build(qa): take the SMTP host, port and TLS flag from QA_ stack variables (#258) #259

Merged
bermudalamb merged 1 commits from chore/258-qa-smtp-stack-vars into main 2026-09-01 11:51:15 -05:00
Showing only changes of commit cbb0090579 - Show all commits
+18 -7
View File
@@ -37,6 +37,13 @@
# QA_SMTP_USER — Brevo SMTP login. Named QA_ for the same reason as the # QA_SMTP_USER — Brevo SMTP login. Named QA_ for the same reason as the
# QA_SMTP_PASSWORD database password: pasting production's variables in here # QA_SMTP_PASSWORD database password: pasting production's variables in here
# QA_SMTP_FROM must not silently work. # QA_SMTP_FROM must not silently work.
#
# Optional, each defaulting to the Brevo value it used to be hardcoded to, so
# QA can be aimed at another relay without editing this file:
# QA_SMTP_HOST — default smtp-relay.brevo.com
# QA_SMTP_PORT — default 587
# QA_SMTP_SECURE — default false. Brevo is STARTTLS on 587, so this stays
# false unless the relay is changed to an implicit-TLS one.
# ADMIN_GATE_SECRET — the shared secret Nginx Proxy Manager injects as the # ADMIN_GATE_SECRET — the shared secret Nginx Proxy Manager injects as the
# X-Admin-Gate header on the gated location. Both sides must # X-Admin-Gate header on the gated location. Both sides must
# hold the same value or the admin API returns 403. See #63. # hold the same value or the admin API returns 403. See #63.
@@ -80,13 +87,17 @@ services:
# flows — verification, password reset, favorite-sold alerts and the # flows — verification, password reset, favorite-sold alerts and the
# cart-reminder cron — cannot be regression tested without it. See #87. # cart-reminder cron — cannot be regression tested without it. See #87.
# #
# Host, port and secure are not secrets and are pinned here rather than # Host, port and secure are not secrets, and they are now settable from
# inherited: the mailer's fallbacks are Gmail's (smtp.gmail.com, 465, # the stack so QA can be pointed at a different relay without editing this
# TLS) and Brevo needs 587 with STARTTLS, which is why SMTP_SECURE is # file. Each keeps the Brevo value as its default rather than being left
# false. Getting these wrong fails at send time, not at boot. # to fall through: the mailer's own fallbacks are Gmail's (smtp.gmail.com,
- SMTP_HOST=smtp-relay.brevo.com # 465, TLS) and Brevo needs 587 with STARTTLS, so an unset variable with
- SMTP_PORT=587 # no default here would silently aim QA at Gmail and fail at send time
- SMTP_SECURE=false # rather than at boot. `:-` supplies the default only when the variable is
# unset or empty, so setting one still wins.
- SMTP_HOST=${QA_SMTP_HOST:-smtp-relay.brevo.com}
- SMTP_PORT=${QA_SMTP_PORT:-587}
- SMTP_SECURE=${QA_SMTP_SECURE:-false}
- SMTP_USER=${QA_SMTP_USER} - SMTP_USER=${QA_SMTP_USER}
- SMTP_PASSWORD=${QA_SMTP_PASSWORD} - SMTP_PASSWORD=${QA_SMTP_PASSWORD}
- SMTP_FROM=${QA_SMTP_FROM} - SMTP_FROM=${QA_SMTP_FROM}