Server configuration
Maintainer reference.
The account service uses Node.js 24 or newer. Copy account-service/.env.example to its local .env file and fill the server settings there.
DATABASE_URLandDATABASE_SSL_CA_PATH: database connection and trusted TLS certificate.PUBLIC_ORIGIN: website HTTPS origin in production.INSTALLER_PATH: private, validated Windows installer.TRUSTED_PROXY_IPS: exact ingress addresses allowed to supplyX-Real-IP. The ingress must overwrite that header.RECOVERY_SECRET,RESEND_API_KEYandEMAIL_FROM: password recovery configuration. Use a verified sender domain.
Set ACCOUNT_SERVICE_URL before compiling a native release. Set NEXT_PUBLIC_SITE_URL before building the public website with npm run build:release.
Keep database passwords, recovery secrets and email API keys on the server. Never put them in NEXT_PUBLIC_*, source control or an installer. Ordinary app users do not need these settings.
For operating the app, see the Worship Studio guide.