Files
omar ffc462cf28 Build in detached worktrees and advance pins only after the fence
- update.py builds target commits in temporary detached worktrees with
  temporary image tags; checkouts and runtime tags move only after the API
  fence and quiescence check pass, so refused/build-only runs keep
  --verify-only passing.
- Activation includes the execution profile (worker/watchdog restart under
  the fence) and verifies every service container runs the built image
  before writing approved-commits.env.
- Compose: bounded local logging, API healthcheck via `otche healthcheck`,
  web healthcheck and healthy API dependency, env-driven worker limits.
- TLS example: request-time upstream resolution, gzip, immutable assets,
  headers not duplicated on /api.
- README: new update flow, sizing for parallel runs, fenced backup and
  restore drill.
2026-09-24 17:55:13 +03:00

15 lines
509 B
Bash

# Copy to .env; no credentials belong here.
# Local development: http://localhost:8088 + ALLOW_INSECURE_HTTP=true.
# Production: exact public HTTPS origin, Secure cookies remain required.
PUBLIC_ORIGIN=https://otche.example.invalid
ALLOW_INSECURE_HTTP=false
BIND_ADDRESS=127.0.0.1
WEB_PORT=8088
MAX_UPLOAD_BYTES=536870912
MAX_OWNER_BYTES=8589934592
MAX_QUEUED_JOBS=20
# Worker/FFmpeg container limits; size separately from Windows guest resources.
WORKER_CPUS=2.0
WORKER_MEM_LIMIT=1536m
WORKER_PIDS_LIMIT=128