Files
treg/deploy/render.example.yaml

56 lines
2.0 KiB
YAML

# Generic Render Blueprint for a self-hosted registry.
#
# Copy this file into your own deployment repository and adjust names, region,
# plans and environment variables. The treg.to production topology and settings
# are intentionally maintained in the private treg-internal repository:
# https://github.com/superdesigndev/treg-internal/blob/main/docs/production/deploy.md
databases:
- name: registry-db
databaseName: registry
region: oregon
plan: basic-256mb
services:
- type: web
name: registry
runtime: python
region: oregon
plan: starter
branch: main
# Install exactly what uv.lock records, so the running service carries the dependency set CI
# tested. A plain `pip install ".[server]"` resolves afresh on every build and picks up whatever
# a dependency published since; that is how a breaking upstream release reaches production
# without any commit. `--locked` fails the build when the lock is stale instead of resolving.
buildCommand: bash scripts/build-web.sh
preDeployCommand: python -m treg upgrade
startCommand: python -m treg
healthCheckPath: /meta
envVars:
# Render adds uv to the Python runtime when uv.lock is present; its default is older than the
# `required-version` in pyproject.toml, so name one it accepts.
- key: NODE_VERSION
value: "22.22.0"
- key: UV_VERSION
value: "0.12.3"
- key: TREG_DATABASE_URL
fromDatabase:
name: registry-db
property: connectionString
- key: TREG_PUBLIC_URL
value: https://registry.example.com
- key: TREG_EMAIL_DEV_MODE
value: "false"
- key: TREG_SECRET_KEY
sync: false
- key: TREG_SESSION_SECRET
sync: false
- key: TREG_GITHUB_CLIENT_ID
sync: false
- key: TREG_GITHUB_CLIENT_SECRET
sync: false
- key: TREG_RESEND_API_KEY
sync: false
- key: TREG_EMAIL_FROM
value: registry <no-reply@registry.example.com>