-
Notifications
You must be signed in to change notification settings - Fork 6
Expand file tree
/
Copy pathfly.toml
More file actions
68 lines (60 loc) · 2.37 KB
/
Copy pathfly.toml
File metadata and controls
68 lines (60 loc) · 2.37 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
# fly.toml app configuration file generated for raxol-playground
#
# See https://fly.io/docs/reference/configuration/ for information about how to use this file.
#
app = 'raxol'
primary_region = 'sjc'
kill_signal = 'SIGTERM'
[build]
dockerfile = "docker/Dockerfile.web"
ignorefile = ".dockerignore"
# [deploy]
# release_command = '/app/bin/migrate'
[env]
PHX_HOST = 'raxol.io'
PORT = '8080'
RAXOL_MODE = 'minimal'
# RAXOL_REPL_EXPOSED is deliberately absent, and this app must never set it.
# The HTTPS gallery serves every catalog demo at /demos/:demo with no auth,
# and the REPL demo evaluates submitted Elixir with the node's full
# authority -- the same exposure the SSH playground was suspended for, over
# a surface that was never suspended. With the flag unset the demo renders
# and refuses to evaluate. Setting it here would also make any node running
# Raxol.Payments.Deployment.assert_signing_isolated!/0 refuse to boot, which
# is the intended relationship, not an accident.
# The anonymous SSH playground (port 2222) is deliberately absent: it was
# suspended 2026-08-26 after review found it reachable, unauthenticated, on
# the app's dedicated IPv6. Re-enabling it is a separate, explicit decision
# gated on the SSH safety defaults (loopback-unless-acknowledged bind, boot
# posture line, accept/close logging, host keys on a persistent volume) and
# on verification from outside the app over BOTH address families.
# Hosted coding agent (multi-tenant, port 2223): flip on once a tenants
# volume exists. The build already carries raxol_agent, raxol_payments and
# req (see web/mix.exs); boot refuses to serve without all three, and
# without BOTH the per-user key root and a per-tenant spend cap -- a hosted
# tenant spends the host's provider credential.
# RAXOL_SSH_CODE = 'true'
# RAXOL_SSH_CODE_PORT = '2223'
# RAXOL_SSH_CODE_TENANTS = '/data/tenants'
# RAXOL_SSH_CODE_BUDGET_USD = '5.00'
[http_service]
internal_port = 8080
force_https = true
auto_stop_machines = 'stop'
auto_start_machines = true
min_machines_running = 1
processes = ['app']
[http_service.concurrency]
type = 'connections'
hard_limit = 1000
soft_limit = 800
[[http_service.checks]]
grace_period = "10s"
interval = "30s"
method = "GET"
timeout = "5s"
path = "/health"
[[vm]]
memory = '1gb'
cpu_kind = 'shared'
cpus = 1