Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 12 additions & 0 deletions .env.example
Original file line number Diff line number Diff line change
Expand Up @@ -452,6 +452,18 @@ HEALTH_READY_SUCCESS_THRESHOLD=2
HEALTH_EVENT_LOOP_MAX_LAG_MS=1000
# Soroban RPC endpoints for the quorum check (default: SOROBAN_RPC_URL).
SOROBAN_RPC_HEALTH_URLS=
# JSON map of EVM chain name to HTTPS JSON-RPC URL for admin token verification.
# Example: {"ethereum":"https://ethereum.example/rpc","base":"https://base.example/rpc"}
EVM_RPC_URLS={}
# Public anonymised datasets (RFC 0001). Disabled until an operator opts in.
DATASETS_ENABLED=false
DATASETS_ANONYMIZE=true
DATASETS_SALT=
DATASETS_SALT_ROTATION_HOURS=24
DATASETS_SALT_RETENTION_WINDOWS=2
DATASETS_PUBLIC_BUCKET=vortex-public-datasets
DATASETS_STORAGE_KIND=memory
DATASETS_LOCAL_DIR=./data/datasets

# ─── Intents store (issue #404) ──────────────────────────────────────────────
# memory | dual | postgres — supersedes INTENTS_PERSISTENCE above.
Expand Down
1 change: 0 additions & 1 deletion .env.mainnet.example
Original file line number Diff line number Diff line change
Expand Up @@ -324,7 +324,6 @@ HEALTH_READY_SUCCESS_THRESHOLD=2
HEALTH_EVENT_LOOP_MAX_LAG_MS=1000
# Soroban RPC endpoints for the quorum check (default: SOROBAN_RPC_URL).
SOROBAN_RPC_HEALTH_URLS=

# ─── Persistence ─────────────────────────────────────────────────────────────
# REQUIRED: production must not lose intents on restart. Promote through
# memory → dual → postgres per docs/runbooks/intents-store-migration.md.
Expand Down
1 change: 0 additions & 1 deletion .env.staging.example
Original file line number Diff line number Diff line change
Expand Up @@ -211,7 +211,6 @@ HEALTH_READY_SUCCESS_THRESHOLD=2
HEALTH_EVENT_LOOP_MAX_LAG_MS=1000
# Soroban RPC endpoints for the quorum check (default: SOROBAN_RPC_URL).
SOROBAN_RPC_HEALTH_URLS=

# Staging runs the dual-write phase so the consistency verifier can soak
# before production moves to postgres (docs/runbooks/intents-store-migration.md).
INTENTS_STORE=dual
Expand Down
198 changes: 0 additions & 198 deletions .env.testnet.example
Original file line number Diff line number Diff line change
@@ -1,198 +0,0 @@
# .env.testnet.example
#
# Environment template for LOCAL DEVELOPMENT against Stellar TESTNET.
# Copy to .env and fill in any values marked with <CHANGE_ME>.
#
# cp .env.testnet.example .env
#
# Testnet is safe to experiment with — tokens have no real value and contract
# deployments are free via Friendbot. Never reuse testnet keys on mainnet.
#
# Closes #136

# ─── Database ────────────────────────────────────────────────────────────────
# Local Docker Compose default. Adjust if you use a remote or managed DB.
DATABASE_URL=postgresql://vortex:vortex@localhost:5432/vortex?schema=public

# ─── Server ──────────────────────────────────────────────────────────────────
PORT=4000
NODE_ENV=development

# ─── Stellar / Soroban ───────────────────────────────────────────────────────
STELLAR_NETWORK=testnet
SOROBAN_RPC_URL=https://soroban-testnet.stellar.org

# Testnet contract IDs — leave blank until you have deployed contracts.
# The service boots without them; on-chain write paths are no-ops when empty.
SETTLEMENT_CONTRACT_ID=
SOLVER_REGISTRY_CONTRACT_ID=

# Testnet signing key — generate a throwaway keypair, fund it with Friendbot,
# and paste the secret seed here. Never reuse this key on mainnet.
#
# # Generate a new key:
# npx @stellar/stellar-cli keys generate local-dev --network testnet
# npx @stellar/stellar-cli keys show local-dev
#
# # Or via the SDK:
# node -e "console.log(require('@stellar/stellar-sdk').Keypair.random().secret())"
#
# # Fund it (testnet only):
# curl "https://friendbot.stellar.org/?addr=<YOUR_PUBLIC_KEY>"
#
# Optional in development — leave blank to skip on-chain writes.
SOROBAN_SIGNING_KEY=

