mirror of
https://github.com/Sea-Haven-Industries/shoc-backend.git
synced 2026-09-30 17:43:12 +00:00
The org PR template pre-filled Summary / Validation / Tests / Notes here while REVIEW_AND_PR_FRAMEWORK.md section 8 prescribes Summary / Changes and value / Ticket. A repo template now overrides the org one, and the framework notes the divergence from the org pr-policy workflow, which is not wired in. README.md orients a reader: environments, architecture in one line, project map, local commands, the governance gate, deployment, and a documentation map. Cleanup: TODO.md is removed because Jira owns work status and its items are stale or done. BACKEND_ARCHITECTURE.md is removed as superseded; the two references now point at git history. .env.example loses its BOM and mojibake dashes. .gitattributes keeps its one active rule.
55 lines
2.6 KiB
Text
55 lines
2.6 KiB
Text
# Sea Haven Industries — shoc-backend required configuration
|
|
#
|
|
# This file documents the secrets that used to be hardcoded in appsettings*.json
|
|
# and source files. Copy the values into one of the supported configuration sources;
|
|
# do NOT commit real values.
|
|
#
|
|
# .NET resolves configuration in this order (later wins):
|
|
# 1. appsettings.json / appsettings.{Environment}.json (committed — placeholders only)
|
|
# 2. User Secrets (local dev): dotnet user-secrets set "Key:Sub" "value"
|
|
# 3. Environment variables (use "__" as the section separator)
|
|
#
|
|
# Environment-variable form is shown below. In AWS Elastic Beanstalk these map to
|
|
# environment properties; locally you can export them or use dotnet user-secrets.
|
|
#
|
|
# AWS credentials for the S3 client are NOT listed here on purpose: UploadFileHp now
|
|
# uses the AWS SDK default credential chain (env AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY,
|
|
# the shared profile/SSO, or the EC2/ECS instance role). Prefer an instance role in prod.
|
|
|
|
# --- Sentry error and transaction monitoring ---
|
|
# The DSN is public ingestion configuration, not a secret. Leave it blank locally
|
|
# to keep telemetry inactive. AWS deployments receive SENTRY_DSN and
|
|
# SENTRY_ENVIRONMENT as Elastic Beanstalk environment settings managed by
|
|
# Terraform: dev is labeled "development", staging "staging". Future production
|
|
# wiring will pass the production DSN through the same sentry_dsn module variable.
|
|
SENTRY_DSN=
|
|
SENTRY_ENVIRONMENT=development
|
|
|
|
# --- SQL Server connection string (Api.SeaHavenIndustries + SeaHavenIndustries) ---
|
|
ConnectionStrings__DefaultConnection=Server=<host>;Initial Catalog=<db>;User Id=<user>;Password=<password>;MultipleActiveResultSets=true
|
|
|
|
# --- SendGrid (transactional email) ---
|
|
SendGrid__ApiKey=SG.xxxxxxxxxxxxxxxxxxxxxx
|
|
|
|
# --- JWT signing secret (Api.SeaHavenIndustries) ---
|
|
JWT__Secret=<a-long-random-secret>
|
|
|
|
# --- Google Maps / Places API key (SeaHavenIndustries Blazor app) ---
|
|
GoogleMaps__ApiKey=AIzaSyXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
|
|
|
|
# --- AWS S3 (optional; prefer instance role / SSO over static keys) ---
|
|
# AWS_ACCESS_KEY_ID=
|
|
# AWS_SECRET_ACCESS_KEY=
|
|
# AWS_REGION=us-east-2
|
|
|
|
# --- Work Order ingest (Lambda cutover) ---
|
|
# Leave Enabled=false until ApiKey is a real secret (min 32 chars). Do not use appsettings placeholders.
|
|
WorkOrderIngest__Enabled=false
|
|
WorkOrderIngest__ApiKey=<shared-secret-for-X-Ingest-Key-min-32-chars>
|
|
|
|
# --- Dynamo sync bridge (keep false after Lambda cutover; avoid dual-run with ingest) ---
|
|
Sync__Enabled=true
|
|
|
|
# --- Legacy endpoint deprecation headers ---
|
|
LegacyEndpoints__DeprecationEnabled=false
|
|
LegacyEndpoints__SunsetDate=2026-12-31
|