-
Notifications
You must be signed in to change notification settings - Fork 3
Expand file tree
/
Copy path.env.example
More file actions
80 lines (64 loc) · 2.5 KB
/
Copy path.env.example
File metadata and controls
80 lines (64 loc) · 2.5 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
# OpenRisk Environment Configuration
# Copy this file to .env and fill in the values
# ==================== DATABASE ====================
# No default password (#485). Generate one: openssl rand -hex 24
DB_HOST=localhost
DB_PORT=5434
DB_USER=openrisk
DB_PASSWORD=
DB_NAME=openrisk
# DATABASE_URL=postgres://openrisk:<DB_PASSWORD>@localhost:5434/openrisk
# First administrator. Empty = generated on first boot into
# INITIAL_ADMIN_PASSWORD_FILE (default secrets/initial_admin_password, 0600).
INITIAL_ADMIN_PASSWORD=
# ==================== API ====================
PORT=8080
APP_ENV=development
# ==================== JWT CONFIGURATION ====================
# JWT RS256 Configuration (requires RSA key pair - see scripts/generate_rsa_keys.sh)
RSA_PRIVATE_KEY_PATH=./backend/keys/private_key.pem
RSA_PUBLIC_KEY_PATH=./backend/keys/public_key.pem
# Fallback to inline keys if paths not set (for CI/CD)
# RSA_PRIVATE_KEY=<PEM-formatted private key>
# RSA_PUBLIC_KEY=<PEM-formatted public key>
# JWT Token TTLs
JWT_ACCESS_TTL=15m
JWT_REFRESH_TTL=168h
# ==================== EMAIL (for invitations) ====================
SMTP_HOST=smtp.brevo.com
SMTP_PORT=587
SMTP_USER=your-brevo-username
SMTP_PASS=your-brevo-password
SMTP_FROM=noreply@openrisk.io
# ==================== APP URL (for invitation links) ====================
APP_URL=http://localhost:3000
# ==================== INVITATION ====================
INVITATION_TTL_HOURS=72
# ==================== PERMISSIONS CACHE ====================
PERMISSIONS_CACHE_TTL=5m
# ==================== CORS ====================
CORS_ORIGINS=http://localhost:5173,http://localhost:3000
# ==================== INTEGRATIONS ====================
# TheHive
THEHIVE_URL=http://localhost:9000
THEHIVE_API_KEY=your-api-key
# OpenCTI
OPENCTI_URL=http://localhost:3000
OPENCTI_TOKEN=your-api-token
# ==================== FEATURES ====================
FEATURE_WEBHOOKS=true
FEATURE_SYNC_ENGINE=true
FEATURE_GAMIFICATION=true
# ==================== LOGGING ====================
LOG_LEVEL=info
LOG_FORMAT=json
# ==================== REDIS ====================
REDIS_URL=redis://localhost:6379/0
# ==================== STORAGE ====================
# Only "local" exists today; an S3-backed driver can be added later behind
# the same storage.Storage interface (see backend/pkg/storage).
STORAGE_DRIVER=local
STORAGE_LOCAL_PATH=./uploads
# Org roles that MUST enrol MFA before holding a session (comma-separated).
# Default admin,root. Empty string disables mandatory MFA enrolment entirely.
MFA_REQUIRED_ROLES=admin,root