{
  "manifest_version": "1.0.0",
  "template": {
    "id": "6d1692bf-153a-4743-9a2f-1fe7b1d9e3e3",
    "slug": "cap-screen-recording-and-sharing",
    "name": "Cap Screen Recording and Sharing",
    "description": "Record and share screen videos with links and comments. Loom alternative.",
    "url": "https://railway.com/deploy/cap-screen-recording-and-sharing",
    "upstream": {
      "image": "ghcr.io/capsoftware/cap-web@sha256:8ee4cbd3fd87f88f538831aed06c954c525db9c2426a62abeaf0ca307c5e1ce9"
    }
  },
  "services": [
    {
      "name": "Cap Media Server",
      "source": {
        "image": "ghcr.io/capsoftware/cap-media-server@sha256:2dc90e055447026d7ff70656344cde74ec91b9d458a6050d9be6040a7074b62b"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Bucket CORS",
      "source": {
        "image": "amazon/aws-cli:2.37.12"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "Cap Maintenance",
      "source": {
        "image": "curlimages/curl:8.22.0"
      },
      "needs_volume": false,
      "http": false
    },
    {
      "name": "MySQL",
      "source": {
        "image": "mysql:9.7.2"
      },
      "needs_volume": true,
      "volume_mount_path": "/var/lib/mysql",
      "http": false
    },
    {
      "name": "Cap",
      "source": {
        "image": "ghcr.io/capsoftware/cap-web@sha256:8ee4cbd3fd87f88f538831aed06c954c525db9c2426a62abeaf0ca307c5e1ce9"
      },
      "needs_volume": false,
      "http": true
    }
  ],
  "required_inputs": [
    {
      "key": "PORT",
      "service": "Cap Media Server",
      "description": "Port the media server listens on (Bun binds [::], dual-stack); used for the healthcheck.",
      "secret": false,
      "strategy": "default",
      "default": "3456"
    },
    {
      "key": "MEDIA_SERVER_WEB_ORIGIN",
      "service": "Cap Media Server",
      "description": "Cap's public origin; lets the media server fetch media through Cap's storage proxy with the shared secret.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MEDIA_SERVER_WEBHOOK_SECRET",
      "service": "Cap Media Server",
      "description": "Shared with Cap: references Cap.MEDIA_SERVER_WEBHOOK_SECRET (edit it there).",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_REGION",
      "service": "Bucket CORS",
      "description": "Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "BUCKET_NAME",
      "service": "Bucket CORS",
      "description": "Bucket to configure.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_ENDPOINT",
      "service": "Bucket CORS",
      "description": "Bucket S3 endpoint.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "PUBLIC_ORIGIN",
      "service": "Bucket CORS",
      "description": "Cap's public origin (used in the log line).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "AWS_ACCESS_KEY_ID",
      "service": "Bucket CORS",
      "description": "Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CORS_CONFIGURATION",
      "service": "Bucket CORS",
      "description": "CORS rule letting browsers on Cap's domain upload (multipart, needs ETag) and play recordings via presigned URLs. Add custom domains to AllowedOrigins and redeploy this service.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "AWS_SECRET_ACCESS_KEY",
      "service": "Bucket CORS",
      "description": "Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CRON_SECRET",
      "service": "Cap Maintenance",
      "description": "Shared with Cap: references Cap.CRON_SECRET (edit it there).",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CAP_INTERNAL_URL",
      "service": "Cap Maintenance",
      "description": "Cap's private address.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "MYSQLHOST",
      "service": "MySQL",
      "description": "Railway Private Domain Name.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "MYSQLPORT",
      "service": "MySQL",
      "description": "MySQL port.",
      "secret": false,
      "strategy": "default",
      "default": "3306"
    },
    {
      "key": "MYSQLUSER",
      "service": "MySQL",
      "description": "MySQL user, used for the Data panel.",
      "secret": false,
      "strategy": "default",
      "default": "root"
    },
    {
      "key": "MYSQL_URL",
      "service": "MySQL",
      "description": "URL to connect to MySQL.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "MYSQL_USER",
      "service": "MySQL",
      "description": "Application user created on first boot with full rights on MYSQL_DATABASE.",
      "secret": false,
      "strategy": "default",
      "default": "cap"
    },
    {
      "key": "MYSQLDATABASE",
      "service": "MySQL",
      "description": "Default database, used for Data panel.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MYSQLPASSWORD",
      "service": "MySQL",
      "description": "Root password, used for Data panel.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MYSQL_DATABASE",
