-
Notifications
You must be signed in to change notification settings - Fork 8
Expand file tree
/
Copy path.env.example
More file actions
157 lines (143 loc) · 11.6 KB
/
Copy path.env.example
File metadata and controls
157 lines (143 loc) · 11.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
# CodeRunner V2 — Environment Configuration
#
# Copy this file to .env and edit as needed.
# All values shown are defaults. Uncomment and change only what you need.
#
# The control plane reads these on startup. Restart to apply changes.
# When deploying with docker compose, the same .env is read twice: compose
# interpolates the CODERUNNER_* values below into docker-compose*.yml, and the
# whole file is passed into the control container (env_file).
# ─── Docker compose deployment ───────────────────────────────────────
# CODERUNNER_TAG=latest # Image tag to run (release tag like v2.5.0, or latest)
# CODERUNNER_IMAGE_NS=ghcr.io/mathewdunne
# # Registry + owner for both coderunner images. Forks
# # publishing their own images set this once; it is read
# # by compose, the image build/pull script, and the
# # control plane's CODE_IMAGE default.
# CODERUNNER_HOST_DATA_DIR= # HOST path of the data bind mount (default: ./data
# # in the checkout). Set to relocate the data dir
# # onto a mounted disk. Compose resolves ./ against
# # the project directory.
# COMPOSE_FILE=docker-compose.yml:docker-compose.prod.yml
# # Production VM only: select the prod stack
# # (Caddy + Alloy) without -f flags.
# ─── Server ──────────────────────────────────────────────────────────
# PORT=4000 # HTTP/WS listen port
# ─── Paths ───────────────────────────────────────────────────────────
# Leave this whole section unset when deploying with docker compose — the
# image fixes the in-container paths (/data, /app/...) and overriding them
# here would break the container.
# FRC_DATA_DIR=data # Runtime data root (users, DB, logs)
# FRC_DB_PATH=data/app.db # SQLite database file
# FRC_MIGRATIONS_DIR= # DB migration files (default: auto-detected)
# FRC_WEB_DIST_DIR=apps/web/dist # Built web shell assets
# FRC_ASCOPE_DIST_DIR=dist/advantagescope # Built AdvantageScope Lite assets
# ─── Lessons catalog ─────────────────────────────────────────────────
# Unset LESSONS_CATALOG_REPO → zero-config bundled catalog (in-repo `catalog/`).
# Set it to use a remote public lessons repo (no image rebuild to edit lessons).
# LESSONS_CATALOG_REPO=mathewdunne/coderunner-lessons # owner/repo or full https URL
# LESSONS_CATALOG_BRANCH=main # remote lessons repo branch
# LESSONS_CATALOG_DIR=catalog # bundled catalog path (baked into the image at /opt/frc-catalog)
# ─── OAuth / Better Auth ──────────────────────────────────────────────
# BETTER_AUTH_SECRET=<random string> # CHANGE THIS in production deployments!
# BETTER_AUTH_URL=http://localhost:4000 # Base URL for OAuth callbacks
# GITHUB_CLIENT_ID= # GitHub OAuth app client ID
# GITHUB_CLIENT_SECRET= # GitHub OAuth app client secret
# GOOGLE_CLIENT_ID= # Google OAuth client ID
# GOOGLE_CLIENT_SECRET= # Google OAuth client secret
#
# At least one OAuth provider must be configured for login to work.
# Register apps at your provider and set the callback URL:
# GitHub: ${BETTER_AUTH_URL}/api/auth/callback/github
# Google: ${BETTER_AUTH_URL}/api/auth/callback/google
#
# CODERUNNER_ADMIN_EMAIL= # Comma-separated emails that bootstrap admin
# # access. Each is added to the allowlist at
# # startup and granted the admin role on first
# # sign-in; an existing account with that email
# # is promoted to admin at startup. Lets a fresh
# # deployment reach the admin panel with no exec
# # steps. e.g. coach@frcteam.org,asst@frcteam.org
# ─── Docker ──────────────────────────────────────────────────────────
# The three CODERUNNER_* vars below govern the CONTROL container itself
# (compose interpolates them into docker-compose.yml), distinct from the FRC_*
# vars further down which govern the workspace siblings. Leave them at the
# defaults on a single-user host where the first user (uid 1000) owns ./data.
# CODERUNNER_UID=1000 # uid the control container runs as; should
# CODERUNNER_GID=1000 # own CODERUNNER_HOST_DATA_DIR so ./data
# # stays host-owned (no root-owned files).
