# ------------------------------------------------------------------
# Documenos docker-compose environment file
#
# IMPORTANT: Replace the placeholder values below with your own strong,
# unique secrets BEFORE running "docker compose up -d".
# Do not reuse these placeholder values in production.
# ------------------------------------------------------------------

# --- DOCKER HUB CONFIG ---
IMAGE_TAG=7.74

# --- SECURITY & NETWORK ---
# 127.0.0.1 = Local Only
# 0.0.0.0 = Public
DB_BIND_IP=127.0.0.1
SEARCH_BIND_IP=127.0.0.1
SIGNER_BIND_IP=127.0.0.1
TRANSLATE_BIND_IP=127.0.0.1
APP_BIND_IP=0.0.0.0

# --- PORT CONFIG ---
DB_PORT=5433
SIGNER_PORT=5001
ES_PORT=9201
TRANSLATE_PORT=5002
APP_PORT=8080

# --- DATABASE CONFIG ---
DB_USER=postgres
DB_PASSWORD=123456AaAa

# --- SEARCH CONFIG ---
ELASTIC_VERSION=9.2.3
ES_MEM_LIMIT=512m

# --- TRANSLATION CONFIG ---
LIBRETRANSLATE_VERSION=v1.9.6

# Languages LibreTranslate loads. The ten Documenos locales.
# Trim this list to shrink the first-start download; every entry costs disk and RAM.
# NOTE: this flag does not REMOVE models already present in the volume, it only
# controls which ones are installed and served.
TRANSLATE_LOAD_ONLY=ar,de,en,es,fi,fr,it,ru,sv,tr

# Grace period given to LibreTranslate on its very first start, while it
# downloads the models listed above. During this window failed health checks
# do not mark the container unhealthy, and "docker compose up -d" waits here.
# With the ten locales above expect roughly 5-10 minutes on a normal
# connection. Increase it if your server has a slow link or you load more
# languages; the value is only an upper bound, startup is not delayed by it.
TRANSLATE_START_PERIOD=900s

# --- APPLICATION SECRETS ---
GOOGLE_CLIENT_ID=get_your_google_id
GOOGLE_CLIENT_SECRET=get_your_google_secret

MS_CLIENT_ID=get_your_ms_id
MS_CLIENT_SECRET=get_your_ms_secret
MS_TENANT_ID=common

# --- APP SETTINGS ---
DEFAULT_PWD=Documenos123

AI_SERVICE_URL=http://documenos_ai:5000
SIGNATURE_SERVICE_URL=http://documenos_signer:8080
TRANSLATE_SERVICE_URL=http://documenos_translate:5000
WHISPER_MODEL=whisper-large-v1.bin

# Leave empty if there is no load balancer / reverse proxy.
# Example: X-Forwarded-For
CLIENT_IP_HEADER=

# --- FACE RECOGNITION ---
# Minimum similarity percentage required for a face match.
# 100 = identical face, 0 = unrelated.
FACE_RECOGNITION_MINIMUM_SIMILARITY_PERCENT=90

# --- MOBILE RATE LIMIT ---
# Maximum number of requests allowed from one device
# within the configured time window.
RATE_LIMIT_MOBILE_PERMIT_LIMIT=30
RATE_LIMIT_MOBILE_WINDOW_SECONDS=60

# --- IDENTITY / USERNAME POLICY ---
# Allowed username characters.
# Empty value means all characters are allowed.
IDENTITY_ALLOWED_USERNAME_CHARACTERS=abcdefghijklmnopqrstuvwxyz0123456789-_.

# --- IDENTITY / EMAIL POLICY ---
IDENTITY_REQUIRE_UNIQUE_EMAIL=true

# --- IDENTITY / PASSWORD POLICY ---
IDENTITY_PASSWORD_REQUIRE_DIGIT=true
IDENTITY_PASSWORD_REQUIRE_LOWERCASE=true
IDENTITY_PASSWORD_REQUIRE_UPPERCASE=true
IDENTITY_PASSWORD_REQUIRE_NON_ALPHANUMERIC=false

# Minimum password length.
IDENTITY_PASSWORD_REQUIRED_LENGTH=4

# --- IDENTITY / LOCKOUT POLICY ---
IDENTITY_LOCKOUT_MAX_FAILED_ATTEMPTS=5
IDENTITY_LOCKOUT_MINUTES=5
IDENTITY_LOCKOUT_ALLOWED_FOR_NEW_USERS=true

# --- DATA PROTECTION ---
KEYS_PATH=/usr/share/documenos/data

# --- VOLUMES ---
DB_VOLUME_NAME=documenos_database
SEARCH_VOLUME_NAME=documenos_search
TRANSLATE_VOLUME_NAME=documenos_translate
DATA_VOLUME_NAME=documenos_data
