Configuration
Datasource, broker, security, station time, scheduler, and frontend deployment configuration.
SmartGare is station-agnostic. Deployment differences belong in environment configuration, referential records, or effective-dated rules.
Backend configuration groups
| Concern | Configuration |
|---|---|
| Database | DATABASE_URL or standard Spring datasource properties |
| Kafka | KAFKA_BOOTSTRAP_SERVERS and Spring Kafka settings |
| JWT | JWT_ISSUER_URI plus deployment authority mapping |
| CORS | Explicit allowed origins; closed by default |
| Rules | Station timezone and activation delay |
| Permit expiry | Enabled flag, timezone, warning horizons, cron |
| Modulith events | Publication completion and republishing behavior |
| Management | Actuator port, exposure, readiness groups |
DATABASE_URL supports standard PostgreSQL URI forms and percent-encoded
credentials. Another database scheme is rejected rather than guessed.
Station time
Every business date comes from configured station time, not the server's local zone or a browser clock. Rules effective inputs and permit expiry share that principle.
Use an IANA timezone such as Africa/Casablanca. Missing or invalid timezones
must stop startup for components that cannot decide safely without one.
Frontend deployment
The shared edge gateway exposes one public station origin and keeps upstream services private.
| Public path | Upstream |
|---|---|
/realms/* | Keycloak, excluding master administration |
/counter/* | Counter static application |
/console/* | Back-office SSR application |
/api/* | SmartGare backend with /api stripped |
Back-office runtime configuration includes its public origin, session secret, API URL, OIDC authority, and confidential client credentials. Counter and supervision receive only allowlisted public configuration.
Keep secrets out of builds and docs
Refer to credentials by variable name. Never print, copy, document, or embed their values in client bundles, examples, logs, screenshots, or generated artifacts.