# SCHA Wheaton Django site for SCHA Wheaton. Packaging via `uv`; production deploy via `server-infra`. ## Local development ### Prerequisites - Python 3.12+ - [uv](https://docs.astral.sh/uv/) - Docker + Docker Compose (optional, recommended) ### uv (host) ```bash cp .env.example .env uv sync uv run python manage.py migrate uv run python manage.py runserver ``` Without `DATABASE_URL` / `DB_HOST`, settings fall back to SQLite (`db.sqlite3`). ### Docker (dev, bundled Postgres) ```bash docker compose up --build ``` App: http://localhost:8000 — Postgres via `DATABASE_URL=postgres://scha:scha@db:5432/scha`. ## Environment variables | Variable | Dev default | Prod required | Notes | |----------|-------------|---------------|-------| | `DJANGO_ENV` | `dev` | `prod` / `beta` | Selects settings module | | `DJANGO_SECRET_KEY` | insecure default | yes | Must be set in prod | | `DJANGO_DEBUG` | env default / true in `dev` | `false` | | | `DJANGO_ALLOWED_HOSTS` | `*` | yes | Comma-separated | | `DJANGO_CSRF_TRUSTED_ORIGINS` | derived from hosts | optional | Comma-separated full origins | | `DATABASE_URL` | SQLite fallback | yes | Shared Postgres in prod | | `WEB_PORT` | n/a (compose) | `8002` | Host port for prod compose | | `STRIPE_*` | empty | yes (prod/beta) | Publishable, secret, webhook | | `RECAPTCHA_*` | empty | yes (prod/beta) | Public + private | Templates: `.env.example` (local), `.env.prod.example` (control-node secret). Control-node secret path (server-infra): ```text ~/Documents/secrets/scha/scha_prod.env ``` Validate with: ```bash ./scripts/validate-env.sh ~/Documents/secrets/scha/scha_prod.env ``` ## Production (docker-compose.prod.yml) - Single `web` service; **no** bundled DB — `DATABASE_URL` points at shared Postgres (`10.0.0.230`). - Host port from `WEB_PORT` (catalog: **8002**). - Deployed by `server-infra/scripts/deploy.sh --app scha --env prod --ref `. ## CI / CD (Gitea Actions) | Workflow | Trigger | Action | |----------|---------|--------| | `unittests.yml` | push + PR → `master` | `uv sync` + `manage.py test` | | `ci.yml` | PR → `master` | same unit tests | | `deploy.yml` | after Unit Tests succeeds on `master` **push** | docker build/test → `deploy.sh` | Deploy never runs on PRs. ## Security note Stripe and reCAPTCHA keys previously lived in `settings.py`. Treat them as compromised; rotate and set real values only in the control-node env file (never commit).