Files
3cloud-backend/core/.env.example
JamesBhattarai 92d9c8c9d2 Feat: Authenticate workers with a per-host secret
Core accepts XCLOUDIFY_API_KEY for Full-Access or a host's own enrollment secret limited to the routes a worker calls, for its own
data only.
2026-08-23 11:47:47 +05:45

67 lines
2.2 KiB
Bash

# Controls Flask debug mode / reloader.
FLASK_ENV=development
# Controls Swagger UI (/apidocs). Set to "development" to enable, anything else to disable.
APP_ENV=development
# MySQL connection string used by Flask-SQLAlchemy and the websocket server.
DATABASE_URL=mysql://theapi_user:theapi_password@172.17.0.1:3306/theapi
# DB 0 — Celery broker (read as BROKER_URL, fallback CELERY_BROKER_URL)
BROKER_URL=redis://172.17.0.1:6379/0
# DB 1 — Celery result backend (read as RESULT_BACKEND, fallback CELERY_RESULT_BACKEND)
RESULT_BACKEND=redis://172.17.0.1:6379/1
# DB 2 — Operational tasks (websocket server, PING logging)
REDIS_URL=redis://172.17.0.1:6379/2
SCHEDULER_MAX_ALLOCATION_ATTEMPTS=8
SCHEDULER_RETRY_BASE_DELAY_SECONDS=60
SCHEDULER_RETRY_BACKOFF_FACTOR=2.0
SCHEDULER_RETRY_JITTER_SECONDS=30
SCHEDULER_RETRY_MAX_DELAY_SECONDS=1800
API_BASE_URL=http://172.17.0.1:5000/api
# WebSocket Server base URL
WEBSOCKET_SERVER_URL=http://172.17.0.1:6001
# Socket.IO mount path on the WebSocket Server (default: "/ws")
WEBSOCKET_SERVER_PATH=/ws
# Ping heartbeat configuration
PING_HEARTBEAT_TIMEOUT_SECONDS=30
# Debug flags for the websocket server (set to "true" to enable)
ENABLE_WEBSOCKET_PING_DEBUG=false
ENABLE_TASK_ASSIGNMENT_DEBUG=false
VNC_SECRET_KEY=change-me-to-a-strong-random-secret
VNC_BASE_URL=https://vnc-console.xcloudify.tech/vnc.html
VNC_PROXY_HOST=vnc-proxy.xcloudify.tech
VNC_PROXY_PORT=443
VNC_PROXY_WS_PATH=/vnc
# Ports used by the local VNC proxy process (vnc_proxy.py)
VNC_PROXY_HTTP_PORT=6002
VNC_PORT_LOCAL=5900
# Logging verbosity for the VNC proxy's socket.io engine (DEBUG/INFO/WARNING/ERROR)
ENGINEIO_LOGGER_LEVEL=WARNING
SIO_LOGGER_LEVEL=WARNING
# Seconds a VNC console ticket stays valid. Tickets are signed with
# VNC_SECRET_KEY and checked by the VNC proxy itself.
VNC_TICKET_TTL_SECONDS=3600
# Shared key for all API calls, sent as the X-Internal-Xcloudify-API header.
XCLOUDIFY_API_KEY=change-me-generate-a-real-key
# Base domain for user-facing resources (certificates, etc.)
BASE_DOMAIN=xcloudify.tech
# Tunnel domain used for container/workload hostnames via Cloudflare tunnels
# Default OVS bridge name used when creating networks (optional)
XCF_DEFAULT_OVS_BRIDGE=br-xcloudify