# ============================================================================= # .env.docker.example — template for `docker compose --env-file .env.docker up` # # DO NOT COMMIT .env.docker. It contains real secrets. # Usage: # cp .env.docker.example .env.docker # $EDITOR .env.docker # docker compose --env-file .env.docker up --build # ============================================================================= # --- PostgreSQL (local container) --------------------------------------------- POSTGRES_USER=crm_user # Generate a strong password, e.g.: # python -c "import secrets; print(secrets.token_urlsafe(24))" POSTGRES_PASSWORD=STRONG_PASSWORD_HERE POSTGRES_DB=crm_db # --- Redis (REQUIRED) --------------------------------------------------------- # Generate a strong password: # python -c "import secrets; print(secrets.token_urlsafe(24))" REDIS_PASSWORD=STRONG_REDIS_PASSWORD_HERE # --- CRM Application: Runtime DB user (NOSUPERUSER, NOBYPASSRLS) -------------- # The app and worker use crm_runtime — RLS is enforced. # This user is created by migration 0044 with DML-only permissions. # Set RUNTIME_DB_PASSWORD to the password you want for crm_runtime. RUNTIME_DB_PASSWORD=STRONG_RUNTIME_PASSWORD_HERE DATABASE_URL=postgresql+asyncpg://crm_runtime:STRONG_RUNTIME_PASSWORD_HERE@postgres:5432/crm_db # --- CRM Application: Migration DB user (owner, can run DDL) ----------------- # Migrations and DDL operations use the owner user (crm_user). # This is NOT used by the app at runtime — only by prestart.sh / alembic. MIGRATION_DATABASE_URL=postgresql+asyncpg://crm_user:STRONG_PASSWORD_HERE@postgres:5432/crm_db # --- SECRET_KEY (REQUIRED, min 32 chars) ------------------------------------- # Session signing secret. MUST be at least 32 characters. # Generate with: # python -c "import secrets; print(secrets.token_urlsafe(48))" SECRET_KEY=MIN_32_CHARS_GENERATE_WITH_secrets_token_urlsafe_32_xxxxxxxxxxxx # --- Frontend URL (for email links) ------------------------------------------ # The public URL where users access the LeoCRM frontend. # Used for password reset links, invitations, etc. FRONTEND_URL=https://crm.example.com # --- CORS / environment ------------------------------------------------------- # Comma-separated, NO wildcards. In dev we allow localhost:8000 (the app) and # :5173 (e.g. Vite dev server). In production, restrict to the real domain. CORS_ORIGINS=https://crm.example.com ENVIRONMENT=production LOG_LEVEL=INFO # --- SMTP (for password reset emails) ----------------------------------------- SMTP_HOST=smtp.example.com SMTP_PORT=587 SMTP_USERNAME=noreply@example.com SMTP_PASSWORD=YOUR_SMTP_PASSWORD SMTP_FROM_EMAIL=noreply@example.com SMTP_USE_TLS=true # --- bcrypt tuning ---------------------------------------------------------- BCRYPT_ROUNDS=12