# Database DATABASE_URL="postgresql://torqvoice:torqvoice@db:5432/torqvoice" # Authentication (generate with: openssl rand -hex 32) BETTER_AUTH_SECRET="your-secret-here" # App URL (used by both the app and Better Auth) NEXT_PUBLIC_APP_URL="http://localhost:3000" # Where uploaded files and the app's other data live. Unset, it is `data` # beside the app, which is where everything has always been written; set it to # put uploads on a disk with room on them. Files already written to the old # place keep being found, so this can be turned on at any time. # # In Docker, move the volume with it: the compose file mounts # `/app/data/uploads`, and a DATA_ROOT pointing anywhere else would write into # the container instead, where a redeploy loses it. # DATA_ROOT="/var/lib/torqvoice" # Set to true only when Cloudflare proxies every request AND the origin # refuses traffic that did not come through it (Cloudflare IP ranges allowed # at the firewall or in nginx). # # Behind Cloudflare this is required, not optional: the proxy sets X-Real-IP # from the connection it sees, which is a Cloudflare edge address shared by # thousands of visitors, so leaving this off collapses everyone into a handful # of rate-limit buckets and real users start getting 429s. # # Without the origin lock it is worse than useless, because cf-connecting-ip is # then just a header anyone reaching the box directly can write for themselves. TRUST_CF_CONNECTING_IP=false # Integrations (Settings → Integrations) # Key that seals third-party tokens at rest (generate with: openssl rand -hex 32). # Without it the key is derived from BETTER_AUTH_SECRET, with a warning at startup. INTEGRATIONS_ENCRYPTION_KEY="" # OAuth apps the platform registers with each provider. Leave empty on a # self-hosted install to have each workshop enter its own app credentials. GOOGLE_INTEGRATION_CLIENT_ID="" GOOGLE_INTEGRATION_CLIENT_SECRET="" # Google sign-in (cloud mode only). A web OAuth client in the Google Cloud console # with this authorised redirect URI: /api/public/auth/callback/google # Separate from the calendar connector client above, which requests calendar scopes. GOOGLE_AUTH_CLIENT_ID="" GOOGLE_AUTH_CLIENT_SECRET="" MICROSOFT_INTEGRATION_CLIENT_ID="" MICROSOFT_INTEGRATION_CLIENT_SECRET="" ZOOM_INTEGRATION_CLIENT_ID="" ZOOM_INTEGRATION_CLIENT_SECRET="" # Intuit development keys reach sandbox companies, production keys live ones; # the connector works out which it was given. QUICKBOOKS_INTEGRATION_CLIENT_ID="" QUICKBOOKS_INTEGRATION_CLIENT_SECRET=""