      "service": "MySQL",
      "description": "Database created on first boot; Cap's DATABASE_URL points at it.",
      "secret": false,
      "strategy": "default",
      "default": "cap"
    },
    {
      "key": "MYSQL_PASSWORD",
      "service": "MySQL",
      "description": "Password of the application user (letters and digits only, it is embedded in a URL).",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "MYSQL_ROOT_PASSWORD",
      "service": "MySQL",
      "description": "Root password for MySQL DB.",
      "secret": true,
      "strategy": "generate",
      "generate": "strong_password"
    },
    {
      "key": "PORT",
      "service": "Cap",
      "description": "Port the Next.js server listens on; Railway routes traffic and healthchecks here.",
      "secret": false,
      "strategy": "default",
      "default": "3000"
    },
    {
      "key": "WEB_URL",
      "service": "Cap",
      "description": "Public URL of this Cap instance (share links, desktop app sign-in, OAuth callbacks). Change it when you add a custom domain.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_domain"
    },
    {
      "key": "CRON_SECRET",
      "service": "Cap",
      "description": "Bearer token for Cap's maintenance endpoints; Cap Maintenance references it.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "DATABASE_URL",
      "service": "Cap",
      "description": "MySQL connection string over the private network (Cap requires MySQL).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "NEXTAUTH_URL",
      "service": "Cap",
      "description": "Must equal WEB_URL; NextAuth builds its callback URLs from it.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_PATH_STYLE",
      "service": "Cap",
      "description": "Use path-style bucket URLs (Cap's default for non-AWS storage). Keep true: browser uploads depend on the bucket CORS rule set by Bucket CORS.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "CAP_AWS_BUCKET",
      "service": "Cap",
      "description": "Railway Bucket that stores recordings, thumbnails and exports.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CAP_AWS_REGION",
      "service": "Cap",
      "description": "Bucket region.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "MYSQL_WAIT_HOST",
      "service": "Cap",
      "description": "Host the start command waits for before booting; Cap migrates on boot and gives up after three quick attempts.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "NEXTAUTH_SECRET",
      "service": "Cap",
      "description": "Signs session tokens (32 random bytes, hex). Changing it signs everyone out.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "MEDIA_SERVER_URL",
      "service": "Cap",
      "description": "Private address of the ffmpeg media server.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "CAP_AWS_ACCESS_KEY",
      "service": "Cap",
      "description": "Bucket access key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "CAP_AWS_SECRET_KEY",
      "service": "Cap",
      "description": "Bucket secret key.",
      "secret": true,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_PUBLIC_ENDPOINT",
      "service": "Cap",
      "description": "S3 endpoint used in the presigned URLs browsers and the desktop app upload to and play from.",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "S3_INTERNAL_ENDPOINT",
      "service": "Cap",
      "description": "S3 endpoint for server-side calls (Railway Buckets have no private endpoint, so it equals the public one).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "reference_variable"
    },
    {
      "key": "DATABASE_ENCRYPTION_KEY",
      "service": "Cap",
      "description": "32-byte hex key that encrypts stored credentials (e.g. a user's own S3 keys). Never change it after first boot.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    },
    {
      "key": "MEDIA_SERVER_WEBHOOK_URL",
      "service": "Cap",
      "description": "Private address the media server calls back to (works because the start command binds to ::).",
      "secret": false,
      "strategy": "railway_provided",
      "railway_source": "railway_private_domain"
    },
    {
      "key": "CAP_VIDEOS_DEFAULT_PUBLIC",
      "service": "Cap",
      "description": "New recordings are viewable by anyone with the link (upstream default). Set false to make them private until shared.",
      "secret": false,
      "strategy": "default",
      "default": "true"
    },
    {
      "key": "MEDIA_SERVER_WEBHOOK_SECRET",
      "service": "Cap",
      "description": "Shared secret for media-server progress callbacks; Cap Media Server references it.",
      "secret": true,
      "strategy": "generate",
      "generate": "random_base64_32"
    }
  ],
  "deploy": {
    "mcp": {
      "server": "railway",
      "tool": "deploy_template",
      "args": {
