Files
lasuite-docs/env.d/development/yhub
T
Kevin JahnsandManuel Raynaud f68978d5a6 🔧(yhub) align the yhub db credentials with the backend's dev ones
The yhub database ran under its own yhub role. Every other database in
this stack uses the backend's dev credentials, dinum/pass, which is also
what CI already uses for this database; only the database name stays
apart, since it is a separate database on a separate server.

The url the collaboration server connects with moves into the same file,
beside the credentials it repeats, written once rather than twice — the
yhub service reads the file as well. A yhub-postgres.local override is
created like for the other env files, and the healthcheck asks about
POSTGRES_DB and POSTGRES_USER like the other two do instead of naming the
role.

POSTGRES_USER only takes effect on a fresh initdb, so an existing stack
needs its yhub-pgdata volume dropped and `make migrate-yhub` re-run; the
volume holds local document state only.

Signed-off-by: Kevin Jahns <kevin.jahns@protonmail.com>
2026-09-02 09:41:58 +02:00

53 lines
2.5 KiB
Plaintext

# Collaboration server (yhub)
#
# Everything the collaboration server reads but its database url, and nothing
# else: it shares the backend's stores and origins by value, not by loading the
# backend's own environment. Override any of it in yhub.local, which is not
# committed.
# Stores. Its own valkey and its own postgres database — the backend's live
# next to them and are never touched from here. The postgres url is not here
# but in `yhub-postgres`, the file that database is configured from, so that
# its credentials are written once; this service reads that file too.
PORT=3002
REDIS=redis://yhub-valkey:6379
REDIS_PREFIX=yhub
# Backend. It answers who a user is and what they may do with a document, and
# publishes the JWKS the admin tokens it signs are verified against. The origin
# list is what a browser may open a websocket from — the frontend dev server.
COLLABORATION_BACKEND_BASE_URL=http://app-dev:8000
COLLABORATION_SERVER_ORIGIN=http://localhost:3000
# sent as X-Y-Provider-Key on the calls made to the backend; the same value as
# in `common`, which is where the backend reads the one it compares it to
Y_PROVIDER_API_KEY=yprovider-api-key
# Signs the calls made to the backend, which holds the public half. Generated
# by `make generate-secret-keys`, never committed.
YHUB_JWT_PRIVATE_KEY_FILE=/data/jwt/yhub-private.pem
# Soft migration: seed a room from the legacy Django/S3 document store the
# first time it is opened. The bucket read here is the backend's media one —
# in this stack the same minio, under the credentials of this server rather
# than the backend's own AWS_S3_* settings.
SOFT_MIGRATION=true
LEGACY_S3_ENDPOINT_URL=http://minio:9000
LEGACY_S3_ACCESS_KEY_ID=impress
LEGACY_S3_SECRET_ACCESS_KEY=password
# Document storage: where the blobs of a compaction are written. Off, they stay
# in yhub's postgres, which is what this stack runs. On, they go to object
# storage instead — here the same minio, in a bucket of its own, created
# versioned by compose so that flipping this to true exercises what a
# deployment does rather than a simpler case.
#
# The settings below are read whether or not the toggle is on: they are what
# attaches the S3 plugin, and the plugin is what can read back the objects a
# previous run wrote. Only the writing follows the toggle. See the "Document
# storage" section of src/yhub-server/README.md.
YHUB_S3_PERSISTENCE=false
YHUB_S3_ENDPOINT_URL=http://minio:9000
YHUB_S3_ACCESS_KEY_ID=impress
YHUB_S3_SECRET_ACCESS_KEY=password
YHUB_S3_BUCKET_NAME=yhub-storage