docs: document Space Secrets / env vars for operators
Browse filesDocument required env var names for operators. No secret values included.
README.md
CHANGED
|
@@ -43,3 +43,28 @@ npm run build
|
|
| 43 |
## Deployment
|
| 44 |
|
| 45 |
This repository is configured as a **Docker Space** and serves the Next.js app on port `7860`.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 43 |
## Deployment
|
| 44 |
|
| 45 |
This repository is configured as a **Docker Space** and serves the Next.js app on port `7860`.
|
| 46 |
+
|
| 47 |
+
|
| 48 |
+
## Environment variables (Space Secrets)
|
| 49 |
+
|
| 50 |
+
Set these in **Settings → Variables and secrets** on the Space. Do **not** commit values to git.
|
| 51 |
+
|
| 52 |
+
| Name | Required | Purpose |
|
| 53 |
+
|------|----------|---------|
|
| 54 |
+
| `SESSION_SECRET` | Yes | Signs session cookies (`src/lib/session.ts`). Use a long random string; rotate if leaked. |
|
| 55 |
+
| `HF_OAUTH_CLIENT_ID` | Yes* | Hugging Face OAuth app client id (`src/lib/huggingface.ts`). |
|
| 56 |
+
| `HF_OAUTH_CLIENT_SECRET` | Yes* | OAuth app client secret — Space **Secret** only. |
|
| 57 |
+
| `HF_DATASET_REPO` | Yes* | Target dataset repo for signup writes (e.g. `org/name`). |
|
| 58 |
+
| `HF_DATASET_WRITE_TOKEN` | Yes* | Write-scoped Hub token for that dataset — Space **Secret** only; least privilege. |
|
| 59 |
+
| `APP_URL` | Recommended | Public Space URL used for OAuth redirects (e.g. `https://humanitys-last-hackathon-signup.hf.space`). |
|
| 60 |
+
| `HF_HUB_URL` | Optional | Hub base URL; defaults to `https://huggingface.co`. |
|
| 61 |
+
| `NODE_ENV` | Set by Docker | `production` in the Space image. |
|
| 62 |
+
|
| 63 |
+
\*Required when using the full HF OAuth + dataset write path. If the live page only deep-links to HF registration, some OAuth vars may be unused — verify against current `page.tsx` / API routes before rotating.
|
| 64 |
+
|
| 65 |
+
### Operator checks
|
| 66 |
+
|
| 67 |
+
1. Secrets exist in the Space UI (not in the repo).
|
| 68 |
+
2. `SESSION_SECRET` is unique to this Space and not reused elsewhere.
|
| 69 |
+
3. `HF_DATASET_WRITE_TOKEN` is scoped to the signup dataset only; rotate after staff changes.
|
| 70 |
+
4. OAuth redirect URI in the HF OAuth app matches `APP_URL` + the callback route under `/api/auth/huggingface/callback`.
|