# Fee percentile used when estimating Soroban inclusion fees.
# p50 is a safe default for testnet; raise to p90+ for time-sensitive mainnet txs.
SOROBAN_FEE_PERCENTILE=p50

# ─── CORS ────────────────────────────────────────────────────────────────────
# Wildcard is fine for local development — tighten this in staging/production.
CORS_ORIGIN=*

# ─── WebSocket ───────────────────────────────────────────────────────────────
WS_MAX_CONNECTIONS=1000

# ─── Pluggable signer backend (issue #400) ───────────────────────────────────
# SIGNER_BACKEND=local is the default for development.
# In production use SIGNER_BACKEND=vault and supply VAULT_ADDR + VAULT_TOKEN.
SIGNER_BACKEND=local
VAULT_ADDR=
VAULT_TOKEN=
VAULT_TRANSIT_KEY_NAME=vortex-signer
ALLOW_LOCAL_SIGNER_IN_PROD=false
# ─── Resource-exhaustion limits (issue #476) ─────────────────────────────────
# Maximum JSON nesting depth — rejects deeply-nested body attacks (default 10).
JSON_MAX_DEPTH=10
# Maximum chain values in a single WS subscribe message (default 20).
WS_MAX_FILTER_CHAINS=20
# Maximum active subscriptions per WS connection (default 10).
WS_MAX_SUBSCRIPTIONS=10
# Postgres statement_timeout for standard queries in ms (default 5000).
DB_QUERY_TIMEOUT_MS=5000
# Postgres statement_timeout for batch queries in ms (default 10000).
DB_BATCH_QUERY_TIMEOUT_MS=10000
# Postgres statement_timeout for stats queries in ms (default 15000).
DB_STATS_QUERY_TIMEOUT_MS=15000

# Emergency kill-switch (issue #477)
# Postgres-backed so a pause survives a restart and reaches every replica.
KILLSWITCH_OPERATOR_TOKEN=
KILLSWITCH_REDIS_URL=
KILLSWITCH_POLL_MS=2000
KILLSWITCH_PERSISTENCE=prisma

# ─── Observability (optional) ────────────────────────────────────────────────
# Leave blank to disable Sentry error reporting.
SENTRY_DSN=

# debug | info | warn | error (defaults to "debug" in development)
LOG_LEVEL=debug

# ── Shadow-mode divergence monitor (issue #401) ─────────────────────────
# Off by default in every environment. It runs read-only `simulateTransaction`
# calls against SETTLEMENT_CONTRACT_ID in parallel with the off-chain intent
# path and never signs or submits anything.
#
# SHADOW_SOURCE_ACCOUNT only has to be a valid Stellar public key: it is used to
# populate the source-account field of the simulated envelope and is never
# signed, never charged a fee and never broadcast. It must still be set, or
# every transition reports "contract_unconfigured".
SHADOW_MODE_ENABLED=false
SHADOW_SAMPLE_RATE=1
SHADOW_QUEUE_MAX=256
SHADOW_CONCURRENCY=4
SHADOW_SOURCE_ACCOUNT=
# ─── Governance / Protocol Parameters ────────────────────────────────────────
# On-chain governance parameters contract ID — leave blank to use code defaults.
PARAMS_CONTRACT_ID=

# Poll interval in ms. 30 000 is fine for testnet.
PARAMS_POLL_INTERVAL_MS=30000
# ─── Leader election ─────────────────────────────────────────────────────────
# Enable for multi-replica testnet deployments.
LEADER_ELECTION_ENABLED=false
LEADER_ELECTION_HEARTBEAT_MS=5000

# ─── Background jobs (issue #494) ────────────────────────────────────────────
# api | worker | all — queue workers only run in "worker" or "all".
PROCESS_ROLE=all
# memory (single-process, dev/test) | bullmq (Redis-backed, uses REDIS_URL)
JOBS_DRIVER=memory
# Grace period for in-flight jobs on SIGTERM before they are returned to the queue.
JOBS_SHUTDOWN_TIMEOUT_MS=25000

