# The only release value required for the normal manual installation.
# Gateway, Relay, and Secure Link connector tags are derived from it.
GATEWAY_VERSION=v2.11.2

# Compose derives these values automatically from GATEWAY_VERSION.
# For optional digest pinning, replace only the three image values.
GATEWAY_IMAGE_REF=ghcr.io/the-square-labs/gateway:${GATEWAY_VERSION}
GATEWAY_RELAY_IMAGE_REF=ghcr.io/the-square-labs/gateway/relay:${GATEWAY_VERSION}-relay
GATEWAY_RELAY_BUILD_VERSION=${GATEWAY_VERSION}
GATEWAY_RELAY_PROTOCOL_MAJOR=1
SECURE_LINK_CONNECTOR_IMAGE=ghcr.io/the-square-labs/gateway/secure-link-connector:${GATEWAY_VERSION}-relay

# Generate locally: openssl rand -hex 24
DB_PASSWORD=REPLACE_WITH_RANDOM_DATABASE_PASSWORD

# Generate locally: openssl rand -hex 32
PKI_MASTER_KEY=REPLACE_WITH_RANDOM_PKI_MASTER_KEY
GATEWAY_REGISTRY_HTTP_SECRET=REPLACE_WITH_RANDOM_REGISTRY_SECRET

# First-start and service foundation settings
SETUP_BOOTSTRAP=true
WEB_TLS_BOOTSTRAP_MODE=https
SANDBOX_RUNNER_WORKSPACE_DIR=/var/lib/gateway/sandbox-workspaces
# Third-party images pinned by digest, pulled from the Gateway mirror on ghcr.io.
# Without access to ghcr.io, use the Docker Hub image with the same digest:
# docker.io/library/registry@sha256:ddf754342cfc8acc51a56d5d0ab6af06826461864460636d8bd5c546dab2a7b8 (3.1.2),
# docker.io/library/postgres@sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea (16.15-alpine),
# docker.io/library/redis@sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499 (7.4.11-alpine).
GATEWAY_REGISTRY_IMAGE_REF=ghcr.io/the-square-labs/gateway/registry@sha256:ddf754342cfc8acc51a56d5d0ab6af06826461864460636d8bd5c546dab2a7b8
GATEWAY_POSTGRES_IMAGE_REF=ghcr.io/the-square-labs/gateway/postgres@sha256:721873c34ceb9f8d8fc265984940dc982404c105f19ad51be9fdc5970a6080ea
GATEWAY_REDIS_IMAGE_REF=ghcr.io/the-square-labs/gateway/redis@sha256:858f009f9709ce576febc734aa78b8f6d624b82571f9ddb6bda4377c833b3499
GATEWAY_RELAY_MANAGED=true
GATEWAY_LOCAL_HOSTS=
