One .env file, read at container start. Real environment variables win over the file.
Database
| Variable | |
|---|
DB_NAME | Database name (hridasign) |
DB_USERNAME / DB_PASSWORD | Credentials |
POSTGRES_HOST | Server host (hrida-postgres in the bundled compose) |
SPRING_DATASOURCE_URL | Overrides the assembled JDBC URL if set |
Schema is managed by Hibernate ddl-auto — set it to validate for production once the schema is stable.
App & CORS
| Variable | |
|---|
APP_URL | Public origin — used to build the deep-links in invitation and OTP emails. https://sign.hrida.ai in production. Republished as APP_BASE_URL / APP_FRONTEND_BASE_URL / FRONTEND_URL. |
CORS_ALLOWED_ORIGINS | Comma-separated allow-list of browser origins |
FILE_UPLOAD_DIR | Base directory for uploads (a Docker volume) |
Auth & security
| Variable | |
|---|
JWT_SECRET | Signs session tokens. Long random string, never reused across environments. |
ADMIN_SETUP_KEY | Required to register the first platform admin |
Email — required
| Variable | |
|---|
MAIL_HOST / MAIL_PORT | SMTP server (smtp.gmail.com / 587) |
MAIL_USERNAME / MAIL_PASSWORD | Credentials — Gmail needs an App Password |
MAIL_FROM | Default From address |
CONTACT_TEAM_EMAIL | Where contact-form submissions go |
Optional integrations
| Feature | Variables |
|---|
| Cloudinary storage | CLOUDINARY_CLOUD_NAME, CLOUDINARY_API_KEY, CLOUDINARY_API_SECRET |
| OpenAI — AI PDF tools | OPENAI_API_KEY, OPENAI_OCR_MODEL (gpt-4.1-mini), OPENAI_API_URL |
| Razorpay — payments | RAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET, RAZORPAY_WEBHOOK_SECRET |
Leaving an integration's variables empty disables that feature — the app runs without any of them.
Ports
| Environment | Frontend | API | Database |
|---|
| Docker | 127.0.0.1:8084 → 8080 (one container) | same | external hrida-postgres |
| Local dev | 5173 (Vite) | 8080 | 5432 |