# CODERUNNER_DOCKER_GID=0 # gid owning the bind-mounted Docker socket,
# # added as a supplementary group so the
# # non-root process can reach it. The 0
# # default is right for Docker Desktop on
# # macOS and native Windows, whose socket is
# # root-owned — leave it unset there. On
# # Linux and WSL2 (WSL2 integration included)
# # the socket belongs to the `docker` group
# # instead, so set this:
# # stat -c '%g' /var/run/docker.sock
# # (stock Debian/Ubuntu often 999/998).
# FRC_DOCKER_PATH=docker # Path to the docker binary
# In a containerized deployment the control plane inspects its own container at
# startup to auto-detect the three settings below (the data-dir owner, the
# workspace network, and the host data path). Set them only to override that
# detection for an unusual setup.
# FRC_CONTAINER_USER= # UID:GID workspace containers run as. On a host
# # dev run, auto-detected from the current user; in a
# # container, derived from the data dir's owner.
# # Also accepts FRC_UID + FRC_GID separately.
# FRC_CONTAINER_AUTO_START=true # Auto-start containers when workspace opens
# FRC_CONTAINER_NETWORK= # Docker network workspace containers join instead of
# # publishing loopback host ports (containerized control
# # plane). Auto-detected from the control plane's own
# # network attachment; leave unset for host/dev runs.
# FRC_HOST_DATA_DIR= # Host-side path of FRC_DATA_DIR for bind-mount
# # translation when the control plane runs in a
# # container. Auto-detected from the container's mounts.
# ─── Code Container (merged sim + editor) ────────────────────────────
# CODE_IMAGE=ghcr.io/mathewdunne/coderunner-workspace:latest
# # Docker image for merged code containers. Defaults to
# # ${CODERUNNER_IMAGE_NS}/coderunner-workspace:${CODERUNNER_TAG}.
# CODE_MEMORY_LIMIT=4096m # Memory cap per code container
# CODE_DISK_READ_LIMIT=64mb # Per-device disk read cap (--device-read-bps);
# # containerized deployments only. 0 disables.
# SIM_PORT_RANGE=25810-25899 # Loopback port range for sim NT4
# VSCODE_PORT_RANGE=33000-33099 # Loopback port range for codium-server
# HALSIM_PORT_RANGE=34000-34099 # Loopback port range for the HALSim bridge
# ─── Capacity ────────────────────────────────────────────────────────
# MAX_ACTIVE_CONTAINERS=10 # Max simultaneously-running student containers
# ─── Run Lifecycle ───────────────────────────────────────────────────
# RUN_BUILD_TIMEOUT_MS=90000 # Gradle build timeout (ms)
# SIM_STARTUP_TIMEOUT_MS=30000 # Sim readiness timeout after build (ms)
# ─── Idle Management ─────────────────────────────────────────────────
# IDLE_STOP_MINUTES=30 # Stop containers after N minutes idle
# IDLE_CHECK_INTERVAL_MS=60000 # How often to sweep for idle workspaces (ms)
# ─── Admin ───────────────────────────────────────────────────────────
# ADMIN_TOKEN= # Bearer token for /admin/* endpoints.
# # Optional break-glass bootstrap token.
# # If unset, admin routes require an admin user session.
# METRICS_TOKEN= # Bearer token for scraping GET /metrics.
# # If unset, /metrics requires an admin session instead.
# ─── Demo Mode ───────────────────────────────────────────────────────
# CODERUNNER_DEMO_MODE=false # Single-admin demo mode. NOT safe to expose publicly.
# ─── Logging ─────────────────────────────────────────────────────────
# LOG_LEVEL=debug # trace|debug|info|warning|error|fatal
# # Controls control-plane log verbosity.
# # Defaults to "warning" when NODE_ENV=test, "debug" otherwise.
# LOG_FORMAT=text # text|json
# # "text" = colored/human-readable for local dev (default).
# # "json" = NDJSON for log shipping (Grafana Cloud Loki via Alloy).
# # Production sets json via deploy/cloud-init/user-data.yaml.
# ─── Resource Sizing Guide ───────────────────────────────────────────
#
# Each active student uses ~2.5 GB (code container with sim + editor).
# Recommended host sizing:
#
# Students RAM CPU cores Notes
# ──────── ─────── ───────── ─────
# 3-5 16 GB 4+ Conservative memory limit
# 6-10 32 GB 6+ Preferred for full classroom
# 10+ 48+ GB 8+ Raise CODE_MEMORY_LIMIT if GC pressure
#
# If RAM is tight, lower CODE_MEMORY_LIMIT to 2048m.
# See docs/operating/monitoring.md and docs/operating/capacity.md for host sizing.