#!/usr/bin/env bash set -euo pipefail REPO_DIR="." SECRETS_DIR="$REPO_DIR/data/secrets" RUNTIME_ENV="$SECRETS_DIR/runtime.env" # 1️⃣ Create secrets folder mkdir -p "$SECRETS_DIR" # 2️⃣ Generate per‐install secrets DB_USER="postgres" DB_PASS="$(openssl rand -hex 16)" DB_NAME="lnbitsdb" FLASK_SECRET="$(openssl rand -hex 32)" DATABASE_URL="postgresql://${DB_USER}:${DB_PASS}@db:5432/${DB_NAME}" # 3️⃣ Write runtime.env cat > "$RUNTIME_ENV" <