docs(deploy): HQ connects as shared postgres superuser (no per-app roles on box)

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
feat/client-detail-redesign
Thomas Joise 4 days ago
parent 70234161dc
commit a11d650416

@ -52,11 +52,10 @@ other apps. (D20 target, revised: `.in` not `.com`, Docker not RDS — see notes
| Thing | Value | | Thing | Value |
|---|---| |---|---|
| Superuser (admin) | `postgres` (connect via `sudo docker exec -i accurate-postgres psql -U postgres`) | | Superuser (admin) | `postgres` (connect via `sudo docker exec -it accurate-postgres psql -U postgres`) |
| HQ database | `hq` | | HQ database | `hq` (owned by `postgres`) |
| HQ role (login) | `hq` | | HQ login | `postgres` — the shared superuser. Every app on this box uses it; there are **no** per-app roles (checked 2026-07-18). A dedicated `hq` role is a future hardening. |
| HQ password | *generated on the box*, stored only in `apps/hq/.env` — never in git | | Connection string | `postgres://postgres:<postgres-password>@host.docker.internal:5432/hq` |
| Connection string | `postgres://hq:<password>@host.docker.internal:5432/hq` |
## App environment (`apps/hq/.env`) ## App environment (`apps/hq/.env`)
@ -64,7 +63,7 @@ other apps. (D20 target, revised: `.in` not `.com`, Docker not RDS — see notes
|---|---| |---|---|
| `HQ_PORT` | `5182` | | `HQ_PORT` | `5182` |
| `HQ_OWNER_EMAIL` | `simssoftware13@gmail.com` (first-boot owner login) | | `HQ_OWNER_EMAIL` | `simssoftware13@gmail.com` (first-boot owner login) |
| `DATABASE_URL` | `postgres://hq:<password>@host.docker.internal:5432/hq` | | `DATABASE_URL` | `postgres://postgres:<postgres-password>@host.docker.internal:5432/hq` |
| `SIMS_PIN_PEPPER` | generated on box — **set once, never change** | | `SIMS_PIN_PEPPER` | generated on box — **set once, never change** |
| `HQ_SECRET_KEY` | generated on box (needed before Gmail) | | `HQ_SECRET_KEY` | generated on box (needed before Gmail) |

Loading…
Cancel
Save