# Copy to .env.production and fill in. Everything here is read by python-decouple. # --- Django --- DJANGO_SECRET_KEY= # python -c "import secrets; print(secrets.token_urlsafe(64))" DJANGO_DEBUG=False # The leading dot matches every club subdomain. DJANGO_ALLOWED_HOSTS=.rosterchief.app DJANGO_CSRF_TRUSTED_ORIGINS=https://rosterchief.app,https://*.rosterchief.app DJANGO_TIME_ZONE=Europe/Brussels # --- Tenancy --- # Drives subdomain resolution, the shared session cookie, and the WebAuthn RP ID (one passkey # across every club). ROSTERCHIEF_BASE_DOMAIN=rosterchief.app ROSTERCHIEF_RP_NAME=RosterChief # --- Services --- DJANGO_DATABASE_URL=postgres://rosterchief:CHANGEME@db:5432/rosterchief DJANGO_REDIS_URL=redis://redis:6379/0 # --- HTTPS (off by default in code; the deploy is what turns them on) --- DJANGO_SECURE_SSL_REDIRECT=True DJANGO_SESSION_COOKIE_SECURE=True DJANGO_CSRF_COOKIE_SECURE=True DJANGO_SECURE_HSTS_SECONDS=31536000 DJANGO_SECURE_HSTS_INCLUDE_SUBDOMAINS=True # Preload is a one-way door — turn it on only once the wildcard cert has proven itself. DJANGO_SECURE_HSTS_PRELOAD=False # --- Static --- DJANGO_STATICFILES_BACKEND=whitenoise.storage.CompressedManifestStaticFilesStorage # --- Uploads: set these and club logos move off local disk (required for >1 app server) --- # AWS_STORAGE_BUCKET_NAME=rosterchief-media # AWS_S3_ENDPOINT_URL=https://fsn1.your-objectstorage.com # AWS_S3_REGION_NAME=fsn1 # AWS_ACCESS_KEY_ID= # AWS_SECRET_ACCESS_KEY=