From 7b8cd00b59b4bad4e3440b367d7559ecd68f2d17 Mon Sep 17 00:00:00 2001 From: Julien Lucca Date: Sat, 22 Aug 2026 12:16:09 +0200 Subject: [PATCH] chore: template the pm2 config and stop it being the only copy MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The production pm2 process definition at /home/ubuntu/apps/event-source/ecosystem.config.js is untracked, holds the production database password in plaintext, and has no backup anywhere — losing the box means reconstructing the credentials by hand. Adds ecosystem.config.example.js documenting every variable src/config/prod.js reads, and gitignores the real ecosystem.config.js so a future copy on a dev machine cannot be committed with live credentials in it. The server file is deliberately left alone: it is what pm2 replays on reboot, and rewiring it to read from a sourced env file would mean an unattended restart comes up with no database configuration at all. Also fixes a .gitignore line where the FuseBox cache entry and a config path had been concatenated into a single nonexistent path, so neither was ignored. Co-Authored-By: Claude Opus 5 --- .gitignore | 7 +++++- ecosystem.config.example.js | 50 +++++++++++++++++++++++++++++++++++++ 2 files changed, 56 insertions(+), 1 deletion(-) create mode 100644 ecosystem.config.example.js diff --git a/.gitignore b/.gitignore index 49eeb9c..cf762de 100644 --- a/.gitignore +++ b/.gitignore @@ -76,4 +76,9 @@ typings/ .serverless # FuseBox cache -.fusebox/src/config/fresh.js +.fusebox/ +src/config/fresh.js + +# PM2 process definition: holds the production DB password in plaintext. +# Use ecosystem.config.example.js as the template. +ecosystem.config.js diff --git a/ecosystem.config.example.js b/ecosystem.config.example.js new file mode 100644 index 0000000..f7617a5 --- /dev/null +++ b/ecosystem.config.example.js @@ -0,0 +1,50 @@ +// PM2 process definition for the production event-source indexer. +// +// Copy this to `ecosystem.config.js` ON THE SERVER and fill in the real values. +// The real file is intentionally NOT tracked: it holds the production database +// password in plaintext. It is also the only copy that exists, so if you change +// it, back it up off-box as well (see "Backups" below). +// +// cp ecosystem.config.example.js ecosystem.config.js +// $EDITOR ecosystem.config.js +// pm2 restart event-source --update-env +// +// Every value below is read by src/config/prod.js straight off process.env, so +// the names here must match that file exactly. +// +// Backups: the live file lives at +// /home/ubuntu/apps/event-source/ecosystem.config.js +// on app.cambiatus.io. Keep a copy somewhere private and chmod 600 — losing it +// means reconstructing the DB credentials by hand. + +module.exports = { + apps: [ + { + name: 'event-source', + time: true, + script: 'src/app.js', + watch: false, + exec_mode: 'fork', + autorestart: true, + env: { + NODE_ENV: 'prod', + + // Chain + BLOCKCHAIN_INIT_BLOCK: '60000000', + BLOCKCHAIN_TOKEN_CONTRACT: 'cambiatus.tk', + BLOCKCHAIN_COMMUNITY_CONTRACT: 'cambiatus.cm', + // Optional: src/config/prod.js defaults it to cambiatus.es when unset. + BLOCKCHAIN_ESCROW_CONTRACT: 'cambiatus.es', + BLOCKCHAIN_URL: 'https://', + + // Database — same Postgres the backend writes to. + DB_USER: '', + DB_PASS: '', + DB_HOST: '', + DB_NAME: '', + + EVENT_SOURCE_HTTP_PORT: 3001 + } + } + ] +}