        "template_code": "cap-screen-recording-and-sharing"
      }
    },
    "cli": "railway deploy --template cap-screen-recording-and-sharing",
    "api": {
      "method": "POST",
      "path": "/graphql/v2",
      "body": {
        "query": "mutation templateDeploy($input: TemplateDeployV2Input!) { templateDeployV2(input: $input) { projectId workflowId } }",
        "variables": {
          "input": {
            "templateId": "6d1692bf-153a-4743-9a2f-1fe7b1d9e3e3",
            "serializedConfig": {
              "buckets": {
                "6d038945-4959-5307-8a97-58d4232ec9b4": {
                  "name": "Bucket"
                }
              },
              "services": {
                "2faded53-7d3a-55d5-b180-fc93c3c7b444": {
                  "icon": "https://cdn.simpleicons.org/ffmpeg/007808",
                  "name": "Cap Media Server",
                  "deploy": {
                    "healthcheckPath": "/health",
                    "restartPolicyType": "ALWAYS",
                    "healthcheckTimeout": 300
                  },
                  "source": {
                    "image": "ghcr.io/capsoftware/cap-media-server@sha256:2dc90e055447026d7ff70656344cde74ec91b9d458a6050d9be6040a7074b62b"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port the media server listens on (Bun binds [::], dual-stack); used for the healthcheck.",
                      "defaultValue": "3456"
                    },
                    "MEDIA_SERVER_WEB_ORIGIN": {
                      "isOptional": true,
                      "description": "Cap's public origin; lets the media server fetch media through Cap's storage proxy with the shared secret.",
                      "defaultValue": "${{Cap.WEB_URL}}"
                    },
                    "MEDIA_SERVER_WEBHOOK_SECRET": {
                      "isOptional": true,
                      "description": "Shared with Cap: references Cap.MEDIA_SERVER_WEBHOOK_SECRET (edit it there).",
                      "defaultValue": "${{Cap.MEDIA_SERVER_WEBHOOK_SECRET}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "363ebbc9-fbb1-55dc-8c9e-cf7d5c2c6b67": {
                  "icon": "https://cdn.jsdelivr.net/gh/homarr-labs/dashboard-icons/svg/aws.svg",
                  "name": "Bucket CORS",
                  "deploy": {
                    "startCommand": "/bin/sh -c \"aws s3api put-bucket-cors --bucket $BUCKET_NAME --endpoint-url $S3_ENDPOINT --region $S3_REGION --cors-configuration \\\"$CORS_CONFIGURATION\\\" && echo 'Bucket CORS configured for' $PUBLIC_ORIGIN\"",
                    "restartPolicyType": "NEVER"
                  },
                  "source": {
                    "image": "amazon/aws-cli:2.37.12"
                  },
                  "variables": {
                    "S3_REGION": {
                      "isOptional": true,
                      "description": "Bucket region.",
                      "defaultValue": "${{Bucket.REGION}}"
                    },
                    "BUCKET_NAME": {
                      "isOptional": true,
                      "description": "Bucket to configure.",
                      "defaultValue": "${{Bucket.BUCKET}}"
                    },
                    "S3_ENDPOINT": {
                      "isOptional": true,
                      "description": "Bucket S3 endpoint.",
                      "defaultValue": "${{Bucket.ENDPOINT}}"
                    },
                    "PUBLIC_ORIGIN": {
                      "isOptional": true,
                      "description": "Cap's public origin (used in the log line).",
                      "defaultValue": "https://${{Cap.RAILWAY_PUBLIC_DOMAIN}}"
                    },
                    "AWS_ACCESS_KEY_ID": {
                      "isOptional": true,
                      "description": "Bucket access key.",
                      "defaultValue": "${{Bucket.ACCESS_KEY_ID}}"
                    },
                    "CORS_CONFIGURATION": {
                      "isOptional": true,
                      "description": "CORS rule letting browsers on Cap's domain upload (multipart, needs ETag) and play recordings via presigned URLs. Add custom domains to AllowedOrigins and redeploy this service.",
                      "defaultValue": "{\"CORSRules\":[{\"AllowedOrigins\":[\"https://${{Cap.RAILWAY_PUBLIC_DOMAIN}}\"],\"AllowedMethods\":[\"GET\",\"HEAD\",\"PUT\",\"POST\"],\"AllowedHeaders\":[\"*\"],\"ExposeHeaders\":[\"ETag\"],\"MaxAgeSeconds\":3600}]}"
                    },
                    "AWS_SECRET_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Bucket secret key.",
                      "defaultValue": "${{Bucket.SECRET_ACCESS_KEY}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "ae69d2e2-3228-5718-9a64-25e669a704fe": {
                  "icon": "https://cdn.simpleicons.org/curl/073551",
                  "name": "Cap Maintenance",
                  "deploy": {
