# =============================================================================
# Kedebah Commerce deployment configuration.
# Copy to `.env` (cp .env.example .env) and fill every "change-me" value.
# This single file feeds docker-compose interpolation AND every container's
# runtime environment.
# =============================================================================

# Public domain (no scheme, no trailing slash)
DOMAIN=topup.kedebah.com

# Docker image tag for all built images
IMAGE_TAG=latest

# -----------------------------------------------------------------------------
# Application source repositories.
# Paths are relative to this deployment repository unless absolute paths are
# used. The defaults expect all repositories to be sibling directories.
# On the server, change these to wherever each existing checkout is located.
# -----------------------------------------------------------------------------
FINANCE_SOURCE=../kedebah_v2_finance
COMMERCE_SOURCE=../kedebah_v2_commerce_and_distribution
AUTH_SOURCE=../kedebah_v2_auth_api
ONBOARDING_SOURCE=../kedebah_v2_onboarding_api
TENANT_PROCESSOR_SOURCE=../kedebah_v2_tenant_processor
EMAIL_SOURCE=../kedebah_v2_email_api

# -----------------------------------------------------------------------------
# Database — the EXISTING PostgreSQL/PgBouncer on this host.
# From inside containers the host is reachable as host.docker.internal
# (mapped to host-gateway in docker-compose.yml). Point DB_PORT at PgBouncer.
# -----------------------------------------------------------------------------
DB_CONNECTION=pgsql
DB_HOST=host.docker.internal
DB_PORT=6432
DB_DATABASE=kedebah_v2
DB_USERNAME=kedebah
DB_PASSWORD="8kedeW!tmebah_v2nyPa.#wrM@sa"

# -----------------------------------------------------------------------------
# Redis (bundled container) — used for cache + sessions.
# -----------------------------------------------------------------------------
REDIS_HOST=redis
REDIS_PORT=6379
REDIS_PASSWORD=MYredisPassWord2012

# -----------------------------------------------------------------------------
# Inter-service caller credentials.
# Each key must match the `kedebah_services.key` row whose `name` is shown.
# The receiving API validates the (service_name, service_key) pair.
# -----------------------------------------------------------------------------
FINANCE_SERVICE_KEY=QJiauvlmWlCibNcSR8eg
AUTH_SERVICE_KEY=Twus5lQlCoMxhFprWlSv
ONBOARDING_SERVICE_KEY=QFXg7Qiz3p8Hd2w0YVPv
TENANT_PROCESSOR_SERVICE_KEY=kabxAX0sNM5XwEpXOFux

# Auth uses this when calling the Administrative API. Set it to the callback
# key expected there; it may equal AUTH_SERVICE_KEY if that is your setup.
AUTH_INTERNAL_CALLBACK_SERVICE_KEY=change-me-auth-callback-key

# -----------------------------------------------------------------------------
# Reverb (websockets). One shared app credential set.
# The browser (VITE_*, baked at build time) and the server both use APP_KEY,
# so keep them identical. APP_ID/SECRET are server-side only.
# -----------------------------------------------------------------------------
REVERB_APP_ID=kedebah
REVERB_APP_KEY=kedebah_reverb_8f4c9d7a2e6b1f5a9c3d7e8f0a2b4c6d
REVERB_APP_SECRET=9f7a3c8e2d6b5a1f4e8c0d9b7a2f6e3c5d8a1b9f4e7c2d6a0b5f8e3c1a9d7

# -----------------------------------------------------------------------------
# Mail (finance/email/onboarding notifications). Set MAIL_MAILER=smtp for prod.
# -----------------------------------------------------------------------------
MAIL_MAILER=smtp
MAIL_HOST=mail.kedebahlite.com
MAIL_PORT=587
MAIL_USERNAME=support@kedebahlite.com
MAIL_PASSWORD=oLOZ2cfgUGRrl0lF
MAIL_ENCRYPTION=tls
MAIL_FROM_ADDRESS=support@kedebahlite.com
MAIL_FROM_NAME=Kedebah

# -----------------------------------------------------------------------------
# AWS / S3 (optional — leave blank to use local disk).
# -----------------------------------------------------------------------------
AWS_ACCESS_KEY_ID=
AWS_SECRET_ACCESS_KEY=
AWS_DEFAULT_REGION=us-east-1
AWS_BUCKET=
AWS_USE_PATH_STYLE_ENDPOINT=false

# -----------------------------------------------------------------------------
# Tenant processor replica provisioning (optional).
# Only needed if you use read-replica provisioning; otherwise leave blank.
# -----------------------------------------------------------------------------
REPLICA_TEMPLATE_DATABASE=

# -----------------------------------------------------------------------------
# TLS / Let's Encrypt (used by bin/init-letsencrypt.sh + certbot service).
# -----------------------------------------------------------------------------
LETSENCRYPT_EMAIL=support@npontu.com

APP_KEY_FINANCE=base64:SmU+ctvDSOzVJ98B3LqTjprZp+r3x/6tq+l7O8oVu3k=
APP_KEY_COMMERCE=base64:O95QVhANB1DydaHmgi4rlj9NLgm2Ju+Vp6uBELy20+U=
APP_KEY_AUTH=base64:Y+X5xpmJhJGIXuZnis1un3morb4SJ71eivRHBmxhw4w=
APP_KEY_ONBOARDING=base64:rdjzNBBRywUdRqoo8j/qfc2y5sZwBGD1giQu5CotiwU=
APP_KEY_TENANT=base64:HB6kiQmerRKss+P7QoJCqmQ6rqdrNrEeqf01LE5j6XY=
APP_KEY_EMAIL=base64:TV6THkakCnBOWrzlqEJjm1At2jL6Tg51fyxViMCVNAo=
APP_KEY_SMS=base64:mj7bk4Em2sGV96YVOlVIrmTl4oFLobg/MTCJssMqx+I=

FINANCE_FPM_MAX_CHILDREN=200
COMMERCE_FPM_MAX_CHILDREN=200
AUTH_FPM_MAX_CHILDREN=32
ONBOARDING_FPM_MAX_CHILDREN=24
EMAIL_FPM_MAX_CHILDREN=16
TENANT_PROCESSOR_FPM_MAX_CHILDREN=24
REDIS_MAXMEMORY=2gb

SMS_GATEWAY_URL="https://deywuro.com/api/sms"
SMS_GATEWAY_USERNAME=npontutest
SMS_GATEWAY_PASSWORD=npontutest
SMS_GATEWAY_SOURCE=KEDEBAH

GRAFANA_ADMIN_USER=support@npontu.com
GRAFANA_ADMIN_PASSWORD="Ocean#4821"
TELEGRAM_BOT_TOKEN=7768447389:AAGEE3-OFiC6nphP8v3ipwYyzIQiBbjfW8w
TELEGRAM_CHAT_ID="-1003826557622"
