# Copy to .env.production in the project root. Never commit real credentials. # Replace the domain, database connection and initial admin password before startup. NODE_ENV=production DATABASE_URL="mysql://USER:URL_ENCODED_PASSWORD@MYSQL_HOST:3306/worthpath" ADMIN_USERNAME=admin ADMIN_PASSWORD=REPLACE_WITH_A_STRONG_INITIAL_PASSWORD API_HOST=0.0.0.0 PORT=3100 # Container path; Compose binds /opt/worthpath/data/icons on the host here. ICON_STORAGE_DIR=/app/data/icons API_ALLOWED_HOSTS=worthpath.example.com WEB_ORIGIN=https://worthpath.example.com MCP_PUBLIC_URL=https://worthpath.example.com/mcp MCP_WEB_URL=https://worthpath.example.com MCP_ALLOWED_HOSTS=worthpath.example.com MCP_ALLOWED_ORIGINS=https://worthpath.example.com MCP_ALLOW_LOOPBACK_HOSTS=false NETWORK_ALLOW_HTTP=false NETWORK_ALLOW_HTTP_REDIRECTS=false NETWORK_ALLOW_WILDCARD_ORIGINS=false NETWORK_REQUIRE_SECURE_COOKIE=true NETWORK_HSTS=true NETWORK_UPGRADE_INSECURE_REQUESTS=true NETWORK_RATE_LIMIT_ENABLED=true COOKIE_SECURE=true COOKIE_SAME_SITE=strict