Repository navigation
Expand file tree
/
Copy path.env
More file actions
73 lines (60 loc) · 2.37 KB
/
Copy path.env
File metadata and controls
73 lines (60 loc) · 2.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
# Application
APP_PREFIX=sdep
# Postgres database
POSTGRES_DB_NAME=sdep-data
POSTGRES_DB_USER=sdep
POSTGRES_DB_PASSWORD=sdep
# Postgres server
POSTGRES_CONTAINER_NAME=sdep-postgres
POSTGRES_PORT=5432
POSTGRES_VERSION=17.6
# Postgres superuser
POSTGRES_SUPER_USER=postgres
POSTGRES_SUPER_PASSWORD=postgres
# Keycloak container
KC_WAIT_HTTP_TIMEOUT_SECONDS=300
KC_CONTAINER_NAME=sdep-keycloak
KC_PORT=8080
KC_VERSION=26.2.4
KC_BASE_URL=http://localhost:8080
# Keycloak admin realm
KC_ADMIN_REALM_ADMIN_USERNAME=admin
KC_ADMIN_REALM_ADMIN_PASSWORD=admin
# Keycloak database
KC_DB=postgres
KC_DB_URL=jdbc:postgresql://sdep-postgres:5432/keycloak
KC_DB_USERNAME=keycloak
KC_DB_PASSWORD=keycloak
# Keycloak webapp
KC_HOSTNAME_STRICT_HTTPS=false
KC_HOSTNAME_STRICT=false
KC_HTTP_ENABLED=true
# Authentication - Client Credentials Flow
# Only intended for test purposes (easy start in Swagger UI, less secure)
# Default true; to disable and simulate Production (enforce Client-Signed JWT Authentication only), override to false in .env.extra
CLIENT_SECRET_AUTH_ENABLED=true
# Alpha API versions - served up to PRE only, never in PRD (see docs/API_TECH.md)
# Default true locally; to simulate Production (no alpha versions), override to false in .env.extra
API_ALPHA_ENABLED=true
# ClamAV malware scanning
MALWARE_SCAN_ENABLED=true
MALWARE_SCAN_CLAMAV_PORT=3310
# Backend image
BACKEND_IMAGE_NAME=local/sdep-backend
BACKEND_IMAGE_VERSION=latest
# Keycloak application realm
# KC_APP_REALM_MACHINE_CLIENT_YAML is the extended machine-client file that is actually provisioned into Keycloak: originating from keycloak/machine-clients.yaml, augmented with generated client-signed JWT clients
# It is written by "make keycloak-generate-machine-clients" (invoked on its own, or implicitly by "make keycloak-up" and "make up")
# KC_ENV selects which Keycloak the client-inspection targets talk to (local, tst, acc, pre, prd) override per invocation with "make <target> KC_ENV=tst" etc.
KC_ENV=local
KC_APP_REALM_CONFIG_YAML=keycloak/realm.yaml
KC_APP_REALM_ADMIN_ID=cicd_admin
KC_APP_REALM_ADMIN_NAME=client_cicd_admin
KC_APP_REALM_ADMIN_DESC="CI/CD admin client"
KC_APP_REALM_ROLE_YAML=keycloak/roles.yaml
KC_APP_REALM_MACHINE_CLIENT_YAML=tmp/machine-clients-extended.yaml
# Backend test
BACKEND_CONTAINER_NAME=sdep-backend
BACKEND_PORT=8000
BACKEND_BASE_URL=http://localhost:8000
BACKEND_KC_BASE_URL=http://sdep-keycloak:8080