Files
music_library/config/runtime.exs
T
2026-04-30 13:39:39 +01:00

210 lines
6.9 KiB
Elixir

import Config
# config/runtime.exs is executed for all environments, including
# during releases. It is executed after compilation and before the
# system starts, so it is typically used to load production configuration
# and secrets from environment variables or elsewhere. Do not define
# any compile-time configuration in here, as it won't be applied.
# The block below contains prod specific runtime configuration.
# ## Using releases
#
# If you use `mix release`, you need to explicitly enable the server
# by passing the PHX_SERVER=true when you start it:
#
# PHX_SERVER=true bin/music_library start
#
# Alternatively, you can use `mix phx.gen.release` to generate a `bin/server`
# script that automatically sets the env var above.
if System.get_env("PHX_SERVER") do
config :music_library, MusicLibraryWeb.Endpoint, server: true
end
if openai_key = System.get_env("OPENAI_KEY") do
config :music_library, OpenAI, api_key: openai_key
end
if personal_access_token = System.get_env("DISCOGS_PERSONAL_ACCESS_TOKEN") do
config :music_library, Discogs, personal_access_token: personal_access_token
end
if api_key = System.get_env("BRAVE_SEARCH_API_KEY") do
config :music_library, BraveSearch, api_key: api_key
end
if default_timezone = System.get_env("DEFAULT_TIMEZONE") do
config :music_library, :default_timezone, default_timezone
end
MusicLibrary.Repo.ensure_supported_platform!()
config :music_library, MusicLibrary.Repo,
auto_vacuum: :incremental,
load_extensions: [
MusicLibrary.Repo.extension_path("unicode"),
MusicLibrary.Repo.extension_path("vec0")
]
config :music_library, MusicLibrary.BackgroundRepo, auto_vacuum: :incremental
config :music_library, MusicLibrary.TelemetryRepo, auto_vacuum: :incremental
cloak_encryption_key =
System.get_env("CLOAK_ENCRYPTION_KEY") ||
raise """
environment variable CLOAK_ENCRYPTION_KEY is missing.
Generate one with: iex> 32 |> :crypto.strong_rand_bytes() |> Base.encode64()
"""
config :music_library, MusicLibrary.Vault,
json_library: JSON,
ciphers: [
default:
{Cloak.Ciphers.AES.GCM,
tag: "AES.GCM.V1", key: Base.decode64!(cloak_encryption_key), iv_length: 12}
]
if config_env() !== :test do
if api_key = System.get_env("LAST_FM_API_KEY") do
config :music_library, LastFm, api_key: api_key
end
if shared_secret = System.get_env("LAST_FM_SHARED_SECRET") do
config :music_library, LastFm, shared_secret: shared_secret
end
if user = System.get_env("LAST_FM_USER") do
config :music_library, LastFm, user: user
end
end
if config_env() == :prod do
mailgun_api_key =
System.get_env("MAILGUN_API_KEY") ||
raise """
environment variable MAILGUN_API_KEY is missing.
"""
mailgun_domain =
System.get_env("MAILGUN_DOMAIN") ||
raise """
environment variable MAILGUN_DOMAIN is missing.
"""
config :music_library, MusicLibrary.Mailer, api_key: mailgun_api_key, domain: mailgun_domain
database_path =
System.get_env("DATABASE_PATH") ||
raise """
environment variable DATABASE_PATH is missing.
For example: /etc/music_library/music_library.db
"""
config :music_library, MusicLibrary.Repo,
database: database_path,
# 128MB * pool_size = base memory usage
cache_size: -128_000,
pool_size: String.to_integer(System.get_env("POOL_SIZE") || "5"),
show_sensitive_data_on_connection_error: false
background_database_path =
System.get_env("BACKGROUND_DATABASE_PATH") ||
raise """
environment variable BACKGROUND_DATABASE_PATH is missing.
For example: /etc/music_library/music_library_background.db
"""
config :music_library, MusicLibrary.BackgroundRepo,
database: background_database_path,
# 16MB * pool_size = base memory usage
cache_size: -8000,
pool_size: String.to_integer(System.get_env("POOL_SIZE") || "5"),
show_sensitive_data_on_connection_error: false
telemetry_database_path =
System.get_env("TELEMETRY_DATABASE_PATH") ||
raise """
environment variable TELEMETRY_DATABASE_PATH is missing.
For example: /etc/music_library/music_library_telemetry.db
"""
config :music_library, MusicLibrary.TelemetryRepo,
database: telemetry_database_path,
cache_size: -4000,
pool_size: 2,
show_sensitive_data_on_connection_error: false
# The secret key base is used to sign/encrypt cookies and other secrets.
# A default value is used in config/dev.exs and config/test.exs but you
# want to use a different value for prod and you most likely don't want
# to check this value into version control, so we use an environment
# variable instead.
secret_key_base =
System.get_env("SECRET_KEY_BASE") ||
raise """
environment variable SECRET_KEY_BASE is missing.
You can generate one by calling: mix phx.gen.secret
"""
login_password =
System.get_env("LOGIN_PASSWORD") ||
raise """
environment variable LOGIN_PASSWORD is missing.
"""
api_token =
System.get_env("API_TOKEN") ||
raise """
environment variable API_TOKEN is missing.
"""
host = System.get_env("SERVICE_FQDN_WEB") || "example.com"
port = String.to_integer(System.get_env("PORT") || "4000")
config :music_library, MusicLibraryWeb, login_password: login_password, api_token: api_token
config :music_library, MusicLibraryWeb.Endpoint,
url: [host: host, port: 443, scheme: "https"],
http: [
# Enable IPv6 and bind on all interfaces.
# Set it to {0, 0, 0, 0, 0, 0, 0, 1} for local network only access.
# See the documentation on https://hexdocs.pm/bandit/Bandit.html#t:options/0
# for details about using IPv6 vs IPv4 and loopback vs public addresses.
ip: {0, 0, 0, 0, 0, 0, 0, 0},
port: port
],
secret_key_base: secret_key_base
# ## SSL Support
#
# To get SSL working, you will need to add the `https` key
# to your endpoint configuration:
#
# config :music_library, MusicLibraryWeb.Endpoint,
# https: [
# ...,
# port: 443,
# cipher_suite: :strong,
# keyfile: System.get_env("SOME_APP_SSL_KEY_PATH"),
# certfile: System.get_env("SOME_APP_SSL_CERT_PATH")
# ]
#
# The `cipher_suite` is set to `:strong` to support only the
# latest and more secure SSL ciphers. This means old browsers
# and clients may not be supported. You can set it to
# `:compatible` for wider support.
#
# `:keyfile` and `:certfile` expect an absolute path to the key
# and cert in disk or a relative path inside priv, for example
# "priv/ssl/server.key". For all supported SSL configuration
# options, see https://hexdocs.pm/plug/Plug.SSL.html#configure/1
#
# We also recommend setting `force_ssl` in your config/prod.exs,
# ensuring no data is ever sent via http, always redirecting to https:
#
# config :music_library, MusicLibraryWeb.Endpoint,
# force_ssl: [hsts: true]
#
# Check `Plug.SSL` for all available options in `force_ssl`.
end