Configuration & Secret Governance
Planovi adheres to a strict zero-secret policy: no passwords, API tokens, encryption keys, or private certificates may ever be committed to any Git repository.
ποΈ Centralized Secret Management (PA Management)
All credentials, database passwords, and third-party service tokens are securely stored in the internal firm system: π System PA Management β ModuΕ βLoginyβ
Only authorized DevOps administrators have access to this vault. When provisioning or updating the VPS environment, credentials are retrieved from the vault and populated directly onto the server filesystem.
π Infrastructure Environment Schema (/opt/vps-stack/.env)
The core Docker Compose stack reads configuration exclusively from /opt/vps-stack/.env. Below is the complete environment matrix referenced in .env.example:
| Variable Name | Required | Purpose / Service | Example / Notes |
|---|---|---|---|
POSTGRES_PASSWORD | Yes | Root password for supabase-db | Strong 32+ character alpha-numeric secret |
JWT_SECRET | Yes | Shared secret for signing Supabase JWT tokens | Min 32 characters, used by Auth, PostgREST, Kong |
SUPABASE_ANON_KEY | Yes | Public/Client JWT token for frontend APIs | Signed with JWT_SECRET (role: anon) |
SUPABASE_SERVICE_ROLE_KEY | Yes | Administrative bypass JWT for backend functions | Signed with JWT_SECRET (role: service_role) |
WEBHOOK_SECRET | Yes | HMAC SHA-256 secret for GitHub deployer webhooks | Configured in GitHub repo webhook settings |
GOOGLE_CHAT_WEBHOOK_URL | Optional | Google Chat Space webhook for deployment notifications | https://chat.googleapis.com/v1/spaces/... |
RESEND_API_KEY | Yes | SMTP API key for GoTrue transactional auth emails | re_... |
SMTP_ADMIN_EMAIL | Yes | Sender email address for system emails | auth@planovi.app |
SITE_URL | Yes | Primary frontend URL for OAuth redirects | https://panel.planovi.app |
API_EXTERNAL_URL | Yes | Public URL for the Supabase Kong Gateway | https://api.planovi.app |
GEMINI_API_KEY | Yes | Google Gemini API key for OCR and AI balancing | Used by Deno Edge Functions |
DEALFLOW_BASE_URL | Yes | Microservice dealflow URL | https://dealflow.planovi.app |
DEALFLOW_API_SECRET | Yes | Secret header token (X-Secret-Key) | Microservice authentication token |
SCHEDULER_BASE_URL | Yes | Microservice scheduler URL | https://scheduler.planovi.app |
SCHEDULER_API_SECRET | Yes | Secret header token (X-Secret-Key) | Microservice authentication token |
INCHARGE_API_TOKEN | Optional | InCharge energy aggregator API integration token | Bearer token |
π± Frontend Application Environments (/opt/vps-apps/flutter-app/)
The Flutter Web application requires distinct environment injection during build time:
/opt/vps-apps/flutter-app/dev.envβ Injected intodev-panel.planovi.app/opt/vps-apps/flutter-app/prod.envβ Injected intopanel.planovi.app
Each file contains the respective environmentβs SUPABASE_URL and SUPABASE_ANON_KEY.
π Permission & Ownership Best Practices
On the host VPS, environment files must have restricted file permissions:
# Set root-only read/write permissions on secretschmod 600 /opt/vps-stack/.envchmod 600 /opt/vps-apps/flutter-app/*.envchmod 600 /opt/vps-stack/cloudflare-ssl/*.pemchmod 600 /opt/vps-stack/cloudflare-ssl/*.key