mirror of
https://github.com/djdevin/recflare.git
synced 2026-09-08 14:41:28 -07:00
115 lines
7.1 KiB
Bash
115 lines
7.1 KiB
Bash
# Base domain all service hosts are derived from, e.g. accounts.<domain>. Used by
|
|
# `just dev` too, so a locally-run worker hands out the same addresses it would deployed.
|
|
RECFLARE_DOMAIN=rec.example.com
|
|
|
|
# Optional per-app subdomain overrides, as a compact JSON object keyed by the
|
|
# worker's directory name. Defaults to the directory name when unset. Use "@" to
|
|
# put a worker on the APEX of the domain rather than a subdomain.
|
|
# RECFLARE_SUBDOMAINS='{"playersettings":"settings"}'
|
|
#
|
|
# The combined `mono` worker (an alternative to deploying the services separately:
|
|
# it mounts most of them in one deployable and routes on the first path segment, so
|
|
# every address is https://<domain>/rooms, https://<domain>/auth, …) belongs on the
|
|
# apex, and won't hand out the right addresses anywhere else. It ships only when you
|
|
# ask for it — `just deploy-mono`, never `just deploy` — since it's an alternative to
|
|
# the split set, not part of it:
|
|
# RECFLARE_SUBDOMAINS='{"mono":"@"}'
|
|
|
|
# Id of the shared `recflare` D1 database (create it manually with
|
|
# `wrangler d1 create recflare`). All D1-backed workers bind this one database.
|
|
# Kept out of the committed wrangler.jsonc (which uses a "local" placeholder) and
|
|
# spliced in at deploy time. Required to deploy any worker that uses D1.
|
|
# RECFLARE_D1=d44083e1-5bfe-4467-aa9a-f13c5c2496d5
|
|
|
|
# KV namespace ids, as a compact JSON object keyed by binding name. Each namespace
|
|
# is distinct (create with `wrangler kv namespace create <BINDING>`). Kept out of
|
|
# the committed wrangler.jsonc (which uses "local" placeholders) and spliced in at
|
|
# deploy time. Required to deploy any worker with the matching KV binding.
|
|
# RECFLARE_KV='{"RECFLARE_MATCH_PRESENCE":"9f53f04b7dd244658d59f515a14748b6","RECFLARE_PLAYER_SETTINGS":"d33a90014e904b0eac720bddcbe0b036"}'
