashboard session password. Used by h3's `useSession` to seal the# `synchub-session` cookie. 32+ characters of entropy.## Generate with: pnpm gen:encryption-key# (any sufficiently long random string works; the base64 output is convenient).# ---------------------------------------------------------------------------NUXT_SESSION_PASSWORD=<32+ char random string># ---------------------------------------------------------------------------# GitHub App credentials. If you are unsure where these values are in GitHub,# see "Run it locally" in README.md for the full GitHub App setup walkthrough.# After creating the App at https://github.com/settings/apps/new, copy:# - The numeric App ID (top of the App settings page).# - The webhook secret you set during creation.# - A generated private key (.pem). On Vercel, store with literal "\n" in# place of newlines; locally, keep the real newlines.# - The Client ID and a generated client secret ("Client secrets" section).# These drive the user-to-server OAuth that proves a connecting user# actually administers the installation they're binding a tangled handle# to. Distinct from the private key above. Required for the /connect flow.# ---------------------------------------------------------------------------NUXT_GITHUB_APP_ID=<numeric app id>NUXT_GITHUB_WEBHOOK_SECRET=<webhook secret>NUXT_GITHUB_APP_CLIENT_ID=<github app client id, e.g. Iv1.abc123>NUXT_GITHUB_APP_CLIENT_SECRET=<github app client secret>NUXT_GITHUB_APP_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----...-----END RSA PRIVATE KEY-----"# URL for installing the GitHub App. Used to redirect returning sign-ins that# have an authenticated tangled identity but no GitHub install bound yet.# Find it on your GitHub App's "Public page" link, in the form# `https://github.com/apps/<app-slug>/installations/new`.NUXT_GITHUB_APP_INSTALL_URL=https://github.com/apps/synchub-to/installations/new# ---------------------------------------------------------------------------# Cron secret — protects the worker tick endpoint (`/api/jobs/run`) from# unauthenticated callers. Vercel auto-injects this as the `Authorization:# Bearer` header on cron invocations, so the name must be exactly CRON_SECRET# (not NUXT_-prefixed). Locally, `pnpm jobs:tick` reads the same var.## Generate with: pnpm gen:cron-secret# ---------------------------------------------------------------------------CRON_SECRET=<base64url-encoded 32 bytes># Optional: per-invocation worker time budget in milliseconds.# Default 270_000 (just under the 300s Vercel maxDuration). Set lower in dev# so `pnpm jobs:tick` returns sooner when the queue is empty.# NUXT_WORKER_BUDGET_MS=5000# Optional: how many jobs the worker runs concurrently per invocation.# Default 6. Jobs are network-bound (SSH to the knot, HTTPS to GitHub), so# concurrency raises throughput without CPU contention.# NUXT_WORKER_CONCURRENCY=6