homelab/.env.example
Nik Afiq e6550d0e39 fix: rotate Gitea DB password and Dashy API key off plaintext, fix internal CA issuerRef
Stage 1 of REFACTOR_PLAN.md. values/gitea.yaml and config/dashy/conf.yaml now
reference secrets injected at apply-time (gitea-postgres-secret.sh, .env) instead
of hardcoding a live DB password and weather API key in git. Both values must be
treated as compromised and rotated by the operator (see .env.example).

Also fixes authentik-ingress.yaml and traefik-dashboard-ingress.yaml, which
pointed at the internal-ca root ClusterIssuer instead of internal-ca-issuer,
the chained issuer every other internal Certificate uses -- causing untrusted-cert
warnings on the SSO login and Traefik dashboard.

Extends .gitignore for *.retry, .vault_pass*, kubeconfig patterns, and editor
swap files.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-23 18:14:46 +09:00

48 lines
1.6 KiB
Plaintext

# Config for: Environment variables template
# Applied by: Copy to .env and fill in values; sourced by shell scripts
# Porkbun API credentials
PORKBUN_API_KEY=pk1_your_key_here
PORKBUN_SECRET_KEY=sk1_your_key_here
# K3s node token for agent join
K3S_NODE_TOKEN=your_token_here
# Gitea runner token for CI/CD
GITEA_RUNNER_TOKEN=your_token_here
# Grafana admin password
GRAFANA_ADMIN_PASSWORD=your_password_here
# Authentik secrets
AUTHENTIK_PROXY_TOKEN=your_token_here
AUTHENTIK_GITEA_CLIENT_ID=your_client_id_here
AUTHENTIK_GITEA_CLIENT_SECRET=your_client_secret_here
AUTHENTIK_GRAFANA_CLIENT_ID=your_client_id_here
AUTHENTIK_GRAFANA_CLIENT_SECRET=your_client_secret_here
AUTHENTIK_ARGOCD_CLIENT_ID=your_client_id_here
AUTHENTIK_ARGOCD_CLIENT_SECRET=your_client_secret_here
# Gitea container registry credentials
REGISTRY_SERVER=your_registry_server_here
REGISTRY_USER=your_username_here
REGISTRY_PASSWORD=your_token_here
# Home Assistant and Discord integration
HA_TOKEN=your_home_assistant_token_here
DISCORD_TOKEN=your_discord_token_here
GUILD_ID=your_discord_guild_id_here
SWITCHBOT_TOKEN=your_switchbot_token_here
SWITCHBOT_SECRET=your_switchbot_secret_here
# Immich database credentials
IMMICH_POSTGRES_PASSWORD=your_password_here
# Gitea database credentials (rotated off the plaintext value formerly in values/gitea.yaml)
GITEA_POSTGRES_PASSWORD=your_password_here
# Dashy weather widget API key (rotated off the plaintext value formerly in config/dashy/conf.yaml)
DASHY_WEATHER_API_KEY=your_api_key_here
PIA_USER=your_pia_username_here
PIA_PASSWORD=your_pia_password_here