diff --git a/docker-compose.yml b/docker-compose.yml index 17ae275..a6d35ee 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -24,6 +24,10 @@ services: # Dedicated ledger-signing key. Falls back to JWT_SECRET (with a warning) if empty; # set a distinct one in prod. See apps/server/.env.example + local-jwt-auth. EVENT_SIGNING_KEY: ${EVENT_SIGNING_KEY:-} + # Dedicated backup-ENCRYPTION key (separate from the signing key). Empty = backups stay + # off (the in-UI target + retention do nothing without it). Per-booth + unique; escrow it + # offsite. See apps/server/.env.example + wiki/concepts/backup-recovery.md. + BACKUP_KEY: ${BACKUP_KEY:-} # CRITICAL on the plain-HTTP booth LAN: cookies are Secure (HTTPS-only) by DEFAULT, # so without COOKIE_SECURE=0 the auth cookie is never sent over http and operators # CANNOT LOG IN. Leave unset only behind TLS. See disk-os-hardening "deploy-time runbook". diff --git a/komodo/resources.toml b/komodo/resources.toml index b1ef16f..2a2de15 100644 --- a/komodo/resources.toml +++ b/komodo/resources.toml @@ -46,10 +46,10 @@ registry_provider = "git.infra.msai.al" registry_account = "komodo" environment = """ REGISTRY=git.infra.msai.al/mca/parking_solution -# Staging booth: pin an immutable stage- per deploy. PLACEHOLDER below — after merging -# dev → stage and CI builds :stage-, set this to that exact sha (or override TAG in Core at -# deploy). The moving `:stage` tag exists as the pointer; we deploy the sha, not the mover. -TAG=stage-REPLACE_WITH_BUILT_SHA +# Staging booth: pinned immutable stage-. After each promotion (merge dev → stage, CI builds +# :stage-), bump this to the new sha and re-sync/deploy from Core. The moving `:stage` tag +# exists as the pointer; we deploy the sha, not the mover. +TAG=stage-39c778f COOKIE_SECURE=0 VISION_ENABLED=1 WS_ALLOWED_ORIGINS=