                    "cronSchedule": "*/15 * * * *",
                    "startCommand": "/bin/sh -c \"for job in recover-failed-video-processing finalize-stale-desktop-segments; do curl -sS --max-time 240 --retry 2 --retry-delay 10 --retry-connrefused -o /dev/null -w \\\"$job: HTTP %{http_code} in %{time_total}s\\n\\\" -H \\\"Authorization: Bearer $CRON_SECRET\\\" \\\"$CAP_INTERNAL_URL/api/cron/$job\\\"; done\"",
                    "restartPolicyType": "NEVER"
                  },
                  "source": {
                    "image": "curlimages/curl:8.22.0"
                  },
                  "variables": {
                    "CRON_SECRET": {
                      "isOptional": true,
                      "description": "Shared with Cap: references Cap.CRON_SECRET (edit it there).",
                      "defaultValue": "${{Cap.CRON_SECRET}}"
                    },
                    "CAP_INTERNAL_URL": {
                      "isOptional": true,
                      "description": "Cap's private address.",
                      "defaultValue": "http://${{Cap.RAILWAY_PRIVATE_DOMAIN}}:3000"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  }
                },
                "b2cb5a5d-aa16-56a7-90a0-ddc88dae6a21": {
                  "icon": "https://devicons.railway.app/i/mysql.svg",
                  "name": "MySQL",
                  "deploy": {
                    "startCommand": "docker-entrypoint.sh mysqld --innodb-use-native-aio=0 --disable-log-bin --performance_schema=0 --innodb-buffer-pool-size=1G --character-set-server=utf8mb4 --collation-server=utf8mb4_unicode_ci --max-connections=1000",
                    "restartPolicyType": "ON_FAILURE",
                    "restartPolicyMaxRetries": 10
                  },
                  "source": {
                    "image": "mysql:9.7.2"
                  },
                  "variables": {
                    "MYSQLHOST": {
                      "isOptional": true,
                      "description": "Railway Private Domain Name.",
                      "defaultValue": "${{RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "MYSQLPORT": {
                      "isOptional": true,
                      "description": "MySQL port.",
                      "defaultValue": "3306"
                    },
                    "MYSQLUSER": {
                      "isOptional": true,
                      "description": "MySQL user, used for the Data panel.",
                      "defaultValue": "root"
                    },
                    "MYSQL_URL": {
                      "isOptional": true,
                      "description": "URL to connect to MySQL.",
                      "defaultValue": "mysql://${{ MYSQLUSER }}:${{ MYSQL_ROOT_PASSWORD }}@${{ RAILWAY_PRIVATE_DOMAIN }}:3306/${{ MYSQL_DATABASE }}"
                    },
                    "MYSQL_USER": {
                      "isOptional": true,
                      "description": "Application user created on first boot with full rights on MYSQL_DATABASE.",
                      "defaultValue": "cap"
                    },
                    "MYSQLDATABASE": {
                      "isOptional": true,
                      "description": "Default database, used for Data panel.",
                      "defaultValue": "${{ MYSQL_DATABASE }}"
                    },
                    "MYSQLPASSWORD": {
                      "isOptional": true,
                      "description": "Root password, used for Data panel.",
                      "defaultValue": "${{ MYSQL_ROOT_PASSWORD }}"
                    },
                    "MYSQL_DATABASE": {
                      "isOptional": true,
                      "description": "Database created on first boot; Cap's DATABASE_URL points at it.",
                      "defaultValue": "cap"
                    },
                    "MYSQL_PASSWORD": {
                      "isOptional": true,
                      "description": "Password of the application user (letters and digits only, it is embedded in a URL).",
                      "defaultValue": "{{MYSQL_PASSWORD}}"
                    },
                    "MYSQL_ROOT_PASSWORD": {
                      "isOptional": true,
                      "description": "Root password for MySQL DB.",
                      "defaultValue": "{{MYSQL_ROOT_PASSWORD}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {}
                  },
                  "volumeMounts": {
                    "4cf65b29-ee91-521c-983a-2850b4a750e0": {
                      "mountPath": "/var/lib/mysql"
                    }
                  }
                },
                "d046307a-2187-580c-a16b-127865406a42": {
                  "icon": "https://cdn.jsdelivr.net/gh/CapSoftware/Cap@a32e4806b3004071effe00243e1dabd52bc7068c/apps/web/public/logos/logo-solo.svg",
                  "name": "Cap",
