# ============================================================ # Coolify Environment Variables — ClinicPro (Docker Compose) # ------------------------------------------------------------ # Copy these into the Coolify resource's "Environment Variables" tab. # Only the variables referenced as ${...} in docker-compose.yml need to be set. # # MariaDB and Redis are SEPARATE Coolify Database Resources (not in the compose). # So DATABASE_URL / REDIS_URL / MESSENGER_TRANSPORT_DSN must be set HERE, pointing # at those resources by their internal hostname (mariadb- / redis-). # Steps: # 1. Create a standalone MariaDB 11.8 resource + a standalone Redis resource. # 2. Enable "Connect to Predefined Network" on this app stack. # 3. Copy each resource's internal hostname/credentials into the URLs below. # ============================================================ # ── Database / Redis connections (point at the SEPARATE Coolify resources) ── # Replace mariadb-XXXXXXXX / redis-XXXXXXXX with the real hostname shown on each # resource's page (Internal URL). serverVersion MUST match the MariaDB resource (11.8). DATABASE_URL="mysql://clinic:DB_PASSWORD@mariadb-XXXXXXXX:3306/clinic_pro?serverVersion=mariadb-11.8.0&charset=utf8mb4" REDIS_URL="redis://redis-XXXXXXXX:6379" MESSENGER_TRANSPORT_DSN="redis://redis-XXXXXXXX:6379/messages" # If the Redis resource has a password: redis://:PASSWORD@redis-XXXXXXXX:6379 # ── Backend's own domain (single URL — used for payment callbacks & absolute URLs) ── # This is the API host, NOT a frontend domain. APP_BASE_URL=https://api.nobat724.com # ── Frontend domains (MANY) ── # Both values below are GENERATED from docker/frontend-domains.json. # To add/remove a city domain: edit that file, then run: # ddev exec php docker/gen-cors-env.php (or: php docker/gen-cors-env.php on the server) # and paste the new output here / into Coolify. ALLOWED_FRONTEND_HOSTS=ahvaz-nobat.ir,arak-nobat.ir,ardabil-nobat.ir,bandar-nobat.ir,behbahan-nobat.ir,birjand-nobat.ir,bojnord-nobat.ir,bushehr-nobat.ir,dehdasht-nobat.ir,esf-nobat.ir,golestan-nobat.ir,hamadan-nobat.ir,ilam-nobat.ir,karaj-nobat.ir,kerman-nobat.ir,kermanshah-nobat.ir,lorestan-nobat.ir,mashhad-nobat.ir,nobat724.com,qazvin-nobat.ir,qom-nobat.ir,rasht-nobat.ir,sanandaj-nobat.ir,sari-nobat.ir,semnan-nobat.ir,shiraz-nobat.ir,shkord-nobat.ir,tabriz-nobat.ir,tehran-nobat.ir,urmia-nobat.ir,yasuj-nobat.ir,yazd-nobat.ir,zahedan-nobat.ir,zanjan-nobat.ir CORS_ALLOW_ORIGIN='^https://(ahvaz\-nobat\.ir|arak\-nobat\.ir|ardabil\-nobat\.ir|bandar\-nobat\.ir|behbahan\-nobat\.ir|birjand\-nobat\.ir|bojnord\-nobat\.ir|bushehr\-nobat\.ir|dehdasht\-nobat\.ir|esf\-nobat\.ir|golestan\-nobat\.ir|hamadan\-nobat\.ir|ilam\-nobat\.ir|karaj\-nobat\.ir|kerman\-nobat\.ir|kermanshah\-nobat\.ir|lorestan\-nobat\.ir|mashhad\-nobat\.ir|nobat724\.com|qazvin\-nobat\.ir|qom\-nobat\.ir|rasht\-nobat\.ir|sanandaj\-nobat\.ir|sari\-nobat\.ir|semnan\-nobat\.ir|shiraz\-nobat\.ir|shkord\-nobat\.ir|tabriz\-nobat\.ir|tehran\-nobat\.ir|urmia\-nobat\.ir|yasuj\-nobat\.ir|yazd\-nobat\.ir|zahedan\-nobat\.ir|zanjan\-nobat\.ir)$' # ── Secrets (REQUIRED — set before the first deploy) ── APP_SECRET= # php -r "echo bin2hex(random_bytes(32));" JWT_PASSPHRASE= # openssl rand -hex 32 (must exist before first start: JWT keypair is generated with it) # NOTE: DB_PASSWORD / DB_ROOT_PASSWORD are NO LONGER set here. The DB credentials # now belong to the standalone MariaDB resource — set them when you create that # resource, then embed the user password inside DATABASE_URL above. # Tip: in Coolify you may use magic vars instead of hardcoding, e.g. # APP_SECRET=${SERVICE_HEX_APPSECRET} # ── Reverse proxy (Coolify/Traefik) ── # Docker internal network ranges so Symfony trusts X-Forwarded-* headers. TRUSTED_PROXIES=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1 # ── api.ir identity inquiry (Shahkar + IbanMatch) ── # Empty token => fail-closed (representative verification is rejected). API_IR_BASE_URL=https://s.api.ir API_IR_TOKEN= # ── SMS ── # Kavenegar API key is read ONLY from this env (not the DB). KAVENEGAR_API_KEY= # ── Notes ── # • Payment gateway keys (mellat/sep) are read from the DB ("Site Settings"), NOT from env. # • REFRESH_TOKEN_TTL / OTP_TTL / MAX_FILE_SIZE_BYTES are fixed in the compose file. # • MariaDB & Redis are separate Coolify resources — see DATABASE_URL/REDIS_URL above. APP_ENV=prod APP_DEBUG=0 APP_SECRET=... JWT_PASSPHRASE=... JWT_SECRET_KEY=%kernel.project_dir%/config/jwt/private.pem JWT_PUBLIC_KEY=%kernel.project_dir%/config/jwt/public.pem TRUSTED_PROXIES=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,127.0.0.1 ALLOWED_FRONTEND_HOSTS=... # همان خروجی gen-cors-env.php CORS_ALLOW_ORIGIN=... # همان API_IR_BASE_URL=https://s.api.ir API_IR_TOKEN=... REFRESH_TOKEN_TTL / OTP_TTL / MAX_FILE_SIZE_BYTES / UPLOAD_DIR