-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy path.env.example
More file actions
95 lines (81 loc) · 3.98 KB
/
Copy path.env.example
File metadata and controls
95 lines (81 loc) · 3.98 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
# PostgreSQL connection string (Cloud SQL or any Postgres instance)
DATABASE_URL="postgresql://user:password@host:5432/dbname"
# Auth — HMAC secret for signing session cookies (REQUIRED in production).
# Generate with: openssl rand -hex 32
AUTH_TOKEN_SECRET="generate-a-random-secret"
# Adjust API credentials require a stable, server-side encryption key:
# base64 of exactly 32 random bytes. Store the real value in Secret Manager,
# never in source. Unset blocks new connections. Rotation requires a plan to
# re-encrypt existing credentials or reconnect them with their API tokens.
PLATFORM_CREDENTIAL_KEY=""
# Legacy NextAuth env — falls back to AUTH_TOKEN_SECRET if set
NEXTAUTH_SECRET="generate-a-random-secret"
NEXTAUTH_URL="http://localhost:3000"
# Google Cloud Storage bucket for file uploads
GCS_BUCKET="your-gcs-bucket-name"
# Google Ads API (Step 1: OAuth)
GOOGLE_ADS_CLIENT_ID=""
GOOGLE_ADS_CLIENT_SECRET=""
GOOGLE_ADS_REDIRECT_URI="https://your-domain.com/adex/api/auth/google/callback"
# Public URL of your deployment (used for OAuth redirects on Cloud Run)
PUBLIC_URL="https://your-domain.com"
# Google Drive API key (for Drive folder sync)
GDRIVE_API_KEY=""
GDRIVE_FOLDER_ID=""
# Seedance2 (doubao-seedance-2-0) — AI video generation
SEEDANCE2_API_KEY=""
# Competitor-remix cost guardrails (optional — sane defaults if unset)
REMIX_BURST_LIMIT="20" # max remix renders per org per 10-min window
REMIX_DAILY_CAP="50" # max remix renders per org per day
# Comma-separated tier allowlist for /api/creatives/remix-jobs. Defaults to
# "t0_5" (borrow-structure-not-pixels only) if unset. t1/t2 use a Tier-2
# hand-picked competitor video as a reference/source and are opt-in only —
# e.g. REMIX_ENABLED_TIERS="t0_5,t1,t2"
REMIX_ENABLED_TIERS=""
# Optional: explicit access token for GCS uploads in local dev
GOOGLE_ACCESS_TOKEN=""
# Anthropic Claude API — enables the LLM-powered Advisor and AI ad copy
# generation. If unset, the Advisor falls back to rule-based suggestions.
ANTHROPIC_API_KEY=""
# Optional — defaults to claude-sonnet-4-5
ANTHROPIC_MODEL=""
# SMTP for daily digest email. If unset, digest is saved to DB but not sent.
SMTP_HOST=""
SMTP_PORT="587"
SMTP_SECURE="false"
SMTP_USER=""
SMTP_PASS=""
MAIL_FROM="Adex <no-reply@your-domain.com>"
# Cron endpoint shared secret. Required to authorize POST /api/cron/daily.
# Use with Google Cloud Scheduler / Kubernetes CronJob / whatever. Generate:
# openssl rand -hex 32
CRON_SECRET=""
# Growth ingest secrets (org-level PlatformAuth rows override these fallbacks).
# INGEST_WEBHOOK_SECRET — HMAC signing key for POST /api/ingest/events.
# INGEST_ADJUST_SECRET — static token for GET|POST /api/ingest/adjust. MUST be
# distinct from INGEST_WEBHOOK_SECRET: the Adjust token travels in cleartext
# query strings (lands in access logs) and must not unlock HMAC forgery.
INGEST_WEBHOOK_SECRET=""
INGEST_ADJUST_SECRET=""
# Remix worker engine (Cloud Run Job, separate repo) — HMAC signing key shared
# with the /api/worker/remix-jobs/* claim/report/upload endpoints. No fallback
# default: unset means every worker request is rejected.
WORKER_WEBHOOK_SECRET=""
# Minutes a claimed-but-stalled RemixJob (claimed/running/assembling/qc with no
# progress) sits before /api/worker/remix-jobs/claim treats it as abandoned and
# lets another worker reclaim it.
REMIX_JOB_LEASE_MINUTES="30"
# Demo seed config (used by `npm run db:seed`).
# - SEED_EMAIL: defaults to demo@adexads.com if unset.
# - SEED_PASSWORD: if unset, the seed script generates a cryptographically
# random password and prints it ONCE to stdout — copy it before closing
# the terminal. Set this only if you want a deterministic password (e.g.
# in a private internal staging environment). NEVER set it to a
# well-known string in a public deployment.
# - SEED_NAME: display name for the demo user.
SEED_EMAIL=""
SEED_PASSWORD=""
SEED_NAME=""
# basePath — leave empty for adexads.com (root-mounted) or set "/adex"
# to run the app at gogameclaw.com/adex
NEXT_PUBLIC_BASE_PATH=""