feat(deploy): production deployment setup and fixes
- Debian-based api image (bookworm-slim), docker/debian mirrors, prisma binaryTargets for openssl 3.0 - nginx: admin SPA under /admin, TLS via acme.sh (ZeroSSL) + auto-renewal cron, http->https redirect - prisma: add origin_goods.delisted migration, sync missing schema (good_image/tag_font_color/good_tags), fix users.createdAt Timestamptz - api: CORS wildcard reflection, helmet CORP cross-origin, price backfill in persistProductDetail, categoryIcon ancestor fallback, mediaByColor per-color gallery in public goods detail - admin: /admin base path (vite + router) - import-data.mjs: udt_name casting, serial sequence advance fix
This commit is contained in:
+20
-20
@@ -1,20 +1,20 @@
|
||||
# Prisma connection string (PostgreSQL)
|
||||
DATABASE_URL=postgresql://postgres:CHANGE_ME@localhost:5432/inkreach-official-website
|
||||
|
||||
# JWT signing secret: generate with `node -e "console.log(require('crypto').randomBytes(48).toString('hex'))"`
|
||||
# Must be at least 32 characters.
|
||||
JWT_SECRET=CHANGE_ME_TO_A_STRONG_RANDOM_SECRET
|
||||
|
||||
# Access token lifetime (e.g. 30m, 12h); short-lived, rotated via /auth/refresh
|
||||
TOKEN_EXPIRES_IN=30m
|
||||
|
||||
# Refresh token lifetime (HttpOnly cookie)
|
||||
REFRESH_TOKEN_EXPIRES_IN=7d
|
||||
|
||||
# Comma-separated list of allowed CORS origins (leave empty to disable CORS)
|
||||
CORS_ORIGINS=http://localhost:5173
|
||||
|
||||
# Global rate limit per minute (per IP)
|
||||
THROTTLE_LIMIT=120
|
||||
|
||||
PORT=3001
|
||||
# Prisma connection string (PostgreSQL)
|
||||
DATABASE_URL=postgresql://postgres:CHANGE_ME@localhost:5432/inkreach-official-website
|
||||
|
||||
# JWT signing secret: generate with `node -e "console.log(require('crypto').randomBytes(48).toString('hex'))"`
|
||||
# Must be at least 32 characters.
|
||||
JWT_SECRET=CHANGE_ME_TO_A_STRONG_RANDOM_SECRET
|
||||
|
||||
# Access token lifetime (e.g. 30m, 12h); short-lived, rotated via /auth/refresh
|
||||
TOKEN_EXPIRES_IN=30m
|
||||
|
||||
# Refresh token lifetime (HttpOnly cookie)
|
||||
REFRESH_TOKEN_EXPIRES_IN=7d
|
||||
|
||||
# Comma-separated list of allowed CORS origins (leave empty to disable CORS)
|
||||
CORS_ORIGINS=http://localhost:5173
|
||||
|
||||
# Global rate limit per minute (per IP)
|
||||
THROTTLE_LIMIT=120
|
||||
|
||||
PORT=3001
|
||||
|
||||
Reference in New Issue
Block a user