# Copy to chrome/.env on the home machine. Never commit the real .env. # # This file configures the browser unit only. It is separate from the API # stack's ../.env on purpose: the two run on different machines. # The address the CDP port is published on — required, no default. # # Use this machine's **tailnet IP**, e.g. 100.x.y.z (`tailscale ip -4`). Not # 0.0.0.0, not the LAN address: CDP has no authentication of its own, so # anything that can reach this port has full control of the browser and a # foothold on this host. Tailscale device identity plus an ACL is the access # control; the bind address is what enforces it. # # For a throwaway local test, 127.0.0.1 is fine — but then only this machine # can reach it, so the API must run here too. # Left commented so `cp .env.example .env && docker compose up` fails with the # variable's own message telling you what to set, rather than Docker rejecting # "100.x.y.z" as an invalid IP. # BROWSER_BIND_ADDR=100.x.y.z # Clock zone the browser reports. Any real zone works and it need not match # the egress IP's country — but it must not be UTC, which is itself the bot # signal that stops the challenge clearing. The measurement is in entrypoint.sh. # # Unset falls back to the host's /etc/timezone, which is a real zone whenever # the host clock is set to local time. Set this when the host runs UTC — a UTC # server is exactly the case that fails. # BROWSER_TZ=Asia/Jakarta