Add deployment files
CI / backend (push) Failing after 2m26s
CI / frontend (push) Failing after 53s

This commit is contained in:
voltsrage
2026-08-11 20:17:53 +08:00
parent a4faf7eadd
commit c871dc4842
24 changed files with 1880 additions and 0 deletions
+113
View File
@@ -0,0 +1,113 @@
# ---- image coordinates ----
REGISTRY=git.vectur45.com/trent/vigilcare-clinical
IMAGE_TAG=v1.0.0
# ---- exposed ports on the production host ----
API_PORT=5270
GATEWAY_PORT=5081
DASHBOARD_PORT=8088
DASHBOARD_ORIGIN=https://vigilcare-clinical.vectur45.com
# Gitea Actions var PROD_API_URL (dashboard build) — not read by compose:
# https://api.vigilcare-clinical.vectur45.com
# ---- PostgreSQL (container on the same VM, reached via the shared-service network) ----
# Runtime (DML-only) connection used by the API container.
# "postgres" = the service name in the Postgres compose project - rename to match it exactly.
# Port 5432 is the container's internal port, NOT the 5433 published on the host.
# SSL Mode=Disable: Postgres on the shared-services Docker network has no TLS.
# Use Require only when connecting to a TLS-enabled external Postgres.
PG_CONNECTION="Host=postgres;Port=5432;Database=vigilcare;Username=admin;Password=PartyHard753!;SSL Mode=Disable"
# DDL-privileged connection used ONLY by the EF migration bundle (Step 6 / CD migrate job).
# That job currently runs an act_runner container that is NOT joined to shared-service
# (see .gitea/workflows/cd.yml), so it MUST keep using the externally-routable host:port,
# not the container network name, unless that job is later attached to shared-service too.
# Never put this credential in the API container environment.
PG_CONNECTION_DDL="Host=postgres.site.com;Port=5432;Database=vigilcare;Username=admin;Password=PartyHard753!;SSL Mode=Require;Trust Server Certificate=false"
GATEWAY_PG_CONNECTION="Host=postgres;Port=5432;Database=vigilcare_ward;Username=admin;Password=PartyHard753!;SSL Mode=Disable"
