## Summary - Public short domain is **`piha.lc`** (prod) and **`beta.piha.li`** (beta) - `/` is a marketing page in [aimloperations.com](https://aimloperations.com) / `company_site` styling (Inter, dark, cyan) - CTA: want access → [contact](https://aimloperations.com/contact) - Nav/logo/footer match the company site; debug mint form uses the same chrome Closes #3. ## Secrets (control node) Update hostnames only — no new token/pepper unless you are rotating: **`url_shortening_service_prod.env`** ```text DJANGO_ALLOWED_HOSTS=piha.lc,shortener.aimloperations.com,url-shortener,web SHORT_DOMAIN=piha.lc PUBLIC_SHORT_URL=https://piha.lc SHORT_PUBLIC_HOSTS=piha.lc CONTACT_URL=https://aimloperations.com/contact ``` **`url_shortening_service_beta.env`** ```text DJANGO_ALLOWED_HOSTS=beta.piha.li,shortener-beta.aimloperations.com,url-shortener,web SHORT_DOMAIN=beta.piha.li PUBLIC_SHORT_URL=https://beta.piha.li SHORT_PUBLIC_HOSTS=beta.piha.li CONTACT_URL=https://aimloperations.com/contact ``` NPM: `piha.lc` / `beta.piha.li` → this container. Still do not proxy `/api/` on the short host. ## Test plan - [ ] `cd site && uv run python manage.py test` - [ ] `GET /` looks like aimloperations.com; Request access / Contact go to aimloperations.com/contact - [ ] `GET /<code>` still 302 - [ ] `/api/` on Host `piha.lc` is 404 Reviewed-on: #4
38 lines
1.6 KiB
Bash
38 lines
1.6 KiB
Bash
# Local development defaults. Copy to `.env` (gitignored) — never commit secrets.
|
|
# docker compose auto-loads `.env` for ${VAR} substitution into the web container.
|
|
|
|
DJANGO_ENV=dev
|
|
DJANGO_DEBUG=true
|
|
DJANGO_SECRET_KEY=dev-only-change-me
|
|
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
|
|
|
|
# Leave empty for SQLite when running manage.py on the host.
|
|
# Compose ignores this and uses the bundled Postgres via COMPOSE_DATABASE_URL.
|
|
# DATABASE_URL=
|
|
|
|
SITE_NAME=URL Shortening Service
|
|
CREDIT_NAME=AI ML Operations
|
|
CREDIT_URL=https://aimloperations.com
|
|
CONTACT_URL=https://aimloperations.com/contact
|
|
|
|
SHORT_DOMAIN=localhost:8005
|
|
# Origin printed in minted short_url (phones hit this). Local: this machine.
|
|
PUBLIC_SHORT_URL=http://127.0.0.1:8005
|
|
# Host values that only serve GET /<code> (no /api/).
|
|
SHORT_PUBLIC_HOSTS=piha.lc
|
|
# Host values that serve /api/ (Bearer required). May include a public DNS name.
|
|
SHORT_API_HOSTS=localhost,127.0.0.1,0.0.0.0,web,url-shortener
|
|
# Django admin — keep local. Do not add the public API hostname.
|
|
SHORT_ADMIN_HOSTS=localhost,127.0.0.1
|
|
# Named, rotatable tokens. This is what keeps /api/ closed on a public hostname.
|
|
# Generate: python -c "import secrets; print(secrets.token_urlsafe(32))"
|
|
# Format: name:secret,name:secret — never reuse DJANGO_SECRET_KEY.
|
|
SHORTENER_API_TOKENS=monica:dev-only-token
|
|
# target_url hostname allowlist (exact or suffix).
|
|
SHORT_ALLOWED_HOSTS=mkdrealtor.com,aimloperations.com,*.aimloperations.com
|
|
SHORT_CODE_LENGTH=6
|
|
# HMAC pepper for click IP hashes. Distinct from DJANGO_SECRET_KEY.
|
|
CLICK_IP_PEPPER=dev-click-pepper-change-me
|
|
|
|
GUNICORN_WORKERS=2
|