45b70b17f0
THE PAGE. The anonymous route rendered outside Shell, so it sat flush against
the viewport edge and read as a form rather than a product — which is the first
thing anyone at Prime Intellect sees when the link is shared. It now brings its
own chrome and leads with a hero; the platform track is a numbered course, the
concept tracks are a poster grid, and admin add/archive moved behind one Manage
toggle so they stop competing with the content. Verified in Chrome at 1440 and
393, light and dark: horizontal overflow is 0 in all three access states.
THE VIDEOS. Five ~30s walkthroughs, narrated in Karti's cloned voice through
Chatterbox and cut against real screen capture of the seeded demo book. The
audio is rendered FIRST and its measured duration drives the capture, because a
shot list that runs short leaves the narrator talking over a frozen frame and
one that runs long gets cut mid-sentence. Levels are loudness-normalised so
clips do not jump between videos.
Cap cannot take a programmatic upload — video.karti.ai needs an interactive
login — so PIG serves these itself. A native <video> on this origin needs no
iframe and therefore no CSP frame-src at all; Karti's own Cap recordings still
render through the existing iframe path, which is why the resolver is now a
discriminated union.
THREE THINGS THE VERIFIERS CAUGHT, all of which shipped green:
- createMediaRoutes was never mounted. Every layer landed — migration, seed,
both feeds, the bind mount, the docs — except the one that serves the bytes,
so /media/learn/* fell through to the SPA fallback and answered HTTP 200
text/html. The player showed a black box with working controls and no error.
The tests certified the route factory in isolation, which proves the handler
and says nothing about whether it is wired in. There is now an assertion
against the ASSEMBLED app, and it fails loudly on content-type — the failure
mode is a 200, not a 404.
- A symlink in the media directory escaped the root. resolve() is lexical and
stat() follows links, so the containment check this file's own header
promised did not hold. realpath before the check closes it.
- Vite proxied only /api, so self-hosted playback broke for anyone running the
app the documented way — in the same invisible 200-text/html manner.
Also: a duplicate media slug used to throw from the middle of seedDemo() and
take out every later section; it now reports and skips that one entry. And the
player has an onError state, because content-addressed filenames mean a
re-render deliberately leaves the old row pointing at a file that is gone.
The three DEMO platform rows are dropped — five real recordings supersede them,
and placeholders sitting under real ones made the page read as half-finished to
the audience it is meant to convince. The supply and demand concept rows stay:
there are no real recordings for those tracks yet, and an empty track hides the
shape of the page.
