One asset per invoice from a registry (lib/crypto_asset.rb): BTC, LTC,
ETH, XMR, SOL, ALGO, USDT/USDC on ERC-20/TRC-20/BEP-20/Solana/Algorand.
Migration 003 generalizes the ltc_* columns to crypto_* + crypto_coin
(existing LTC invoices backfilled). QR payload adapts per asset: BIP21
amount URIs where supported, bare address for tokens with a network
hint on the PDF. Default addresses come from the CRYPTO_ADDRESSES
secret (JSON code=>address); LTC_ADDRESS still works as legacy.
Extends the .env heredoc the workflow drops on the prod host with:
- ADMIN_USER / ADMIN_PASSWORD — gate /admin/*
- DATABASE_URL — points at the storage stack's Postgres
- S3_* (endpoint, bucket, creds) — MinIO; S3_PUBLIC_ENDPOINT is the
s3.asxp.io hostname used only for
presigning so browser-facing URLs
resolve over Traefik+TLS.
Non-secret values stay hardcoded in the workflow; secrets come from
Forgejo. ASXPIO_DB_PASSWORD / S3 creds must match the corresponding
secrets on the storage repo or the app can't authenticate.