-
Notifications
You must be signed in to change notification settings - Fork 0
Getting Started
This mirrors the Quick Start in the README. It gets the app running locally in demo mode.
- Python 3.10 or 3.12 (CI runs both)
- SQLite (bundled with Python)
- Gunicorn for production; the dev server covers local work
python -m venv .venv
source .venv/Scripts/activate # PowerShell: .\.venv\Scripts\Activate.ps1
pip install -r requirements.txt
export SECRET_KEY="replace-with-a-local-secret"
flask --app shyne.py init-db
python shyne.pyOpen http://localhost:8000/login. With no runtime set, the app starts in demo mode (APP_RUNTIME=demo-dev), and init-db reseeds demo data every time it runs.
flask --app shyne.py init-db seeds four deterministic users, all with the password demo:
| Role | |
|---|---|
superadmin@demo.com |
Superadmin |
staffoperator@demo.com |
Staff Operator |
inventoryproduction@demo.com |
Inventory / Production |
devadmin@demo.com |
Dev Admin |
Use them for local demo and development only. The Dev Admin account stays hidden from the Users & Access table and is the one seeded role with /admin/ console access.
For a real internal deployment, skip init-db and use the schema-only path:
export APP_RUNTIME=live-prod
export SECRET_KEY="non-demo-secret-from-outside-git"
flask --app shyne.py init-live-db
flask --app shyne.py create-admin --email owner@shynebeauty.com
gunicorn -w 1 --threads 4 --bind 127.0.0.1:8000 "shyne_app.app:app"Live mode requires an explicit APP_RUNTIME=live-prod. Put gunicorn behind nginx or Caddy. Live forces SESSION_COOKIE_SECURE=True and rejects FLASK_DEBUG. Admin passwords must clear the web password policy: at least 12 characters, no fragments of the email, and no demo fallbacks. MFA is opt-in and managed from /account/settings.
| Variable | Default | Purpose |
|---|---|---|
SECRET_KEY |
required | Flask session signing |
APP_RUNTIME |
demo-dev |
demo-dev or live-prod
|
DATABASE_URL |
runtime default | Business DB override |
AUTH_DATABASE_URL |
runtime default | Auth DB override |
SHYNE_LOG_DIR |
instance/logs |
Log directory |
SESSION_COOKIE_SECURE |
runtime-dependent | Force only when behind HTTPS |
TRUST_PROXY_HEADERS |
false |
Set true only behind a trusted proxy |
FLASK_DEBUG |
false |
Dev only; blocked under live-prod |
With both database URLs unset, the runtime picks SQLite files under instance/: shynebeauty_demo.db and shynebeauty_demo_auth.db for demo, shynebeauty_live.db and shynebeauty_live_auth.db for live.
flask --app shyne.py export-data writes a timestamped .tar.gz of both database files plus a SHA-256 hash file. Stop the app before copying or restoring files by hand, and back up the business and auth files together.