-
Notifications
You must be signed in to change notification settings - Fork 8
Advanced Setup
Once you have the starter kit up and running (see the Quick Start guide if you still need to do so), you can set up some of its more advanced features.
- Access From Native Apps
- Authentication Via Third Party Providers
- Outgoing Email
- Attachment Library
- Multi-threading
If you wish to allow API-based access for native apps, set the following environment variable:
APP_ACCESS_TOKEN=<Some random string>
From your native app, you must then send this token with each request, thru the 'X-App-Access-Token' header.
By default, the app is configured to support authentication via third party providers. If you don't need this functionality, do the following:
- Comment out the
:omniauthable ...line in /app/models/user.rb - Comment out the
omniauth_callbacks: 'users/omniauth_callbacks'line within thedevise_forblocks in /config/routes.rb
To allow authentication via Facebook, create a Facebook app if you haven't already, and set the following environment variables:
FACEBOOK_APP_ID=<Your Facebook App ID>
FACEBOOK_APP_SECRET=<Your Facebook App Secret>
To allow authentication via Google, create some Google OAuth2 credentials if you haven't already, and set the following environment variables:
GOOGLE_CLIENT_ID=<Your Google OAuth2 client ID>
GOOGLE_CLIENT_DECRET=<Your Google OAuth2 client secret>
To disable authentication via either one of Facebook or Google, modify the :omniauthable ... line in /app/models/user.rb appropriately (it is self-explanatory).
To set up outgoing email, set the following environment variables:
APPLICATION_HOST=<The URL serving your application>
SMTP_ADDRESS=<The SMTP server address>
SMTP_PORT=<The SMTP server port>
SMTP_USER_NAME=<Your SMTP user name>
SMTP_PASSWORD=<Your SMTP password>
SMTP_AUTHENTICATION=<The SMTP authentication strategy>
SMTP_ENABLE_STARTTLS_AUTO=<true or false>
The APPLICATION_HOST variable is required for development and production. The others are only required in production. You need only set them in development if you want to send real emails in development.
In fact, the SMTP settings can even be supplied via the admin UI, so strictly speaking the SMTP_XXX environment variables need not be set. However, it is probably a good idea to set them anyway since they become the fallback in case the admin does not supply them.
If you wish to use the attachment library for file upload management, attaching uploads to models, and viewing them, set the following environment variables. This requires some work, but is worth it!
AWS_ACCESS_KEY_ID=<Your AWS Access Key ID>
AWS_SECRET_ACCESS_KEY=<Your AWS Secret Access Key>
AWS_REGION=<The AWS region you are operating out of>
AWS_S3_BUCKET=<The S3 bucket you want to store your uploads in>
AWS_CF_KEY_PAIR_ID=<The CloudFront Key Pair Id>
AWS_CF_PRIVATE_KEY=<Contents of the Key Pair .pem file (see below)>
AWS_CF_DISTRIBUTION=<The CloudFront distribution linked to the bucket, starting with the protocol (http:// or https://)>
JW_PLAYER_ACCOUNT_TOKEN=<JWPlayer account token>
And only for production, set this too:
DRAGONFLY_CDN=<The CDN used to serve Dragonfly (gem) processed images such as thumbnails etc.>
The origin of the Dragonfly CDN must be set to the domain name of your app.
We recommend you provision an AWS IAM user with limited permissions, so that all unrelated AWS data remains secure. These permissions must of course include uploading and deleting objects from the bucket.
Also ensure that the bucket allows CORS, including the DELETE method: http://docs.aws.amazon.com/AmazonS3/latest/dev/cors.html
Our opinionated view is that S3 objects must always be accessed through the CloudFront CDN, rather than directly. To set up CloudFront, see http://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/PrivateContent.html
Also create a CloudFront Key Pair, to be used for generating signed URLS for protected access to your S3 objects. This Key Pair will be available for download as a .pem file.
Set AWS_CF_PRIVATE_KEY to the entire contents of the .pem file as one long string, manually inserting a \n at the end of each line. If setting via the command line, you should enclose the contents within double quotes.
For playing back video attachments, we provide JWPlayer (an HTML5 and Flash based video player) integration out of the box. If you haven't already, you will need to sign up for an account at http://www.jwplayer.com/sign-up, so you can get an account token.
If you want to use another player, you'll need to provide your own Angular directive for it (easy enough). In this case, you need not set the JW_PLAYER_ACCOUNT_TOKEN environment variable.
The Puma web server supports concurrent request handling, by allowing multiple worker processes per machine and multiple threads per worker.
If you wish to customize worker and/or thread concurrency, set any or all of the following environment variables:
WEB_CONCURRENCY=<Number of simultaneous worker processes>
MAX_THREADS=<Max number of threads per worker>
The defaults are 3 and 5 respectively.
IMPORTANT: Although we believe the app to be thread-safe, there is no way to guarantee it! If you encounter any race conditions, starvation or deadlock, just set MAX_THREADS to 1 (for now).