Repository navigation
Expand file tree
/
Copy pathexample.env
More file actions
148 lines (116 loc) · 5.67 KB
/
Copy pathexample.env
File metadata and controls
148 lines (116 loc) · 5.67 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
# IMPORTANT: Values must not be wrapped in quotes. This file is passed through to the
# containers as is, and 'docker stack deploy' treats quotes as part of the value.
# The environment setting.
# Use 'development' for local development, and 'production' in production.
ENVIRONMENT=development
# The Docker image to use for the app services.
# Defaults to the official GHCR image. Override this to use a locally built image
# (e.g. ADIT_IMAGE=adit-staging:latest for a staging deployment).
# ADIT_IMAGE=ghcr.io/openradx/adit:latest
# Override the Docker Swarm stack name. Defaults to {project_name}_{environment}
# (e.g. adit_dev, adit_prod). Also used to derive unique session and CSRF cookie names
# to prevent cookie conflicts when running multiple stacks on the same host.
# Set explicitly for additional deployments like staging.
# STACK_NAME=adit_staging
# Ports that will be mapped to the host during development.
WEB_DEV_PORT=8000
POSTGRES_DEV_PORT=5432
# Ports that will be mapped to the host during production.
WEB_HTTP_PORT=80
WEB_HTTPS_PORT=443
RECEIVER_PORT=11112
# Django debug settings (only used in development).
FORCE_DEBUG_TOOLBAR=true
REMOTE_DEBUGGING_ENABLED=false
REMOTE_DEBUGGING_PORT=5678
# The Django secret key used for cryptographic signing.
# IMPORTANT: Use a unique and secure key in production!
DJANGO_SECRET_KEY=your_django_secret_key_here
# The Postgres database password (only used in production).
POSTGRES_PASSWORD=your_postgres_password_here
# Miscellaneous Django security settings.
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1
DJANGO_CSRF_TRUSTED_ORIGINS=
DJANGO_INTERNAL_IPS=127.0.0.1
# Redirect all HTTP requests to HTTPS (only used in production).
DJANGO_SECURE_SSL_REDIRECT=true
# The salt that is used for hashing tokens in the token authentication app.
# Cave, changing the salt after some tokens were already generated makes them all invalid!
TOKEN_AUTHENTICATION_SALT=your_token_authentication_salt_here
# Email configuration.
# The email address that is used for sending emails to the users and critical errors
# to the admins. The smtp server is only used in production. In development the emails
# are just logged to the console.
DJANGO_SERVER_EMAIL=server@example-project.example
DJANGO_EMAIL_URL=smtp://localhost:25
# The Django server admins that will receive critical error notifications.
# Also used by django-registration-redux to send account approval emails to.
DJANGO_ADMIN_EMAIL=admin@adit.example
DJANGO_ADMIN_FULL_NAME=ADIT Admin
# A support Email address that is presented to the users where they can get support.
SUPPORT_EMAIL=support@adit.example
# A superuser that will have access to the Django admin interface.
# Optionally with a provided auth token for the API.
SUPERUSER_USERNAME=superuser
SUPERUSER_EMAIL=superuser@adit.example
SUPERUSER_PASSWORD=your_superuser_password_here
SUPERUSER_AUTH_TOKEN=your_superuser_auth_token_here
# Location of the backup folder.
BACKUP_DIR=./.docker-data/backups
# Enable the daily database backup periodic task.
# Set to "false" to no-op the shared backup_db task (e.g. in test environments).
BACKUP_ENABLED=true
# Cron schedule for the shared backup_db periodic task.
BACKUP_CRON=0 3 * * *
# Site information that is synced to the database and used by the sites framework.
SITE_NAME=ADIT
SITE_DOMAIN=localhost
# Settings for SSL encryption (only used in production).
# SSL configuration settings for generating certificates.
# These variables are used to create a certificate key, self-signed certificate,
# and the corresponding certificate chain. If you have an existing certificate
# key and signed certificate from your CA, you can generate the corresponding
# certificate chain using 'uv run cli generate-certificate-chain'.
SSL_HOSTNAME=localhost
SSL_IP_ADDRESSES=127.0.0.1
SSL_SERVER_CERT_FILE=./cert.pem
SSL_SERVER_KEY_FILE=./key.pem
SSL_SERVER_CHAIN_FILE=./chain.pem
# The timezone used by the server.
TIME_ZONE=Europe/Berlin
# Seconds the web and worker containers wait for Postgres to accept connections
# before giving up on startup.
WAIT_POSTGRES_TIMEOUT=180
# The calling AE title of ADIT.
CALLING_AE_TITLE=ADIT1DEV
# The AE title where the receiver is listening for incoming files.
RECEIVER_AE_TITLE=ADIT1DEV
# A comma separated list of DICOM modalities that should be excluded when
# a study is transferred or downloaded pseudonymized using the web interface.
# This does not affect downloads using the ADIT client.
EXCLUDE_MODALITIES=PR,SR
# Replicas of the services that can be scaled (production).
WEB_REPLICAS=5
DICOM_WORKER_REPLICAS=3
MASS_TRANSFER_WORKER_REPLICAS=5
# Tasks whose worker stopped sending heartbeats for this many seconds are treated
# as abandoned and put back to pending. Never set below 30.
DICOM_TASK_STALLED_WORKER_GRACE_SECONDS=30
# How often the sweep for abandoned tasks runs (cron syntax, default every minute).
DICOM_TASK_SWEEP_CRON=* * * * *
# The directory where download folders are mounted.
MOUNT_DIR=./.docker-data/mount
# A seed that is used for anonymizing DICOM files on the client.
ANONYMIZATION_SEED=123456789
# Docker swarm mode does not respect the Docker Proxy client configuration
# (see https://docs.docker.com/network/proxy/#configure-the-docker-client),
# but we can set those environment variables manually.
# Malke sure to use .local in NO_PROXY as otherwise the communication with
# the other services will not work.
# HTTP_PROXY="http://user:pass@myproxy.net:8080"
# HTTPS_PROXY="http://user:pass@myproxy.net:8080"
# NO_PROXY="localhost,.local"
# OpenTelemetry Configuration
# Set this to the OTLP HTTP endpoint of the centralized openradx-observability stack.
# See https://github.com/openradx/openradx-observability for setup instructions.
OTEL_EXPORTER_OTLP_ENDPOINT=http://otel-collector.local:4318