# Copy to `.env` before `docker compose up`. Compose reads every credential # from here and has no defaults of its own — it refuses to start naming the # variable it wanted rather than falling back to a value that would be public. # The local database. Throwaway values are fine; these three are what compose # creates the container with and what it builds DATABASE_URL from. POSTGRES_USER=postgres POSTGRES_PASSWORD=postgres POSTGRES_DB=nestri # For anything run outside a container — `bun dev`, `bun run db:migrate`. DATABASE_URL=postgres://postgres:postgres@localhost:5432/nestri # Isolated database for tests. Required by DB-backed tests; unset tests fail. TEST_DATABASE_URL= # The issuer's public URL — the address a token's `iss` claim will carry. AUTH_ISSUER_URL=http://localhost:1337 # Where to reach the issuer, if that is not where it lives. Unset unless the # public name is unroutable from where the API runs; docker compose sets it. AUTH_INTERNAL_URL= # Turns any request carrying it into an operator, so generate one rather than # typing something: `openssl rand -hex 32`. ADMIN_SHARED_SECRET= # Mail delivery. All three together, or none of them plus EMAIL_DEV_LOG=true, # which prints sign-in codes to the log instead of sending them. Printing them # is a local-development convenience and nothing else. EMAIL_SEND_URL= EMAIL_API_KEY= EMAIL_FROM= EMAIL_DEV_LOG=true