Merchant & operations
Store and environment configuration
Configure database connections, email, application security, currencies, taxes, and persistent storage.
On this page
Separate server settings from merchant settings
Server configuration lives in environment variables and Laravel configuration. Merchant preferences live in the database and are edited in Admin. Keep a protected record of both as part of your backup plan. Editing a sender name in Admin does not configure SMTP, and changing a database preference does not update your web-server virtual host.
Set the production environment explicitly
Review these keys in the existing .env without replacing the file wholesale:
| Key | What to configure |
|---|---|
APP_ENV |
production for the deployed store |
APP_DEBUG |
false on any publicly accessible store |
APP_URL |
The actual HTTPS origin used by customers and payment callbacks |
APP_KEY |
Preserve the key generated during initial installation |
DB_CONNECTION |
mysql or mariadb for the selected database connection |
DB_HOST, DB_PORT |
Database endpoint; a local TCP example is 127.0.0.1 and 3306 |
DB_DATABASE, DB_USERNAME, DB_PASSWORD |
The dedicated application database and its credentials |
QUEUE_CONNECTION |
Set explicitly, for example database on a single VPS |
CACHE_STORE, SESSION_DRIVER |
Choose available persistent backends, such as database |
TRUSTED_PROXIES |
Only the addresses of reverse proxies you actually control |
Do not trust all proxies with *. Direct TLS termination does not need a proxy trust override. A wrong origin can cause insecure links, callback rejection, and login problems. The implementation is in application configuration, database configuration, and middleware setup.
Compensation journal
Core defines DB_COMPENSATION_CONNECTION, defaulting to compensation_journal, with its own DB_COMPENSATION_DATABASE. On MySQL/MariaDB the default database name is agovena_compensation. Host, port, username, and password inherit the main database settings unless overridden by their DB_COMPENSATION_* equivalents.
Provision and protect this database when using the independent journal. Do not silently point its connection at an unrelated database or assume the main migration/backup process includes it. Include the configured journal in your recovery inventory. Ask your operator to resolve a journal connection failure before attempting package lifecycle recovery.
Make email deliverable
The default mailer is log, which does not deliver customer email. For SMTP, set MAIL_MAILER=smtp and the provider's MAIL_HOST, MAIL_PORT, MAIL_SCHEME, MAIL_USERNAME, and MAIL_PASSWORD. Set MAIL_FROM_ADDRESS and MAIL_FROM_NAME to a sender your provider permits. Use the provider's actual connection requirements; do not copy credentials or guess an encryption setting.
The relevant keys are defined in config/mail.php. Admin → Settings → Mail supplies sender name, sender address, and reply-to preferences. Verify a real registration or order message in a mailbox, then inspect Admin → Email log and failed jobs if it does not arrive. A working SMTP connection is not proof of inbox delivery.
Review store settings before the first invoice
Under Admin → Settings, set language, timezone, base currency, automatic currency conversion, logo, seller name/address, document prefixes, and customer-registration policy. The settings registration defines these fields.
Use Admin → Currencies to manage active currencies and optional FX synchronization. Do not assume a provider accepts every enabled currency. Review product-specific prices after changing conversion policy.
Use Admin → Taxes and store settings to review tax behavior. The automatic source covers EU standard VAT rates, not every reduced rate or non-EU tax regime. Have an accountant validate your selling locations, invoice information, and exemptions. Remote FX and tax services require outbound HTTPS; see data-source attribution.
Apply changes and verify persistence
After server environment changes, clear stale configuration and restart long-running workers:
php artisan config:clear
php artisan queue:restart
php artisan agovena:doctor
A process manager must restart an exiting queue worker. If your deployment uses configuration caching, rebuild it only after confirming the intended values, and never publish a configuration dump. Laravel explains configuration caching.
Public media belongs in storage/app/public, exposed through public/storage. Private downloads and backups belong outside the web root. Preserve installed package files under storage/app/packages and the installation marker under storage/app/agovena when replacing releases. See filesystem configuration.