Files
treg/render.yaml
T
Jason ZhouandClaude Fable 5 8ca54c0c6f feat: treg.to is the canonical domain — treg.superdesign.dev becomes the legacy alias
public_url/email_from defaults, render.yaml, CLI fallbacks, packaging (npm/plugin/pyproject),
web pages (+canonical tag), docs and context fragments all move to https://treg.to.

The legacy host keeps serving the FULL API forever — installed CLIs, skill.md files and
.mcp.json configs in the wild hold Bearer tokens pointed at it, and HTTP clients strip
Authorization on cross-host redirects. Only browser-facing marketing pages 301 to treg.to
(new middleware + tests).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
2026-08-13 11:56:20 +10:00

108 lines
4.8 KiB
YAML

# Render Blueprint — deploys treg as one web service (API + dashboard + landing + tutorial +
# /llms.txt + /install.sh) backed by a managed Postgres. See docs/context/ops/deploy.md.
#
# The app is a single FastAPI service: `python -m treg` honors $PORT (Render routes + health-checks
# it). Web assets ship in the wheel via pyproject `force-include src/treg/web`, so `pip install .[server]`
# bundles everything — no separate frontend build. The `[server]` extra pulls the FastAPI/DB/crypto stack
# (the base install is the CLI only — see pyproject).
#
# Secrets (Fernet key, OAuth, Resend, admin/session tokens) are NOT in this file — they are set once
# in the Render dashboard (sync:false below marks them as dashboard-managed). The Postgres URL is
# auto-wired via fromDatabase; config.py rewrites postgres:// → postgresql+asyncpg:// at load.
databases:
- name: treg-db
databaseName: treg
region: oregon
plan: basic-256mb # smallest paid tier with persistence; bump later if needed
services:
- type: web
name: treg
runtime: python
region: oregon
plan: starter
branch: main
buildCommand: pip install ".[server]"
startCommand: python -m treg
healthCheckPath: /meta
autoDeploy: true
envVars:
# Postgres — auto-injected from the managed DB above (config.py adds the asyncpg driver).
- key: TREG_DATABASE_URL
fromDatabase:
name: treg-db
property: connectionString
# Public base URL — drives the OAuth callback, /meta, /llms.txt, /install.sh, all {BASE} links.
- key: TREG_PUBLIC_URL
value: https://treg.to
# Never return OTP codes in prod responses (account-takeover vector); email them via Resend.
- key: TREG_EMAIL_DEV_MODE
value: "false"
- key: TREG_EMAIL_FROM
value: tools-registry <no-reply@treg.to> # requires treg.to Verified in Resend before deploy
- key: PYTHON_VERSION
value: "3.12.7"
# Dashboard-managed secrets (paste values in Render; sync:false keeps them out of git).
- key: TREG_SECRET_KEY # Fernet key — MUST equal local .env verbatim (irreplaceable).
sync: false
- key: TREG_SESSION_SECRET
sync: false
- key: TREG_ADMIN_TOKEN
sync: false
- key: TREG_GITHUB_CLIENT_ID
sync: false
- key: TREG_GITHUB_CLIENT_SECRET
sync: false
- key: TREG_RESEND_API_KEY
sync: false
# Landing live-wire demo (optional — unset = sandbox calls all synthesize / webhook 404s).
- key: TREG_DEMO_STRIPE_KEY # Stripe sandbox restricted key (Charges only) for the live wire
sync: false
- key: TREG_DEMO_STRIPE_WEBHOOK_SECRET # whsec_… from the DEMO Stripe sandbox's webhook endpoint
sync: false
# Tier-4 platform keys: treg's OWN provider credentials, spent on a caller's behalf and metered
# against their prepaid balance (docs/PLATFORM-BALANCE-PLAN.md §Phase 3). A key alone does
# nothing — TREG_PLATFORM_PROVIDERS is the allow-list AND the kill switch: set it to "" to turn
# tier 4 off instantly, without a redeploy. Fund each provider account upstream first.
- key: TREG_PLATFORM_KEY_TIKHUB # TikHub API key (Authorization: Bearer)
sync: false
- key: TREG_PLATFORM_KEY_DATAFORSEO # base64 of "login:password" (HTTP Basic)
sync: false
- key: TREG_PLATFORM_KEY_SCRAPECREATORS # ScrapeCreators API key (x-api-key)
sync: false
- key: TREG_PLATFORM_KEY_BRIGHTDATA # Bright Data account API token (Authorization: Bearer)
sync: false
- key: TREG_PLATFORM_KEY_JUSTONEAPI
sync: false
- key: TREG_PLATFORM_KEY_SERPAPI
sync: false
- key: TREG_PLATFORM_KEY_MOZ # base64 of "access_id:secret_key" (HTTP Basic)
sync: false
- key: TREG_PLATFORM_KEY_SERANKING
sync: false
- key: TREG_PLATFORM_KEY_HUNTER
sync: false
- key: TREG_PLATFORM_KEY_LEADMAGIC
sync: false
- key: TREG_PLATFORM_KEY_LUSHA
sync: false
- key: TREG_PLATFORM_KEY_PDL
sync: false
- key: TREG_PLATFORM_KEY_DIFFBOT
sync: false
- key: TREG_PLATFORM_KEY_AKTA
sync: false
- key: TREG_PLATFORM_KEY_APIFY
sync: false
- key: TREG_PLATFORM_KEY_SERPSTAT # Serpstat API token (?token=…)
sync: false
- key: TREG_PLATFORM_KEY_SPYFU # SpyFu SECRET KEY alone (?api_key=…), not id/base64
sync: false
- key: TREG_PLATFORM_KEY_CORESIGNAL # Coresignal API key (`apikey` header)
sync: false
- key: TREG_PLATFORM_KEY_THECOMPANIESAPI # raw token, injected as "Basic {secret}" un-encoded
sync: false
- key: TREG_PLATFORM_PROVIDERS # e.g. "tikhub,dataforseo,scrapecreators"; "" = tier 4 off
value: ""