# Sea Haven Industries — shoc-backend required configuration # # This file documents the secrets that used to be hardcoded in appsettings*.json # and source files. Copy the values into one of the supported configuration sources; # do NOT commit real values. # # .NET resolves configuration in this order (later wins): # 1. appsettings.json / appsettings.{Environment}.json (committed — placeholders only) # 2. User Secrets (local dev): dotnet user-secrets set "Key:Sub" "value" # 3. Environment variables (use "__" as the section separator) # # Environment-variable form is shown below. In AWS Elastic Beanstalk these map to # environment properties; locally you can export them or use dotnet user-secrets. # # AWS credentials for the S3 client are NOT listed here on purpose: UploadFileHp now # uses the AWS SDK default credential chain (env AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY, # the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod. # --- Sentry error and transaction monitoring --- # The DSN is public ingestion configuration, not a secret. Leave it blank locally # to keep telemetry inactive. AWS deployments receive SENTRY_DSN and # SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by # Terraform: dev is labeled "development", staging "staging". Future production # wiring will pass the production DSN through the same sentry_dsn module variable. SENTRY_DSN= SENTRY_ENVIRONMENT=development # --- SQL Server connection string (Api.SeaHavenIndustries + SeaHavenIndustries) --- ConnectionStrings__DefaultConnection=Server=;Initial Catalog=;User Id=;Password=;MultipleActiveResultSets=true # --- SendGrid (transactional email) --- SendGrid__ApiKey=SG.xxxxxxxxxxxxxxxxxxxxxx # --- JWT signing secret (Api.SeaHavenIndustries) --- JWT__Secret= # --- Google Maps / Places API key (SeaHavenIndustries Blazor app) --- GoogleMaps__ApiKey=AIzaSyXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX # --- AWS S3 (optional; prefer instance role / SSO over static keys) --- # AWS_ACCESS_KEY_ID= # AWS_SECRET_ACCESS_KEY= # AWS_REGION=us-east-2 # --- Work Order ingest (Lambda cutover) --- # Leave Enabled=false until ApiKey is a real secret (min 32 chars). Do not use appsettings placeholders. WorkOrderIngest__Enabled=false WorkOrderIngest__ApiKey= # --- Dynamo sync bridge (keep false after Lambda cutover; avoid dual-run with ingest) --- Sync__Enabled=true # --- Legacy endpoint deprecation headers --- LegacyEndpoints__DeprecationEnabled=false LegacyEndpoints__SunsetDate=2026-12-31