Environment variables
Every setting of the stack's .env, what it does, its default and the services that read it.
Settings for docker compose. make .env copies this file to .env and fills in the empty secrets; run again after this file gains a setting, it adds only what .env lacks. By hand, generate each secret with openssl rand -hex 32 (APP_KEY: "base64:" followed by openssl rand -base64 32).
Postgres: the superuser only sets up the roles; the control plane, the indexer and the Query API have one each.
Read by postgres.
At least 16 bytes. Only the indexer holds it. Read by meilisearch, indexer.
The Query API's key, which may only search and list indexes; the indexer creates it from the master key at start. make .env derives it; by hand, it is the master key's HMAC of the key's uid: printf %s 5e7d2c4a-8f1b-4c3e-9a6d-0b2f4e6a8c1d | openssl dgst -sha256 -hmac "$MEILI_MASTER_KEY" Read by orbsearch.
Authorizes the management API: Authorization: Bearer <key>. Read by control.
The panel and the Query API listen on this host address. 127.0.0.1 keeps them for a proxy on this machine, which also terminates TLS; 0.0.0.0 opens them to the network.
127.0.0.18000Read by control.
7800Read by orbsearch.
Postgres and Meilisearch listen on 127.0.0.1 only.
5432Read by postgres.
7700Read by meilisearch.
3000The demo storefront, which make e2e serves on the host for its browser tests. Read by control.
Where the shop answers, so the panel's previews show its photos; the demo storefront at DEMO_PORT when unset. Read by control.
falseThe catalog source's feed is fetched from the public internet only. true also fetches from private, loopback and link-local addresses, such as a feed on this machine or on the shop's own network; make stack sets it. Read by control.
Behind a proxy that terminates TLS: its addresses, comma-separated. Never *. Read by control.
A real mailer turns on email verification; without one, mail goes to the log.
smtpRead by control.
Read by control.
Read by control.
Read by control.
Read by control.
Optional: a Vercel AI Gateway key turns on mapping suggestions in the import panel (model typesafe-ai/jev). Without it, the panel maps with the import's own rules only. Read by orbsearch.
Guide: Settings