Files
homelabstack/stacks/resume/stack.env
T
ginnoirandClaude Opus 5 fb0b692f83 fix(resume): add ENCRYPTION_SECRET + redis so the AI tab loads
The v5 rewrite gates AI features behind two new env vars we never had.
Opening the AI Integrations tab calls aiProviders.list, which runs
assertCredentialEncryptionConfigured() and throws
AI_CREDENTIAL_ENCRYPTION_UNAVAILABLE when ENCRYPTION_SECRET is unset --
so the tab errored on mount instead of rendering.

The agent workspace has a second gate: isAgentEnvironmentConfigured()
requires ENCRYPTION_SECRET *and* REDIS_URL, so add a dedicated redis to
the stack rather than leaving the agent half-broken. Every other redis
on the host is on another stack's private network.

ENCRYPTION_SECRET encrypts stored provider API keys at rest (schema
requires >=32 chars); rotating it makes saved keys undecryptable, so
it is pinned like AUTH_SECRET.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-25 15:27:27 -05:00

39 lines
2.1 KiB
Bash

# resume stack secrets — injected into all services via env_file.
# Var names are exactly what each container reads (no ${VAR} interpolation).
# Components are duplicated into composites (DATABASE_URL embeds
# POSTGRES_PASSWORD; STORAGE_* mirror MINIO_*) — keep them in sync on rotation.
# postgres
POSTGRES_PASSWORD=postgres
# minio (resume-minio service)
MINIO_ROOT_USER=minioadmin
MINIO_ROOT_PASSWORD=minioadmin
MINIO_OIDC_CLIENT_ID=1jC2ChsCjdh7srOKtr9Jzv1l2RF8omrzshEpAESa
MINIO_IDENTITY_OPENID_CLIENT_ID=1jC2ChsCjdh7srOKtr9Jzv1l2RF8omrzshEpAESa
MINIO_OIDC_CLIENT_SECRET=66KML3RcsdcStPO6FIe04cCRyLTztfUDdHcpkIVImUO6WTTHkAFtao4GfZYu9yq4NvFGWxztTv7M8uGZBi4xaVUtJr3K3GU47pLaaWwF1WMsidsRTy760QUJxsUq3i9C
MINIO_IDENTITY_OPENID_CLIENT_SECRET=66KML3RcsdcStPO6FIe04cCRyLTztfUDdHcpkIVImUO6WTTHkAFtao4GfZYu9yq4NvFGWxztTv7M8uGZBi4xaVUtJr3K3GU47pLaaWwF1WMsidsRTy760QUJxsUq3i9C
# browserless chrome auth token (chrome reads TOKEN, the app reads PRINTER_TOKEN)
TOKEN=chrome_token
PRINTER_TOKEN=chrome_token
# reactive-resume app
DATABASE_URL=postgresql://postgres:postgres@postgres:5432/postgres
STORAGE_ACCESS_KEY=minioadmin
STORAGE_SECRET_KEY=minioadmin
# Auth/JWT signing secret for Reactive Resume.
# Pinned to the running value so recreating the container keeps sessions valid.
# Rotate with: openssl rand -hex 64
AUTH_SECRET=1b7e96f61f080d04d4bf673d9ea1d9349eb7693cddee5772b6c3f153c88032db5b97efd8570087bc6f340d2cd874aabc1e5c681bc22889921240d6a23738bc7f
OAUTH_CLIENT_ID=YpMFNp9q5mGbN8ADM5rUol0ERHmSiTDClJKIVOxK
OAUTH_CLIENT_SECRET=mzwjSt0Xtibo156km61T7VYerT48K6ZTa79cEek4mgdky6t1Sjaddlshw2QcJL8727N6qWzddi2ihxNGSpUVMXUBbjNgx4jtkHAy5xtmvqdk9ouIFclyhCgXh9fzjMCA
# AI features (v5). ENCRYPTION_SECRET encrypts stored AI provider API keys at
# rest (schema requires >=32 chars); without it the AI Integrations tab throws
# AI_CREDENTIAL_ENCRYPTION_UNAVAILABLE. Rotating it makes every saved provider
# key undecryptable, so pin it like AUTH_SECRET. Generate: openssl rand -hex 32
# REDIS_URL is additionally required by the AI agent workspace (streaming).
ENCRYPTION_SECRET=2310384c2befea91af4bb6cdc5dc0eea2b1e492c0ac61003b64356abecad7a61
REDIS_URL=redis://redis_resume:6379