# Local development defaults. Copy to `.env` (gitignored) — never commit secrets. # docker compose auto-loads `.env` for ${VAR} substitution into the web container. DJANGO_ENV=dev DJANGO_DEBUG=true DJANGO_SECRET_KEY=dev-only-change-me DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener # Leave empty for SQLite when running manage.py on the host. # Compose ignores this and uses the bundled Postgres via COMPOSE_DATABASE_URL. # DATABASE_URL= SITE_NAME=URL Shortening Service CREDIT_NAME=AI ML Operations CREDIT_URL=https://aimloperations.com SHORT_DOMAIN=localhost:8005 # Origin printed in minted short_url (phones hit this). Local: this machine. PUBLIC_SHORT_URL=http://127.0.0.1:8005 # Host values that only serve GET / (no /api/). SHORT_PUBLIC_HOSTS=go.mkdrealtor.com # Host values that serve /api/ (Bearer required). May include a public DNS name. SHORT_API_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener # Django admin — keep local. Do not add the public API hostname. SHORT_ADMIN_HOSTS=localhost,127.0.0.1 # Named, rotatable tokens. This is what keeps /api/ closed on a public hostname. # Generate: python -c "import secrets; print(secrets.token_urlsafe(32))" # Format: name:secret,name:secret — never reuse DJANGO_SECRET_KEY. SHORTENER_API_TOKENS=monica:dev-only-token # target_url hostname allowlist (exact or suffix). SHORT_ALLOWED_HOSTS=mkdrealtor.com,aimloperations.com,*.aimloperations.com SHORT_CODE_LENGTH=6 # HMAC pepper for click IP hashes. Distinct from DJANGO_SECRET_KEY. CLICK_IP_PEPPER=dev-click-pepper-change-me GUNICORN_WORKERS=2