- Replace the bare-repo post-receive hook with deploy/poll-deploy.sh: Gitea
and the Docker hosts are separate machines, so each box polls its branch
via host crontab instead of needing an exposed webhook receiver.
- Add Blocksy theme + Blocksy Companion auto-install to deploy.sh (free
tier; the paid Book Store starter site still needs a manual license step).
- Fix deploy.sh/backup.sh/restore.sh sourcing .env files as bash: a bcrypt
hash's `$2a$14$...` shape breaks under `set -u`. Replaced with
deploy/lib/env.sh, a literal (non-executing) KEY=VALUE reader.
- Fix docker compose itself mangling the same kind of value: both
`environment: ${VAR}` and `env_file:` run values through Compose's
interpolation, which silently blanks `$identifier`-shaped substrings.
The staging basic-auth hash is now rendered directly into the Caddyfile
by deploy.sh, bypassing Compose's variable system entirely.
- Fix dev/staging/production silently sharing one Compose project (and
therefore one db_data volume) by pinning an explicit -p per environment.
- cron and wordpress now share one environment anchor so they can't drift
apart again (cron was silently missing WORDPRESS_CONFIG_EXTRA before).
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
57 lines
1.9 KiB
Bash
57 lines
1.9 KiB
Bash
# Copy this to .env.dev / .env.staging / .env.production and fill in real
|
|
# values for that environment. The filled-in files are gitignored — never
|
|
# commit them. Same code everywhere; only these values differ (see
|
|
# design doc §01, Environments & deployment).
|
|
#
|
|
# CAVEAT for DB_PASSWORD, DB_ROOT_PASSWORD, and the API keys below: docker
|
|
# compose passes these into containers via ${VAR} interpolation, which will
|
|
# silently mangle a value containing `$` followed by a letter (it tries to
|
|
# resolve it as another variable and blanks it out if unset). Avoid `$` in
|
|
# these specific values, or double it ($$) if you must use one. This does
|
|
# NOT apply to STAGING_BASIC_AUTH_HASH below — that one's wired through
|
|
# env_file instead specifically so a bcrypt hash's `$` signs are safe.
|
|
|
|
# --- Site ---
|
|
# (WP_ENVIRONMENT_TYPE is NOT set here — it's hardcoded per environment in
|
|
# docker-compose.{dev,staging,production}.yml so it can't go stale.)
|
|
SITE_DOMAIN=staging.example.com
|
|
SITE_URL=https://staging.example.com
|
|
SITE_TITLE="Bookstore (staging)"
|
|
|
|
# --- WordPress admin bootstrap (used only on first install) ---
|
|
WP_ADMIN_USER=admin
|
|
WP_ADMIN_PASSWORD=changeme
|
|
WP_ADMIN_EMAIL=admin@example.com
|
|
|
|
# --- Database ---
|
|
DB_NAME=bookstore
|
|
DB_USER=bookstore
|
|
DB_PASSWORD=changeme
|
|
DB_ROOT_PASSWORD=changeme
|
|
WP_TABLE_PREFIX=wp_
|
|
|
|
# --- Staging only: basic-auth wall + noindex ---
|
|
# Generate the hash with:
|
|
# docker run --rm caddy:2-alpine caddy hash-password --plaintext 'your-password'
|
|
STAGING_BASIC_AUTH_USER=staging
|
|
STAGING_BASIC_AUTH_HASH=
|
|
|
|
# --- Backups (deploy/backup.sh) ---
|
|
BACKUP_DIR=./backups
|
|
BACKUP_REMOTE=
|
|
BACKUP_RETENTION_DAYS=14
|
|
|
|
# --- Supplier adapters (design doc §04) ---
|
|
# staging: gutenberg_test production: booksrun,ingram
|
|
ACTIVE_SUPPLIER_ADAPTERS=gutenberg_test
|
|
BOOKSRUN_API_KEY=
|
|
INGRAM_API_KEY=
|
|
INGRAM_ACCOUNT_ID=
|
|
|
|
# --- Payments (Helcim) ---
|
|
HELCIM_API_TOKEN=
|
|
HELCIM_ACCOUNT_ID=
|
|
|
|
# --- Marketing ---
|
|
MAILERLITE_API_KEY=
|