# Copy to .env for local/docker compose (not committed). PORT=3001 # GT06 GPS tracker TCP listener port (raw TCP, must be reachable by tracker SIMs). 0 disables. GT06_TCP_PORT=5023 DB_HOST=localhost DB_PORT=5433 DB_USER=postgres DB_PASSWORD= DB_NAME=edr_freight # Telebirr payment gateway (freight merchant credentials) TELEBIRR_BASE_URL= TELEBIRR_WEB_BASE_URL= TELEBIRR_FABRIC_APP_ID= TELEBIRR_APP_SECRET= TELEBIRR_MERCHANT_APP_ID= TELEBIRR_MERCHANT_CODE= TELEBIRR_NOTIFY_URL=https://freight-api.edr.et/payments/webhooks/telebirr TELEBIRR_RETURN_URL= TELEBIRR_TIMEOUT_EXPRESS=15m TELEBIRR_PRIVATE_KEY= TELEBIRR_PUBLIC_KEY= TELEBIRR_INSECURE_TLS=false # Public origin of the freight customer portal. Password-reset links sent to # customers are built against this — it must be browser-reachable. FREIGHT_PORTAL_URL=http://localhost:5173 # Portal pages the payment provider redirects the browser to after payment. # Point these at the freight portal's public payment result routes. PAYMENT_RETURN_URL=http://localhost:5173/payment/success PAYMENT_FAILURE_URL=http://localhost:5173/payment/failure # JWT (used by @tria-plc/api-common SharedAuthModule) JWT_SECRET= JWT_ACCESS_TOKEN_SECRET= JWT_REFRESH_TOKEN_SECRET= JWT_EXPIRES_IN=3600 # JWT expiry for @tria-plc/api-common token utils (jsonwebtoken timespan format) JWT_ACCESS_TOKEN_EXPIRES=1h JWT_REFRESH_TOKEN_EXPIRES=7d # IAM seed defaults (used by @tria-plc/iamapi-common on first boot) SUPER_ADMIN_EMAIL=superadmin@tria.com SUPER_ADMIN_PHONE= DEFAULT_PASSWORD=password@tria # Freight org + staff (bookings / rule-engine IAM) SEED_EDR_ORG=true SEED_FREIGHT_STAFF=true SEED_EXPORT_DJIBOUTI_INTERCHANGE_DEMO=false # MinIO (used by @tria-plc/iamapi-common for file storage) MINIO_ENDPOINT=localhost MINIO_PORT=9000 MINIO_USE_SSL=false MINIO_ACCESS_KEY= MINIO_SECRET_KEY= # Preset region so signed URLs are generated locally (no GetBucketLocation # network call per sign). MinIO's default is us-east-1. MINIO_REGION=us-east-1 # Redis REDIS_HOST=localhost REDIS_PORT=6379 # --- Notification broker (RabbitMQ) --------------------------------------------- # SMS/email OTP + notifications are queued to RabbitMQ (consumed by the shared # SMS/email services). Set RABBITMQ_ENABLED=false to skip the broker entirely # (dev without a local broker). RABBITMQ_ENABLED=false RABBITMQ_URL=amqp://localhost:5672 SMS_QUEUE=sms_queue # ── VeriFayda 2.0 (eSignet OIDC) identity verification ────────────────────── # Disabled by default; /fayda/verification/start returns 503 until enabled. FAYDA_ENABLED=false FAYDA_CLIENT_ID= FAYDA_AUTHORIZATION_ENDPOINT= FAYDA_TOKEN_ENDPOINT= FAYDA_USERINFO_ENDPOINT= # Base64-encoded RSA private JWK used for the private_key_jwt client assertion FAYDA_PRIVATE_KEY_BASE64= # OAuth redirect_uri for MOBILE clients (must be registered with eSignet) FAYDA_REDIRECT_URI=http://localhost:3001/api/fayda/verification/complete # OAuth redirect_uri for WEB clients. Defaults to FAYDA_REDIRECT_URI when unset. FAYDA_WEB_REDIRECT_URI=http://localhost:3000/callback CLIENT_ASSERTION_TYPE=urn:ietf:params:oauth:client-assertion-type:jwt-bearer FAYDA_SCOPE=openid profile email phone address FAYDA_ACR_VALUES=mosip:idp:acr:generated-code FAYDA_CLAIMS_LOCALES=en am FAYDA_SESSION_TTL_MINUTES=10 EXPIRATION_TIME=15 ALGORITHM=RS256 EMAIL_QUEUE=email_queue