# Komodo Stack environment — reference of what a booth Stack needs and WHERE it comes # from. Under Komodo, plain env lives in the Stack definition (komodo/resources.toml); # the two SECRETS come from Komodo Core's secret store, PER BOOTH and UNIQUE. This file # is documentation only — do NOT fill in real secrets here (it would be the same leak # we're avoiding). See wiki/decisions/fleet-deployment-komodo.md. # --- plain Stack env (lives in resources.toml; safe in git) ------------------- REGISTRY=git.infra.msai.al/mca/parking_solution # IMMUTABLE per-commit tag. Manual + pinned. Bump per deploy. Never the moving `dev` # on a production booth. TAG=dev-830993b COOKIE_SECURE=0 VISION_ENABLED=1 WS_ALLOWED_ORIGINS= # --- secrets (Core secret store, referenced by name in resources.toml) -------- # Generated PER BOOTH (openssl rand -hex 32), registered in Core under booth-scoped # names, never reused across sites. The user generates these; they are never typed on # a CLI or committed. # JWT_SECRET -> [[booth__jwt_secret]] (login) # EVENT_SIGNING_KEY -> [[booth__event_signing_key]] (ledger signing — fraud root) # Periphery/registry auth also live in Core: # periphery passkey -> [[periphery_passkey_booth_]] # registry account -> [[gitea_registry_account]]