Tests 275, typecheck clean.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
171 lines
8.0 KiB
Bash
171 lines
8.0 KiB
Bash
# ---------------------------------------------------------------------------
|
|
# PIG — environment
|
|
# Copy to .env and fill in. Never commit .env.
|
|
# ---------------------------------------------------------------------------
|
|
|
|
# --- Database ---------------------------------------------------------------
|
|
# PIG owns this database exclusively. Do not point it at a database shared with
|
|
# another application.
|
|
DATABASE_URL=postgres://pig:CHANGEME@localhost:5432/pig
|
|
|
|
# --- Auth (Supabase) --------------------------------------------------------
|
|
# PIG uses Supabase for authentication ONLY. It stores no passwords and issues
|
|
# no sessions of its own; it verifies incoming JWTs against the project JWKS.
|
|
#
|
|
# IMPORTANT: authorization does NOT follow from having a Supabase account.
|
|
# A user must also have a row in PIG's `users` table. If this Supabase project
|
|
# is shared with another application, that application's users get nothing here
|
|
# until they are explicitly invited.
|
|
SUPABASE_URL=https://YOUR_PROJECT_REF.supabase.co
|
|
SUPABASE_ANON_KEY=
|
|
# Service key is only needed for administrative user provisioning. Omit it and
|
|
# PIG runs fine in invite-only mode. Treat it as the most powerful secret here.
|
|
SUPABASE_SERVICE_KEY=
|
|
|
|
# --- Auth: on-premises (OIDC) ---------------------------------------------
|
|
# Set PIG_OIDC_ISSUER to authenticate against your own identity provider —
|
|
# Okta, Entra, Keycloak, Auth0, Authentik, Google Workspace, anything
|
|
# standards-compliant. It TAKES PRECEDENCE over the Supabase values above, so
|
|
# an on-prem install can leave those in place.
|
|
#
|
|
# PIG never sees a password. It verifies the token your provider issued and
|
|
# reads two things: a stable subject, and an email. Everything else — teams,
|
|
# roles, capabilities — is PIG's own data keyed on that subject, so users are
|
|
# provisioned in PIG by invite, not by your directory.
|
|
PIG_OIDC_ISSUER=
|
|
# Optional. Discovered from the issuer's /.well-known/openid-configuration when
|
|
# omitted. Set it to skip discovery entirely on an air-gapped network.
|
|
PIG_OIDC_JWKS_URI=
|
|
# STRONGLY recommended. Without it, a token your provider issued for ANY other
|
|
# application in the same tenant is accepted here as a PIG session.
|
|
PIG_OIDC_AUDIENCE=
|
|
# Comma-separated, in preference order. Defaults to email,preferred_username,upn
|
|
# which covers most providers; Entra sometimes needs upn first.
|
|
PIG_OIDC_EMAIL_CLAIMS=
|
|
|
|
# --- Application ------------------------------------------------------------
|
|
PIG_PORT=8920
|
|
PIG_PUBLIC_URL=http://localhost:8920
|
|
NODE_ENV=development
|
|
|
|
# --- Learn videos, hosted by PIG ---------------------------------------------
|
|
# PIG serves its own Learn videos from disk, as a native <video> — no embed
|
|
# host, no iframe, and therefore nothing to add to the proxy's frame-src.
|
|
#
|
|
# PIG_MEDIA_DIR is where the application READS them. Running from source that
|
|
# is a path on this machine, relative to the repository root; in the container
|
|
# it is always /app/media and docker-compose sets it for you.
|
|
PIG_MEDIA_DIR=./media
|
|
#
|
|
# PIG_MEDIA_HOST_DIR is the HOST directory docker-compose bind-mounts there,
|
|
# read-only. Two names for the two sides of the mount, on purpose. It must
|
|
# exist before `compose up` — Docker creates a missing bind source as an empty
|
|
# root-owned directory, which serves 404s and cannot be written to without
|
|
# sudo. On the deployment host this is normally /opt/pig/media.
|
|
PIG_MEDIA_HOST_DIR=./media
|
|
#
|
|
# Filenames are CONTENT-ADDRESSED — `<slug>.<hash>.mp4` — because the files
|
|
# themselves are served without authentication while the listing behind
|
|
# /api/learn stays code-gated. The hash is what makes a URL unguessable. See
|
|
# deploy/README.md, "Learn videos", for the trade this makes and its cost.
|
|
|
|
# --- Deployment: which image to run -----------------------------------------
|
|
# Leave EMPTY to build from the working tree, which is what a development or
|
|
# self-hosted-from-source install wants. Set it to a published tag and
|
|
# scripts/deploy.sh pulls instead of building, and compose runs exactly that
|
|
# image for both the app and Piggy — never one version of each.
|