# ---- Redis (container on the same VM, reached via the shared-service network) ----
# "redis" = the service name in the Redis compose project - rename to match it exactly.
# Port 6379 is the container's internal port; confirm it matches (it usually does).
REDIS_CONNECTION=redis:6379,abortConnect=false
GATEWAY_REDIS_CONNECTION=redis:6379,abortConnect=false,defaultDatabase=1
# ---- external Seq ----
# On vectur-home-server (Tailscale) - use the ingestion port (5341), not the web UI
# port (8080->80). No TLS is configured, so plain http, not https.
SEQ_URL=http://vectur-home-server:5341
# The compose only sets SEQ_FIRSTRUN_ADMINUSERNAME/PASSWORD for first-run login,
# it does not provision an API key. Generate one manually via Seq's web UI
# (Settings -> API Keys) after the container's first run, then paste it here.
SEQ_API_KEY=CHANGE_ME
# ---- external Kafka ----
# Single-broker cluster on vectur-home-server (Tailscale) - PLAINTEXT only, no SASL.
# Traffic relies on the Tailscale mesh for encryption in transit.
KAFKA_BOOTSTRAP=vectur-home-server:9092
KAFKA_REPLICATION_FACTOR=1
KAFKA_SECURITY_PROTOCOL=Plaintext
# ---- external Elasticsearch ----
# Unauthenticated cluster: leave ES_API_KEY / ES_USERNAME / ES_PASSWORD unset.
# Program.cs only attaches auth when those values are non-empty.
ES_URI=http://vectur-home-server:9200
ES_API_KEY=
# ES_USERNAME=
# ES_PASSWORD=
# ---- external RabbitMQ ----
# Plain AMQP on vectur-home-server (Tailscale) - only 5672 is exposed, no TLS listener.
# RABBITMQ_USERNAME/PASSWORD must match RABBITMQ_DEFAULT_USER/PASS in the RabbitMQ
# compose's own .env on vectur-home-server.
RABBITMQ_HOST=vectur-home-server
RABBITMQ_PORT=5672
RABBITMQ_USERNAME=admin
RABBITMQ_PASSWORD=2va2xcLWTAlRN4abEv3wa7EVawHXk+tnRkQVOOXqs2M=
RABBITMQ_USE_SSL=false
GATEWAY_RABBITMQ_HOST=vectur-home-server
GATEWAY_RABBITMQ_PORT=5672
GATEWAY_RABBITMQ_USERNAME=admin
GATEWAY_RABBITMQ_PASSWORD=2va2xcLWTAlRN4abEv3wa7EVawHXk+tnRkQVOOXqs2M=
GATEWAY_RABBITMQ_USE_SSL=false
# ---- external MinIO ----
# Host publishes the S3 API on 9002 (mapped to container's 9000), no TLS termination.
# MINIO_ACCESS_KEY/SECRET_KEY must match MINIO_ROOT_USER/MINIO_ROOT_PASSWORD in the
# MinIO compose's own .env on vectur-home-server.
MINIO_ENDPOINT=vectur-home-server:9002
MINIO_ACCESS_KEY=admin
MINIO_SECRET_KEY=p3QUh8mXvosfFjrJYJJPd36tGiPbsOASWdIe6FKzdLI=
MINIO_USE_SSL=false
# ---- application secrets (generate with: openssl rand -base64 48) ----
JWT_SIGNING_KEY=T0oK2f3YhBesoMgZnEB7vmi4Dfbd7LxtuemkXI8j3xA=
# WARNING: rotating PHI_SEARCH_TOKEN_KEY invalidates every stored patient
# search token. See docs/ops/phi-encryption-runbook.md before changing it.
PHI_SEARCH_TOKEN_KEY=tbL0Nku3+bK476bv4zmfyRBiiRMTTF3To4Qq9RUOSVg=
GATEWAY_API_KEY=ZxFKE4wUChEg+VzNGM16zFSuHeM+I+IQc59rIzN0U2g=
FHIR_API_KEY=wY29TLNIzLouIEKDu+XAxmZ3T1R5cjE2IIXxaYWpNAg=
GATEWAY_JWT_SIGNING_KEY=TfxbvLz992kr8simlbr8s61W5gKQbLqjyTuPjgCWjV0=
# ---- gateway identity ----
GATEWAY_ID=ce985c14-42de-4db4-8538-c2a203496d9e
GATEWAY_SITE_ID=e9fba67a-fcf5-4966-acb1-dab58a68bff2
GATEWAY_DEPARTMENT=ICU
GATEWAY_CODE=GW-ICU-1
GATEWAY_SITE_CODE=SITE-01
GATEWAY_SITE_NAME=Primary Site
# GATEWAY_SITE_ADDRESS=
# ---- production bootstrap users (API seeds these when missing; not demo accounts) ----
SEED_ADMIN_USERNAME=admin
SEED_ADMIN_PASSWORD="zx+yv8XtbxQq0E5YZ3d8kP5g"
SEED_ADMIN_DISPLAY_NAME=System Admin
SEED_NURSE_USERNAME=nurse
SEED_NURSE_PASSWORD="qcYtKfgLMezlT63AIxrPdmtK"
SEED_NURSE_DISPLAY_NAME=Charge Nurse
SEED_PHYSICIAN_USERNAME=physician
SEED_PHYSICIAN_PASSWORD="msKxpOQIGHK/StlrPIDBx9ZD"
SEED_PHYSICIAN_DISPLAY_NAME=Attending Physician
SIMULATION_ENABLED=true
SIMULATION_RUNNER_PASSWORD=tlIxrcgEEQKh9BYdjZ6/fWwj4TFoN4zTtCUfICrQpxI=