# ─── Runtime feature flags (issue #495) ──────────────────────────────────────
# Change propagation across instances: memory (single instance) | redis
FLAGS_PUBSUB=memory
# Safety-net cache reload interval (ms)
FLAGS_REFRESH_MS=30000
# Break-glass pins that win over DB state, e.g. onchain-dry-run=true
FLAG_OVERRIDES=

# ─── Admin RBAC ──────────────────────────────────────────────────────────────
# Comma-separated id:role:secret (role = admin | superadmin, secret >= 16 chars).
# Sent as the x-admin-key header (the secret part). Empty disables admin APIs.
ADMIN_API_KEYS=

# ─── Guardian emergency ingestion (issue #507) ───────────────────────────────
# Guardian / security-council contract ID. Leave blank to disable ingestion.
GUARDIAN_CONTRACT_ID=

# ─── Synthetic canary (issue #496) ───────────────────────────────────────────
# Canary user + solver addresses; excluded from public stats and leaderboards.
CANARY_ADDRESSES=
# Egress/SSRF Protection
EGRESS_TIMEOUT_MS=10000
EGRESS_MAX_REDIRECTS=3
EGRESS_MAX_BODY_SIZE_BYTES=10485760
SOROBAN_RPC_ALLOWLIST=soroban-testnet.stellar.org,soroban-rpc.stellar.org
WEBHOOK_ALLOWLIST=hooks.example.com,hooks.trusted.com
ORACLE_ALLOWLIST=oracle.trusted.io
# Oracle minDstAmount gates (issue #434). Slippage/premium in basis points.
MAX_USER_SLIPPAGE_BPS=100
MAX_PREMIUM_BPS=50
ORACLE_FAIL_OPEN_MAX_USD=100
ORACLE_MAX_STALENESS_MS=60000
# Public anonymised datasets (RFC 0001). Disabled until an operator opts in.
DATASETS_ENABLED=false
DATASETS_ANONYMIZE=true
DATASETS_SALT=
DATASETS_SALT_ROTATION_HOURS=24
DATASETS_SALT_RETENTION_WINDOWS=2
DATASETS_PUBLIC_BUCKET=vortex-public-datasets
DATASETS_STORAGE_KIND=memory
DATASETS_LOCAL_DIR=./data/datasets
# ─── WS gateway hardening (issue #455) ───────────────────────────────────────
# Inbound frames larger than this close the socket (1009).
WS_MAX_PAYLOAD_BYTES=16384
# Concurrent WS connections per client IP (0 = unlimited).
WS_MAX_CONNECTIONS_PER_IP=20
# Trusted reverse-proxy hops for X-Forwarded-For (0 = socket address only).
WS_TRUST_PROXY_HOPS=0
# Inbound token bucket per connection; repeat violators are disconnected.
WS_RATE_LIMIT_PER_SEC=10
WS_RATE_LIMIT_BURST=20
WS_RATE_LIMIT_MAX_VIOLATIONS=5
# Outbound backpressure: messages held per slow consumer, socket buffer
# threshold (bytes), and what to do when the queue is full.
WS_OUTBOUND_QUEUE_MAX=1000
WS_OUTBOUND_BUFFER_BYTES=1048576
WS_SLOW_CONSUMER_POLICY=drop_oldest
# HS256 secret for solver JWTs from the SEP-10 auth flow (#442); >= 32 chars.
# Empty disables JWT auth on the WS gateway.
AUTH_JWT_SECRET=

# ─── Health probes (issue #492) ──────────────────────────────────────────────
# Roles served by this process (api, ws, worker); readiness checks follow them.
SERVICE_ROLES=api,ws,worker
HEALTH_CHECK_INTERVAL_MS=5000
# Readiness hysteresis: failures before not-ready, successes before ready again.
HEALTH_READY_FAILURE_THRESHOLD=3
HEALTH_READY_SUCCESS_THRESHOLD=2
# Liveness fails when event-loop delay exceeds this.
HEALTH_EVENT_LOOP_MAX_LAG_MS=1000
# Soroban RPC endpoints for the quorum check (default: SOROBAN_RPC_URL).
SOROBAN_RPC_HEALTH_URLS=

Loading
Loading