- Move user-specific config (login, media roots, port, AP ssid/psk, service user) into a gitignored .env; add .env.example template. - config.py reads .env at startup via a tiny zero-dependency parser (works for both `uv run` and systemd), and fails loudly if required vars are unset. - load_secret_key falls back to an ephemeral key on a read-only filesystem instead of crashing. - systemd units become .template files; deploy.sh renders them with the .env-derived user/paths. - deploy.sh: refuses to run on a read-only overlay, git pull --ff-only, uv sync, ensure secret key, re-apply the AP from .env, install units, restart, health-check with automatic rollback to the previous commit. - Scrub literal credentials/ssid out of the README; document .env + deploy.sh. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
22 lines
674 B
Text
22 lines
674 B
Text
# Copy this file to .env and fill in real values.
|
|
# .env is gitignored -- never commit real secrets.
|
|
# Values must be simple (no spaces / shell-special chars) -- this file is both
|
|
# parsed by the app and sourced by deploy.sh.
|
|
|
|
# --- App login (custom login form) ---
|
|
MEDIAPI_USERNAME=changeme
|
|
MEDIAPI_PASSWORD=changeme
|
|
|
|
# --- Media ---
|
|
# colon-separated list of directories to browse
|
|
MEDIAPI_MEDIA_ROOTS=/localmedia
|
|
MEDIAPI_PORT=8080
|
|
|
|
# --- System: systemd services run as this Linux user ---
|
|
MEDIAPI_USER=pi
|
|
|
|
# --- WiFi access point (re-applied by deploy.sh) ---
|
|
MEDIAPI_WIFI_COUNTRY=US
|
|
MEDIAPI_AP_SSID=changeme
|
|
MEDIAPI_AP_PASSWORD=changeme
|
|
MEDIAPI_AP_CONN_NAME=mediapi-ap
|