Extract config into .env; add deploy.sh with overlay guard + rollback
- Move user-specific config (login, media roots, port, AP ssid/psk, service
user) into a gitignored .env; add .env.example template.
- config.py reads .env at startup via a tiny zero-dependency parser (works for
both `uv run` and systemd), and fails loudly if required vars are unset.
- load_secret_key falls back to an ephemeral key on a read-only filesystem
instead of crashing.
- systemd units become .template files; deploy.sh renders them with the
.env-derived user/paths.
- deploy.sh: refuses to run on a read-only overlay, git pull --ff-only,
uv sync, ensure secret key, re-apply the AP from .env, install units,
restart, health-check with automatic rollback to the previous commit.
- Scrub literal credentials/ssid out of the README; document .env + deploy.sh.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 02:06:47 +00:00
|
|
|
# Copy this file to .env and fill in real values.
|
|
|
|
|
# .env is gitignored -- never commit real secrets.
|
|
|
|
|
# Values must be simple (no spaces / shell-special chars) -- this file is both
|
|
|
|
|
# parsed by the app and sourced by deploy.sh.
|
|
|
|
|
|
|
|
|
|
# --- App login (custom login form) ---
|
|
|
|
|
MEDIAPI_USERNAME=changeme
|
|
|
|
|
MEDIAPI_PASSWORD=changeme
|
|
|
|
|
|
|
|
|
|
# --- Media ---
|
|
|
|
|
# colon-separated list of directories to browse
|
|
|
|
|
MEDIAPI_MEDIA_ROOTS=/localmedia
|
|
|
|
|
MEDIAPI_PORT=8080
|
|
|
|
|
|
2026-07-07 01:21:17 +00:00
|
|
|
# --- System: the Linux user the systemd services run as ---
|
|
|
|
|
# Auto-detected from whoever runs install.sh (id -un) when left unset, so you
|
|
|
|
|
# normally don't need this. Uncomment only to force a specific user.
|
|
|
|
|
#MEDIAPI_USER=pi
|
Extract config into .env; add deploy.sh with overlay guard + rollback
- Move user-specific config (login, media roots, port, AP ssid/psk, service
user) into a gitignored .env; add .env.example template.
- config.py reads .env at startup via a tiny zero-dependency parser (works for
both `uv run` and systemd), and fails loudly if required vars are unset.
- load_secret_key falls back to an ephemeral key on a read-only filesystem
instead of crashing.
- systemd units become .template files; deploy.sh renders them with the
.env-derived user/paths.
- deploy.sh: refuses to run on a read-only overlay, git pull --ff-only,
uv sync, ensure secret key, re-apply the AP from .env, install units,
restart, health-check with automatic rollback to the previous commit.
- Scrub literal credentials/ssid out of the README; document .env + deploy.sh.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 02:06:47 +00:00
|
|
|
|
2026-07-07 00:33:46 +00:00
|
|
|
# --- WiFi access point (re-applied by install.sh) ---
|
Extract config into .env; add deploy.sh with overlay guard + rollback
- Move user-specific config (login, media roots, port, AP ssid/psk, service
user) into a gitignored .env; add .env.example template.
- config.py reads .env at startup via a tiny zero-dependency parser (works for
both `uv run` and systemd), and fails loudly if required vars are unset.
- load_secret_key falls back to an ephemeral key on a read-only filesystem
instead of crashing.
- systemd units become .template files; deploy.sh renders them with the
.env-derived user/paths.
- deploy.sh: refuses to run on a read-only overlay, git pull --ff-only,
uv sync, ensure secret key, re-apply the AP from .env, install units,
restart, health-check with automatic rollback to the previous commit.
- Scrub literal credentials/ssid out of the README; document .env + deploy.sh.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-06 02:06:47 +00:00
|
|
|
MEDIAPI_WIFI_COUNTRY=US
|
|
|
|
|
MEDIAPI_AP_SSID=changeme
|
|
|
|
|
MEDIAPI_AP_PASSWORD=changeme
|
|
|
|
|
MEDIAPI_AP_CONN_NAME=mediapi-ap
|
2026-07-07 00:33:46 +00:00
|
|
|
|
|
|
|
|
# --- Advanced (leave unset unless you know you need them) ---
|
|
|
|
|
# Where the mpv IPC socket + runtime dir live. Defaults below are correct for
|
|
|
|
|
# the shipped systemd unit, which hardcodes RuntimeDirectory=mediapi (=/run/mediapi).
|
|
|
|
|
# If you override MEDIAPI_RUNTIME_DIR you MUST also edit
|
|
|
|
|
# systemd/mediapi-mpv.service.template's RuntimeDirectory to match, or the dir
|
|
|
|
|
# won't be created at boot. Most deployments should leave both commented out.
|
|
|
|
|
#MEDIAPI_RUNTIME_DIR=/run/mediapi
|
|
|
|
|
#MEDIAPI_MPV_SOCKET=/run/mediapi/mpv.sock
|