Files
ita-ito-horaires/.env.example
T
vliaudatandClaude Opus 5 dd4d1b97c8 feat: serve the BYOS device API
The panel now pairs, fetches its image and files its logs against this
application rather than against the TRMNL cloud.

Four endpoints: /api/setup issues a token on first contact,
/api/display hands back an image and a wake interval, /api/log stores
firmware diagnostics, and /api/device/image/<hash> serves the bytes.

The wake interval is where freshness and battery are traded off. In BYOS
nothing can be pushed: the device sleeps, wakes, asks and sleeps again.
So the interval is short while the shop trades and long overnight, and
it is shortened further whenever a change of state falls inside it —
the door opening in twenty minutes means waking in twenty-one,
whatever the base interval says.

The image filename is the hash of its own bytes. The firmware skips the
redraw when the name is unchanged, which is the whole battery strategy,
and the URL is immutable, unguessable and safe to cache forever. Two
integration tests pin this: unchanged data must yield the same filename
and store one row, changed hours must yield a different one.

MAC addresses are normalised before use. They are a primary key here,
and firmwares are inconsistent about case and separators; without this a
panel could register twice by capitalising itself differently. Header
names are read in both the hyphen and underscore spellings for the same
reason — the TRMNL docs and the Seeed sources disagree, and being
liberal costs nothing while being wrong costs a blank shop window.

Pairing is deliberately made to survive a rendering failure. The token
is issued once and only its digest is kept, so a device stranded by a
failed response would be registered yet hold no credential, and unable
to register again. The welcome image is worth far less than that. This
was found by running the flow, not by reading it.

satori, yoga and harfbuzz are marked external: bundling rewrites the
relative path satori uses to load its WebAssembly, and the renderer dies
on a missing hb.wasm.

The integration tests run against a real Postgres, in CI too. Mocking
Prisma here would only prove the mock works.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012cSY9pVhZmJUKNN7wf1Myd
2026-09-20 18:00:50 +02:00

88 lines
4.5 KiB
Bash

# =============================================================================
# ITA ITO — Panneau d'administration des horaires (écran e-ink TRMNL, BYOS)
# Copiez ce fichier en `.env` et renseignez les valeurs. `.env` n'est JAMAIS commité.
# =============================================================================
# -----------------------------------------------------------------------------
# Application
# -----------------------------------------------------------------------------
# Nom de domaine public de l'app sur le VPS. Sert à trois choses :
# le callback OIDC, l'URL d'image envoyée à l'écran, et les liens du README.
APP_DOMAIN=trmnl.loxi.ch
# Port publié en local (dev). En production, Traefik s'en charge : aucun port publié.
APP_PORT=3010
APP_BIND=127.0.0.1
TZ=Europe/Zurich
# -----------------------------------------------------------------------------
# Base de données (PostgreSQL 16)
# -----------------------------------------------------------------------------
POSTGRES_DB=horaires
POSTGRES_USER=horaires
POSTGRES_PASSWORD=
DATABASE_URL=postgresql://horaires:CHANGEME@db:5432/horaires?schema=public
# Only needed to run the integration tests. They truncate every table, so this
# must never point at a database holding anything you want to keep.
TEST_DATABASE_URL=
# -----------------------------------------------------------------------------
# Authentification — Authentik (OIDC, Authorization Code + PKCE)
# -----------------------------------------------------------------------------
# Doit correspondre EXACTEMENT à l'`issuer` du document de découverte :
# https://auth.loxi.ch/application/o/<SLUG>/.well-known/openid-configuration
AUTHENTIK_ISSUER=https://auth.loxi.ch/application/o/CHANGEME/
AUTHENTIK_CLIENT_ID=
AUTHENTIK_CLIENT_SECRET=
# Groupe Authentik dont les membres sont administrateurs. Les autres utilisateurs
# authentifiés sont en lecture seule (rôle `viewer`).
AUTHENTIK_ADMIN_GROUP=horaires-admins
# URL publique complète de l'app. L'URI de redirection à déclarer dans Authentik est
# <NEXTAUTH_URL>/api/auth/callback/authentik
NEXTAUTH_URL=https://trmnl.loxi.ch
# Générer avec : openssl rand -base64 33
NEXTAUTH_SECRET=
# -----------------------------------------------------------------------------
# Écran e-ink — API appareil (BYOS)
# -----------------------------------------------------------------------------
# Format d'image servi à l'appareil. Le firmware Seeed référence des .bmp ;
# basculer sur `png` si l'appareil refuse le BMP.
DEVICE_IMAGE_FORMAT=bmp
# Autorise l'appareil à appeler l'API en clair (HTTP). À n'activer que si le
# firmware ESP32 échoue sur la chaîne TLS. Le jeton d'appareil circulerait alors
# en clair : il est distinct de tout autre secret et révocable depuis /admin/parametres.
DEVICE_ALLOW_HTTP=false
# Intervalles de réveil, en secondes. Court quand la boutique est ouverte ou sur le
# point de changer d'état, long la nuit et les jours de fermeture.
DEVICE_REFRESH_OPEN_SEC=600
DEVICE_REFRESH_CLOSED_SEC=7200
# -----------------------------------------------------------------------------
# Traduction FR -> EN — api.loxi.ch (projet api_llm_loxi)
# -----------------------------------------------------------------------------
# ATTENTION : cette API n'est ni Anthropic- ni OpenAI-compatible.
# Contrat réel : POST {TRANSLATION_API_URL}/api/generate {"model_id": <int>, "prompt": "..."}
# -> 200 {"stdout": "...", "stderr": "...", "exit_code": 0}
# Un échec du CLI renvoie quand même HTTP 200 : c'est `exit_code` qui fait foi.
TRANSLATION_API_URL=https://api.loxi.ch
# Clé API créée depuis la page « API keys » du dashboard api-llm-loxi (format llk_...).
TRANSLATION_API_KEY=
TRANSLATION_API_FLAVOR=loxi
# Nom du modèle, résolu en `model_id` au démarrage via GET /api/models.
# L'alias `haiku` pointe toujours vers la dernière version.
TRANSLATION_MODEL_NAME=haiku
# Le backend lance réellement le CLI Claude Code : prévoir large.
TRANSLATION_TIMEOUT_MS=30000
# -----------------------------------------------------------------------------
# Jours fériés — OpenHolidays (aucune clé requise)
# -----------------------------------------------------------------------------
HOLIDAYS_API_URL=https://openholidaysapi.org
# -----------------------------------------------------------------------------
# Déploiement (production, docker-compose.prod.yml)
# -----------------------------------------------------------------------------
TRAEFIK_NETWORK=web
TRAEFIK_ENTRYPOINT=websecure
TRAEFIK_CERTRESOLVER=myresolver