refactor: move sessionSecret+passwordHash to env vars, seed data/ from defaults/

- SESSION_SECRET and PASSWORD_HASH moved out of config.json into env vars
- data.ts: AppConfig no longer holds secrets; loadConfig/loadData seed from
  defaults/ on first run if data/ files are missing
- auth.ts: requireAuth/authRequest read SESSION_SECRET from process.env directly
- login/+server.ts: reads PASSWORD_HASH and SESSION_SECRET from process.env
- defaults/config.json: ships with image (no secrets)
- defaults/units.json: ships with image as initial unit data
- package.json: add dotenv dep; start/serve load .env via -r dotenv/config
- Dockerfile: copy defaults/ into image; data/ is PVC-only
- .env.example: documents required env vars for local dev
- Remove k8s/ — managed externally
This commit is contained in:
Falkan
2026-03-19 23:54:37 -04:00
parent 5b89585505
commit 5480bb246c
11 changed files with 352 additions and 122 deletions

15
package-lock.json generated
View File

@@ -11,7 +11,8 @@
"@picocss/pico": "^2.1.1",
"bcryptjs": "^3.0.3",
"big.js": "^7.0.1",
"cookie": "^1.1.1"
"cookie": "^1.1.1",
"dotenv": "^16.4.7"
},
"devDependencies": {
"@sveltejs/adapter-node": "^5.5.4",
@@ -1430,6 +1431,18 @@
"dev": true,
"license": "MIT"
},
"node_modules/dotenv": {
"version": "16.6.1",
"resolved": "https://registry.npmjs.org/dotenv/-/dotenv-16.6.1.tgz",
"integrity": "sha512-uBq4egWHTcTt33a72vpSG0z3HnPuIl6NqYcTrKEg2azoEyl2hpW0zqlxysq2pK9HlDIHyHyakeYaYnSAwd8bow==",
"license": "BSD-2-Clause",
"engines": {
"node": ">=12"
},
"funding": {
"url": "https://dotenvx.com"
}
},
"node_modules/esbuild": {
"version": "0.27.4",
"resolved": "https://registry.npmjs.org/esbuild/-/esbuild-0.27.4.tgz",