                  "deploy": {
                    "startCommand": "/bin/sh -c \"i=0; until nc -w 3 $MYSQL_WAIT_HOST 3306 </dev/null >/dev/null 2>&1; do i=$((i+1)); if [ $i -ge 150 ]; then echo 'MySQL not reachable after 5 minutes'; exit 1; fi; echo 'waiting for MySQL'; sleep 2; done; HOSTNAME=:: exec node apps/web/server.js\"",
                    "healthcheckPath": "/api/status",
                    "restartPolicyType": "ALWAYS",
                    "healthcheckTimeout": 600
                  },
                  "source": {
                    "image": "ghcr.io/capsoftware/cap-web@sha256:8ee4cbd3fd87f88f538831aed06c954c525db9c2426a62abeaf0ca307c5e1ce9"
                  },
                  "variables": {
                    "PORT": {
                      "isOptional": true,
                      "description": "Port the Next.js server listens on; Railway routes traffic and healthchecks here.",
                      "defaultValue": "3000"
                    },
                    "WEB_URL": {
                      "isOptional": true,
                      "description": "Public URL of this Cap instance (share links, desktop app sign-in, OAuth callbacks). Change it when you add a custom domain.",
                      "defaultValue": "https://${{RAILWAY_PUBLIC_DOMAIN}}"
                    },
                    "CRON_SECRET": {
                      "isOptional": true,
                      "description": "Bearer token for Cap's maintenance endpoints; Cap Maintenance references it.",
                      "defaultValue": "{{CRON_SECRET}}"
                    },
                    "DATABASE_URL": {
                      "isOptional": true,
                      "description": "MySQL connection string over the private network (Cap requires MySQL).",
                      "defaultValue": "mysql://${{MySQL.MYSQL_USER}}:${{MySQL.MYSQL_PASSWORD}}@${{MySQL.RAILWAY_PRIVATE_DOMAIN}}:3306/${{MySQL.MYSQL_DATABASE}}"
                    },
                    "GROQ_API_KEY": {
                      "isOptional": true,
                      "description": "Optional Groq key: AI titles, summaries and chapters (preferred generation provider).",
                      "defaultValue": ""
                    },
                    "NEXTAUTH_URL": {
                      "isOptional": true,
                      "description": "Must equal WEB_URL; NextAuth builds its callback URLs from it.",
                      "defaultValue": "${{WEB_URL}}"
                    },
                    "S3_PATH_STYLE": {
                      "isOptional": true,
                      "description": "Use path-style bucket URLs (Cap's default for non-AWS storage). Keep true: browser uploads depend on the bucket CORS rule set by Bucket CORS.",
                      "defaultValue": "true"
                    },
                    "CAP_AWS_BUCKET": {
                      "isOptional": true,
                      "description": "Railway Bucket that stores recordings, thumbnails and exports.",
                      "defaultValue": "${{Bucket.BUCKET}}"
                    },
                    "CAP_AWS_REGION": {
                      "isOptional": true,
                      "description": "Bucket region.",
                      "defaultValue": "${{Bucket.REGION}}"
                    },
                    "OPENAI_API_KEY": {
                      "isOptional": true,
                      "description": "Optional OpenAI key: AI features fallback.",
                      "defaultValue": ""
                    },
                    "RESEND_API_KEY": {
                      "isOptional": true,
                      "description": "Resend API key for login-code and notification e-mails (HTTP API, works on every Railway plan). Without it, login codes are printed to this service's logs.",
                      "defaultValue": ""
                    },
                    "MYSQL_WAIT_HOST": {
                      "isOptional": true,
                      "description": "Host the start command waits for before booting; Cap migrates on boot and gives up after three quick attempts.",
                      "defaultValue": "${{MySQL.RAILWAY_PRIVATE_DOMAIN}}"
                    },
                    "NEXTAUTH_SECRET": {
                      "isOptional": true,
                      "description": "Signs session tokens (32 random bytes, hex). Changing it signs everyone out.",
                      "defaultValue": "{{NEXTAUTH_SECRET}}"
                    },
                    "ASSEMBLY_API_KEY": {
                      "isOptional": true,
                      "description": "Optional AssemblyAI key: automatic transcription and captions.",
                      "defaultValue": ""
                    },
                    "GOOGLE_CLIENT_ID": {
                      "isOptional": true,
