Worship Studio

Server configuration

Maintainer reference.

The account service uses Node.js 24 or newer. Copy account-service/.env.example to its local .env file and fill the server settings there.

  • DATABASE_URL and DATABASE_SSL_CA_PATH: database connection and trusted TLS certificate.
  • PUBLIC_ORIGIN: website HTTPS origin in production.
  • INSTALLER_PATH: private, validated Windows installer.
  • TRUSTED_PROXY_IPS: exact ingress addresses allowed to supply X-Real-IP. The ingress must overwrite that header.
  • RECOVERY_SECRET, RESEND_API_KEY and EMAIL_FROM: password recovery configuration. Use a verified sender domain.

Set ACCOUNT_SERVICE_URL before compiling a native release. Set NEXT_PUBLIC_SITE_URL before building the public website with npm run build:release.

Keep database passwords, recovery secrets and email API keys on the server. Never put them in NEXT_PUBLIC_*, source control or an installer. Ordinary app users do not need these settings.

For operating the app, see the Worship Studio guide.