# --------------------------------------------------------------------------- # apps/api — copy to .env and adjust. NEVER commit the real .env. # Values below match the services defined in the root docker-compose.yml. # --------------------------------------------------------------------------- NODE_ENV=development PORT=4000 API_GLOBAL_PREFIX=api APP_VERSION=0.1.0 # Comma-separated list of allowed browser origins. CORS_ORIGINS=http://localhost:3000,http://localhost:3001 # --- PostgreSQL ------------------------------------------------------------- DATABASE_URL=postgresql://sport:sport@localhost:5433/sport_store?schema=public # --- Redis ------------------------------------------------------------------ REDIS_URL=redis://localhost:6380 REDIS_KEY_PREFIX=sport: # --- Auth ------------------------------------------------------------------- # Generate with: openssl rand -base64 48 # Access and refresh secrets MUST be different values. JWT_ACCESS_SECRET=dev-only-access-secret-change-me-0000000000 JWT_REFRESH_SECRET=dev-only-refresh-secret-change-me-000000000 JWT_ACCESS_TTL=15m JWT_REFRESH_TTL=30d JWT_ISSUER=sport-store # --- Object storage (S3 compatible: Cloudflare R2 in prod, MinIO locally) ---- STORAGE_ENDPOINT=http://localhost:9000 STORAGE_REGION=auto STORAGE_BUCKET=sport-media STORAGE_ACCESS_KEY_ID=sportminio STORAGE_SECRET_ACCESS_KEY=sportminio # Required by MinIO, must be false for Cloudflare R2. STORAGE_FORCE_PATH_STYLE=true # Public base URL used to build media URLs (CDN domain in production). STORAGE_PUBLIC_URL=http://localhost:9000/sport-media # --- Rate limiting ---------------------------------------------------------- RATE_LIMIT_TTL_SECONDS=60 RATE_LIMIT_MAX=120 # --- Observability ---------------------------------------------------------- LOG_LEVEL=debug LOG_PRETTY=true