Skip to content

Environment Variable Inventory ​

Executive Overview — all summaries for decision-makers.

Keine Secrets in diesem Dokument. Werte nur in Render Dashboard / Azure / Cloudflare setzen.

Production — Backend (mqa-backend) ​

VariablePflichtBeschreibungQuelle
DATABASE_URL✅PostgreSQL Connection StringRender Postgres (auto)
NODE_ENV✅productionrender.yaml
PORT✅3000render.yaml
JWT_SECRET✅JWT Signing (min. 32 Zeichen)Render generate
CORS_ORIGIN✅https://portal.mqa.grouprender.yaml
FRONTEND_URL✅https://portal.mqa.grouprender.yaml
CRON_SECRET✅Header x-cron-secret für /api/jobs/runRender generate
SKIP_OAUTH_VALIDATION✅Muss false sein in Productionrender.yaml
OAUTH_CLIENT_ID✅Azure App RegistrationAzure Portal
OAUTH_CLIENT_SECRET✅Azure App SecretAzure Portal
OAUTH_TENANT_ID✅Azure Tenant IDAzure Portal
OAUTH_REDIRECT_URI✅https://api.mqa.group/api/auth/callbackAzure + Render
ANTHROPIC_API_KEY✅Claude APIAnthropic Console — siehe AI-SERVICES
OPENROUTER_API_KEY⚪Alternative LLM RouteOpenRouter — siehe AI-SERVICES
RESEND_API_KEY⚪E-Mail via ResendResend — siehe RESEND
MICROSOFT_SENDER_EMAIL⚪Graph E-Mail AbsenderAzure
R2_ACCOUNT_ID✅Cloudflare R2 AccountCloudflare (MQA-Org)
R2_ACCESS_KEY_ID✅R2 API KeyCloudflare
R2_SECRET_ACCESS_KEY✅R2 API SecretCloudflare
R2_BUCKET_NAME✅z.B. mqa-mediaCloudflare
R2_PUBLIC_URL✅Public R2 CDN URLCloudflare
ADMIN_MAINTENANCE_SECRET⚪/api/admin/maintenance/*openssl rand
EMAIL_WEBHOOK_SECRET⚪/api/email-tracking/deliveredopenssl rand
OPENSANCTIONS_API_KEY⚪KYC ScreeningOpenSanctions
HIDE_PORTAL_DEMO_CONTENT⚪Demo-Inhalte ausblendentrue in Prod

Production — Frontend (mqa-frontend) ​

VariablePflichtBeschreibung
VITE_API_BASE_URL✅https://api.mqa.group/api
VITE_APP_ENV✅production
VITE_DOCS_URL✅https://docs.mqa.group (externe VitePress-Site)
NODE_VERSION✅20

Niemals Secrets unter VITE_* — landen im Browser-Bundle.

Production — Developer Docs (mqa-docs) ​

VariablePflichtBeschreibung
DOCS_PASSWORD✅HTTP Basic Auth für docs.mqa.group — ohne Wert ist die Site öffentlich
DOCS_USERNAME⚪Basic-Auth-Benutzer (Default mqa)
PORT✅Von Render gesetzt
NODE_VERSION✅20

Staging (geplant) ​

Gleiche Keys wie Production, andere Werte:

  • CORS_ORIGIN / FRONTEND_URL → https://staging.portal.mqa.group
  • VITE_API_BASE_URL → https://staging.api.mqa.group/api
  • Eigene DATABASE_URL, JWT_SECRET, OAuth-App

Local Development ​

DateiGit
backend/.env❌ gitignored
.env.local❌ gitignored
backend/ENV_TEMPLATE.txt✅ Template

Rotation ​

SecretEmpfohlene FrequenzTrigger
JWT_SECRET12 MonateInvalidiert alle Sessions
CRON_SECRET12 MonateRender Cron Job Header updaten
R2 KeysBei Account-MigrationSofort
OAuth Secret24 Monate (Azure Policy)Azure Portal
ADMIN_MAINTENANCE_SECRETBei Team-WechselManuell

Siehe SECURITY-STATUS.