|
#
|
|
# Set automatically by scripts/autodeploy.sh; you only put it here to pin a
|
|
# specific release by hand.
|
|
# PIG_IMAGE=git.karti.ai/pig/pig:release-2026-08-13
|
|
PIG_IMAGE=
|
|
# The loopback port the app is published on. TLS belongs to the proxy in front.
|
|
PIG_HOST_PORT=8920
|
|
|
|
# Comma-separated emails granted platform-admin rights.
|
|
# Every address listed here MUST already have an account. An address listed but
|
|
# unregistered is a standing offer of admin to whoever claims it first.
|
|
PIG_ADMIN_EMAILS=
|
|
|
|
# Invite code gating self-serve profile creation. Rotate freely.
|
|
PIG_INVITE_CODE=
|
|
|
|
# --- Prime Intellect compute API -------------------------------------------
|
|
# Used to sync GPU availability into `inventory_listings`.
|
|
# Mint a key at https://app.primeintellect.ai/dashboard/tokens with the
|
|
# NARROWEST scope that works: `Availability -> Read`. PIG never provisions
|
|
# infrastructure and must not hold a key that could. Set an expiry.
|
|
PRIME_API_KEY=
|
|
PRIME_API_BASE=https://api.primeintellect.ai
|
|
# Rate limits are undocumented upstream; the sync backs off empirically.
|
|
PRIME_SYNC_ENABLED=false
|
|
PRIME_SYNC_INTERVAL_MINUTES=30
|
|
|
|
# --- Piggy (the in-app agent) ----------------------------------------------
|
|
# Piggy drains a leased queue and serves chat on an authenticated internal
|
|
# listener. Generate one internal token and give the same value to API + Piggy.
|
|
# Never publish the Piggy listener or put this token in a URL.
|
|
PIGGY_INFERENCE_API_KEY=
|
|
PIGGY_ENABLED=false
|
|
PIGGY_MODEL=nvidia/nemotron-3-nano-30b-a3b
|
|
PIGGY_INFERENCE_BASE=https://api.pinference.ai/api/v1
|
|
PIGGY_LEASE_SECONDS=300
|
|
PIGGY_INTERNAL_URL=http://127.0.0.1:8931
|
|
PIGGY_INTERNAL_TOKEN=
|
|
PIGGY_CHAT_HOST=127.0.0.1
|
|
PIGGY_CHAT_PORT=8931
|
|
# Only containers on a private network need this; never combine it with a
|
|
# published Piggy port.
|
|
PIGGY_CHAT_ALLOW_NON_LOOPBACK=false
|
|
|
|
# --- Deployment: the release poller -----------------------------------------
|
|
# Only relevant on a host running scripts/autodeploy.sh. These belong in
|
|
# /etc/pig/autodeploy.env (read by the systemd unit), not here — they are
|
|
# listed here so the whole deployment surface is in one file to read.
|
|
#
|
|
# The registry credential is NOT an environment variable. It is a file, mode
|
|
# 0600, holding a pull-only token and nothing else:
|
|
#
|
|
# /etc/pig/registry-token
|
|
#
|
|
# Mint it in Gitea as a token with `read:package` scope ONLY. A token that can
|
|
# write packages, or push to the repository, defeats the point: the reason CI
|
|
# cannot deploy to production is that no build-side credential should be able
|
|
# to change what production runs, and a write-capable token here reintroduces
|
|
# exactly that from the other end.
|
|
#
|
|
# PIG_REGISTRY_USER=pig-deploy # the Gitea user that owns the token
|
|
# PIG_REGISTRY=git.karti.ai
|
|
# PIG_IMAGE_REPO=pig/pig # Gitea lowercases the owner
|
|
# PIG_REGISTRY_TOKEN_FILE=/etc/pig/registry-token
|
|
# PIG_REPO_DIR=/opt/pig
|
|
# PIG_RELEASE_TAG_PREFIX=release-
|
|
#
|
|
# The public origin deploy.sh checks AFTER the container is healthy, to catch a
|
|
# proxy that is answering 200 with an empty body. Defaults to PIG_PUBLIC_URL
|
|
# above, then to the production origin.
|
|
# PIG_DEPLOY_PUBLIC_URL=https://primeintellectgrowth.com
|
|
# A string the real application always renders. Change it only if index.html's
|
|
# mount point changes.
|
|
# PIG_DEPLOY_PUBLIC_MARKER=<div id="root">
|
|
|
|
# --- Slack ------------------------------------------------------------------
|
|
SLACK_BOT_TOKEN=
|
|
SLACK_SIGNING_SECRET=
|
|
SLACK_APP_TOKEN=
|
|
|
|
# --- Buzz (https://github.com/block/buzz) -----------------------------------
|
|
# Buzz agents reach PIG through the MCP server, so no PIG-specific credential is
|
|
# required. These are only for PIG pushing notifications into a Buzz relay.
|
|
BUZZ_RELAY_URL=
|
|
NOTION_CLIENT_ID=
|
|
NOTION_CLIENT_SECRET=
|
|
NOTION_REDIRECT_URI=http://localhost:8920/api/imports/notion/oauth/callback
|
|
GOOGLE_CLIENT_ID=
|
|
GOOGLE_CLIENT_SECRET=
|
|
# Must use the PIG_PUBLIC_URL origin and exact /oauth/google/callback path.
|
|
GOOGLE_REDIRECT_URI=http://localhost:8920/oauth/google/callback
|
|
BUZZ_PRIVATE_KEY=
|
|
# Optional NIP-OA owner attestation JSON for an agent identity.
|
|
BUZZ_AUTH_TAG=
|