|
|
|
|
# Id of the shared Secrets Store that holds the `JWT_SECRET` signing key (create it
|
|
# with `wrangler secrets-store store create recflare --scopes workers`). Every
|
|
# worker binds this one store as JWT_SECRET so auth-signed tokens verify everywhere.
|
|
# Kept out of the committed wrangler.jsonc (which uses a "local" placeholder) and
|
|
# spliced in at deploy time. Required to deploy any worker.
|
|
# RECFLARE_SECRETS_STORE=00000000-0000-0000-0000-000000000000
|
|
|
|
# --- Server tuning (all optional; the shown value is the built-in default) ---
|
|
# Everything below is passed to the workers as a variable, named without the RECFLARE_
|
|
# prefix: RECFLARE_STARTING_TOKENS becomes STARTING_TOKENS. Every worker gets every knob —
|
|
# the ones that don't read a knob just ignore it — so nothing here has to be routed to a
|
|
# particular service, and two services reading the same knob agree on it for free. (The five
|
|
# settings above are the exception: they configure the deploy itself, not the workers.)
|
|
#
|
|
# The same values are used by `just deploy` and by `just dev`, so a knob is set in exactly
|
|
# one place. Change one and re-deploy the worker that reads it (e.g. `just deploy -F auth`)
|
|
# for it to take effect. Leave a line commented out and the worker uses its built-in
|
|
# default — and deleting a line you'd set really does restore that default on the next
|
|
# deploy.
|
|
#
|
|
# Don't set these in the Cloudflare dashboard — a deploy replaces a worker's variables
|
|
# wholesale, so a dashboard-set value is wiped by your next `just deploy`. This file is the
|
|
# durable place. (Actual secrets don't go here either: they live in the Cloudflare Secrets
|
|
# Store, like the shared JWT signing key above.)
|
|
|
|
# How many accounts one signup source may create (`auth`). Enforced on signup only,
|
|
# never on login: an existing account always stays reachable. Set either to 0 to turn
|
|
# that cap off entirely.
|
|
# ...PER_PLATFORM_ID counts accounts per Steam-verified identity — unspoofable.
|
|
# ...PER_IP counts accounts per signup IP — coarse, since a household, NAT or campus
|
|
# network shares one address. This is the one to raise (or zero out) if real players
|
|
# report being locked out.
|
|
# RECFLARE_MAX_ACCOUNTS_PER_PLATFORM_ID=3
|
|
# RECFLARE_MAX_ACCOUNTS_PER_IP=3
|
|
|
|
# How far a ban reaches beyond the account it was handed to (`match` and `auth`), as a
|
|
# comma-separated list out of `ip` and `platform` — or `off` for neither. Unset means
|
|
# BOTH, so a ban also blocks accounts sharing a proven platform identity or an IP with a
|
|
# banned one, and refuses a signup from either. Without that, an evader is back in the
|
|
# game with a new account in under a minute.
|
|
# ...`platform` matches a Steam/Meta identity the player PROVED — sharp, no false
|
|
# positives worth the name.
|
|
# ...`ip` matches the signup/last-login address — coarse. A household, dorm, campus or
|
|
# mobile carrier shares one address, so this arm bans the banned player's housemates
|
|
# along with them, and locks them out of signing up at all. Set BAN_EVASION_MATCH=platform
|
|
# to keep the sharp arm only, or off to make a ban apply to just the banned account.
|
|
# A ban ALWAYS applies to the account it was handed to, whatever this is set to.
|
|
# RECFLARE_BAN_EVASION_MATCH=ip,platform
|
|
|
|
# How many rooms one account may create (`rooms`) and how many clubs (`clubs`).
|
|
# Enforced on creation only — lowering either never touches what players already have,
|
|
# it just stops new ones. Set either to 0 to turn that cap off.
|
|
# ...ROOMS counts rooms the account created, minus their auto-provisioned dorm.
|
|
# ...CLUBS counts clubs the account created (subscription clubs don't count).
|
|
# RECFLARE_MAX_ROOMS_PER_ACCOUNT=10
|
|
# RECFLARE_MAX_CLUBS_PER_ACCOUNT=10
|
|
|
|
# Rooms to switch out at matchmake time (`match`), as comma-separated <fromRoomId>=<to>
|
|
# pairs, where <to> is a room id or room name. This is how a stock RRO room is replaced
|
|
# with your own: 2=MyHub sends everyone who matchmakes into the Rec Center (room 2) to the
|
|
# room named MyHub instead, whether the client asked for it by id or by name, and whether
|
|
# it came through the room list, a club's clubhouse, or a party. Substitution is a single
|
|
# hop (2=3,3=2 swaps the two rooms), a requested subroom is dropped in favour of the
|
|
# substitute's default one, and a target that doesn't exist leaves the original room in
|
|
# place. Following a friend or joining a specific instance is unaffected — those join a
|
|
# live instance, which is already in whichever room it was created in.
|
|
# RECFLARE_ROOM_REDIRECTS=2=MyHub
|
|
|
|
# RecCenterTokens a new player is granted, the first time their balance is read (`econ`).
|
|
# 0 means players start broke. Applies only to players who haven't been granted yet —
|
|
# raising it later does NOT top up existing players.
|
|
# RECFLARE_STARTING_TOKENS=10000
|
|
|
|
# Signup on the website is configured OUTSIDE this file: it's guarded by a Cloudflare
|
|
# Turnstile widget, and both of that widget's keys live in the shared Secrets Store
|
|
# (RECFLARE_SECRETS_STORE above), alongside JWT_SECRET — not as vars, not as worker secrets.
|
|
#
|
|
# wrangler secrets-store secret create <store-id> --name TURNSTILE_SITE_KEY \
|
|
# --scopes workers --remote
|
|
# wrangler secrets-store secret create <store-id> --name TURNSTILE_SECRET_KEY \
|
|
# --scopes workers --remote
|
|
#
|
|
# Setting them both is what opens web signup; with either missing it stays closed. See
|
|
# DEPLOYING.md. Accounts are still created by the game either way, and both `auth` account
|
|
# caps above apply regardless.
|