                      "description": "Optional Google OAuth client ID for 'Sign in with Google' (callback: WEB_URL/api/auth/callback/google).",
                      "defaultValue": ""
                    },
                    "MEDIA_SERVER_URL": {
                      "isOptional": true,
                      "description": "Private address of the ffmpeg media server.",
                      "defaultValue": "http://${{Cap Media Server.RAILWAY_PRIVATE_DOMAIN}}:3456"
                    },
                    "ANTHROPIC_API_KEY": {
                      "isOptional": true,
                      "description": "Optional Anthropic key: AI chat features.",
                      "defaultValue": ""
                    },
                    "CAP_AWS_ACCESS_KEY": {
                      "isOptional": true,
                      "description": "Bucket access key.",
                      "defaultValue": "${{Bucket.ACCESS_KEY_ID}}"
                    },
                    "CAP_AWS_SECRET_KEY": {
                      "isOptional": true,
                      "description": "Bucket secret key.",
                      "defaultValue": "${{Bucket.SECRET_ACCESS_KEY}}"
                    },
                    "RESEND_FROM_DOMAIN": {
                      "isOptional": true,
                      "description": "Domain verified in Resend that e-mails are sent from, e.g. yourcompany.com.",
                      "defaultValue": ""
                    },
                    "S3_PUBLIC_ENDPOINT": {
                      "isOptional": true,
                      "description": "S3 endpoint used in the presigned URLs browsers and the desktop app upload to and play from.",
                      "defaultValue": "${{Bucket.ENDPOINT}}"
                    },
                    "GOOGLE_CLIENT_SECRET": {
                      "isOptional": true,
                      "description": "Optional Google OAuth client secret.",
                      "defaultValue": ""
                    },
                    "S3_INTERNAL_ENDPOINT": {
                      "isOptional": true,
                      "description": "S3 endpoint for server-side calls (Railway Buckets have no private endpoint, so it equals the public one).",
                      "defaultValue": "${{Bucket.ENDPOINT}}"
                    },
                    "DATABASE_ENCRYPTION_KEY": {
                      "isOptional": true,
                      "description": "32-byte hex key that encrypts stored credentials (e.g. a user's own S3 keys). Never change it after first boot.",
                      "defaultValue": "{{DATABASE_ENCRYPTION_KEY}}"
                    },
                    "MEDIA_SERVER_WEBHOOK_URL": {
                      "isOptional": true,
                      "description": "Private address the media server calls back to (works because the start command binds to ::).",
                      "defaultValue": "http://${{RAILWAY_PRIVATE_DOMAIN}}:3000"
                    },
                    "CAP_VIDEOS_DEFAULT_PUBLIC": {
                      "isOptional": true,
                      "description": "New recordings are viewable by anyone with the link (upstream default). Set false to make them private until shared.",
                      "defaultValue": "true"
                    },
                    "CAP_ALLOWED_SIGNUP_DOMAINS": {
                      "isOptional": true,
                      "description": "Comma-separated e-mail domains allowed to sign up, e.g. yourcompany.com. Empty = anyone who can receive the login code.",
                      "defaultValue": ""
                    },
                    "MEDIA_SERVER_WEBHOOK_SECRET": {
                      "isOptional": true,
                      "description": "Shared secret for media-server progress callbacks; Cap Media Server references it.",
                      "defaultValue": "{{MEDIA_SERVER_WEBHOOK_SECRET}}"
                    }
                  },
                  "networking": {
                    "tcpProxies": {},
                    "serviceDomains": {
                      "<hasDomain>:3000": {
                        "port": 3000
                      }
                    }
                  }
                }
              }
            }
          }
        }
      }
    }
  },
  "post_deploy": {
    "healthcheck": {
      "service": "Cap",
      "method": "GET",
      "path": "/api/status",
      "expect_status": 200
    }
  },
  "resources": {
    "expected_services": 5,
    "needs_volume": true
  },
  "generated_at": "2026-10-11T22:14:38.939Z",
  "generator_version": "0.1.0",
  "status": "degraded",
  "validated_at": "2026-10-11T18:54:33.619Z",
  "success_rate_30d": 0,
  "validation": {
    "last_run_id": "run_b4b1e3918b8a454f8371",
    "checks": [
      {
        "name": "workflow_completed",
        "passed": false,
        "detail": "Your workspace has been restricted. Please contact support to resolve this."
      }
    ]
  }
}
