Skip to content

Configuration & Secret Governance

Planovi adheres to a strict zero-secret policy: no passwords, API tokens, encryption keys, or private certificates may ever be committed to any Git repository.


πŸ›οΈ Centralized Secret Management (PA Management)

All credentials, database passwords, and third-party service tokens are securely stored in the internal firm system: πŸ‘‰ System PA Management βž” ModuΕ‚ β€œLoginy”

Only authorized DevOps administrators have access to this vault. When provisioning or updating the VPS environment, credentials are retrieved from the vault and populated directly onto the server filesystem.


πŸ“„ Infrastructure Environment Schema (/opt/vps-stack/.env)

The core Docker Compose stack reads configuration exclusively from /opt/vps-stack/.env. Below is the complete environment matrix referenced in .env.example:

Variable NameRequiredPurpose / ServiceExample / Notes
POSTGRES_PASSWORDYesRoot password for supabase-dbStrong 32+ character alpha-numeric secret
JWT_SECRETYesShared secret for signing Supabase JWT tokensMin 32 characters, used by Auth, PostgREST, Kong
SUPABASE_ANON_KEYYesPublic/Client JWT token for frontend APIsSigned with JWT_SECRET (role: anon)
SUPABASE_SERVICE_ROLE_KEYYesAdministrative bypass JWT for backend functionsSigned with JWT_SECRET (role: service_role)
WEBHOOK_SECRETYesHMAC SHA-256 secret for GitHub deployer webhooksConfigured in GitHub repo webhook settings
GOOGLE_CHAT_WEBHOOK_URLOptionalGoogle Chat Space webhook for deployment notificationshttps://chat.googleapis.com/v1/spaces/...
RESEND_API_KEYYesSMTP API key for GoTrue transactional auth emailsre_...
SMTP_ADMIN_EMAILYesSender email address for system emailsauth@planovi.app
SITE_URLYesPrimary frontend URL for OAuth redirectshttps://panel.planovi.app
API_EXTERNAL_URLYesPublic URL for the Supabase Kong Gatewayhttps://api.planovi.app
GEMINI_API_KEYYesGoogle Gemini API key for OCR and AI balancingUsed by Deno Edge Functions
DEALFLOW_BASE_URLYesMicroservice dealflow URLhttps://dealflow.planovi.app
DEALFLOW_API_SECRETYesSecret header token (X-Secret-Key)Microservice authentication token
SCHEDULER_BASE_URLYesMicroservice scheduler URLhttps://scheduler.planovi.app
SCHEDULER_API_SECRETYesSecret header token (X-Secret-Key)Microservice authentication token
INCHARGE_API_TOKENOptionalInCharge energy aggregator API integration tokenBearer token

πŸ“± Frontend Application Environments (/opt/vps-apps/flutter-app/)

The Flutter Web application requires distinct environment injection during build time:

  • /opt/vps-apps/flutter-app/dev.env βž” Injected into dev-panel.planovi.app
  • /opt/vps-apps/flutter-app/prod.env βž” Injected into panel.planovi.app

Each file contains the respective environment’s SUPABASE_URL and SUPABASE_ANON_KEY.


πŸ”’ Permission & Ownership Best Practices

On the host VPS, environment files must have restricted file permissions:

Terminal window
# Set root-only read/write permissions on secrets
chmod 600 /opt/vps-stack/.env
chmod 600 /opt/vps-apps/flutter-app/*.env
chmod 600 /opt/vps-stack/cloudflare-ssl/*.pem
chmod 600 /opt/vps-stack/cloudflare-ssl/*.key