# Container deployment: remote admin UI, PostgreSQL, built-in accounts.
# Required environment: MCPHUB_PUBLIC_URL,
# MCPHUB_ADMIN_PUBLIC_URL, MCPHUB_CONFIG_KEY,
# MCPHUB_DATABASE_URL (Compose builds this from MCPHUB_POSTGRES_PASSWORD).
# Both listeners bind all container interfaces; compose.postgres.yaml publishes
# them only on host loopback. For a direct host deployment, change BOTH listen
# values to 127.0.0.1:<port>, or a protected private address, before starting.
# See deploy/README.md / deploy/README.zh-CN.md for HTTPS and identity setup.
# Initialize the administrator locally before signing in.

server:
  listen: ":8080"
  public_url: ${MCPHUB_PUBLIC_URL}
auth:
  mode: builtin
  # Enterprise membership must be reverified within this interval.
  # 企业成员关系需在此期限内重新验证。
  enterprise_membership_max_age: 24h
admin:
  enabled: true
  mode: remote
  listen: ":8081"
  public_url: ${MCPHUB_ADMIN_PUBLIC_URL}
  client_id: mcphub-admin
  required_scopes: [mcphub:admin]
  database_driver: postgres
  # Environment variable NAMES. Do not put a DSN/key or ${...} here.
  # Retain the same Base64-encoded 32-byte encryption key across restarts.
  database_dsn_env: MCPHUB_DATABASE_URL
  encryption_key_env: MCPHUB_CONFIG_KEY

# Register services in the admin UI/API. YAML backends seed an empty DB only once.
client_authorization:
  enabled: true
  require_client_grant: true
  client_id: mcphub-portal

backends: []
