# Copy to chrome/.env on the home machine. Never commit the real .env. # # This file configures the browser unit only. It is separate from the API # stack's ../.env on purpose: the two run on different machines. # The address the CDP port is published on — required, no default. # # Use this machine's **tailnet IP**, e.g. 100.x.y.z (`tailscale ip -4`). Not # 0.0.0.0, not the LAN address: CDP has no authentication of its own, so # anything that can reach this port has full control of the browser and a # foothold on this host. Tailscale device identity plus an ACL is the access # control; the bind address is what enforces it. # # For a throwaway local test, 127.0.0.1 is fine — but then only this machine # can reach it, so the API must run here too. BROWSER_BIND_ADDR=100.x.y.z # Clock zone the browser reports. A UTC clock is itself the bot signal — # Cloudflare treats it as the datacenter default — and kagane's challenge then # never clears. Measured 2026-08-08, identical container, one Indonesian egress # IP: UTC never cleared in 60s (twice); Asia/Jakarta and America/New_York both # cleared in 4s. So any real zone works; it does not have to match the IP's # country, it just must not be UTC. # # Unset falls back to the host's /etc/timezone, which is a real zone whenever # the host clock is set to local time. Set this when the host runs UTC — a UTC # server is exactly the case that fails. # BROWSER_TZ=Asia/Jakarta