Skip to main content

Configuration

All configuration is done via environment variables. Copy .env.dist to .env and adjust values.

Required Variables​

VariableDescriptionHow to Generate
DATABASE_URLPostgreSQL connection stringAuto-composed from DB_* variables
DB_HOSTDatabase hostlocalhost for local development
DB_PORTDatabase port5432 (default)
DB_USERNAMEDatabase userdutyduke (default)
DB_PASSWORDDatabase passwordSet your own
DB_NAMEDatabase namedutyduke (default)
PRISMA_FIELD_ENCRYPTION_KEYEncryption key for sensitive fieldsGenerate at https://cloak.47ng.com/
JWT_SECRETSecret for signing JWT tokensnode -e "console.log(require('crypto').randomBytes(128).toString('hex'))"
NEXT_PUBLIC_APP_URLApplication URLhttp://localhost:3000 for development

Organization​

VariableDescriptionDefault
ORGANIZATION_NAMECompany name (used in seeding)"My Company"
ORGANIZATION_TAX_IDCompany tax IDEmpty

Application​

VariableDescriptionDefault
NEXT_PUBLIC_THEMEUI theme class applied to <body>hris
NEXT_PUBLIC_DEFAULT_LANGUAGEDefault localeen
ITEMS_PER_PAGEPagination page size20
HOMEPAGECustom homepage URLEmpty

Email (SMTP)​

VariableDescriptionDefault
mailer_smtp_hostSMTP server hostlocalhost
mailer_smtp_portSMTP server port1025 (Mailcatcher)
mailer_smtp_isSecureUse TLSfalse
mailer_smtp_userSMTP usernameuser
mailer_smtp_passwordSMTP passwordpassword
mailer_email_fromSender address"DutyDuke Admin <admin@localhost>"

For production, point these to your actual SMTP provider (e.g., Amazon SES, SendGrid, Mailgun).

Notifications Service (Optional)​

VariableDescriptionDefault
USE_NOTIFICATIONS_SERVICEEnable external notificationsfalse
NOTIFICATIONS_SERVICE_URLNotifications API URLhttp://localhost:3001/api/notifications
NOTIFICATIONS_SERVICE_APPLICATION_NAMEApp name for notificationsDutyDuke
NOTIFICATIONS_SERVICE_APPLICATION_TOKENAuth token for notificationsEmpty

Other​

VariableDescriptionDefault
SUPPORT_PASSWORDSupport account passwordSet your own
SUGGESTIONS_SLOT_COUNTNumber of suggestion slots3
NEXT_PUBLIC_MAP_TILES_URLMap tile server URLtiles_url

Security Notes​

  • Never commit .env to version control (it's in .gitignore)
  • Always generate unique values for JWT_SECRET and PRISMA_FIELD_ENCRYPTION_KEY per environment
  • Use strong passwords in production
  • Set mailer_smtp_isSecure=true in production with proper TLS certificates