# Secret token — k8s pods must send this in X-Proxy-Token header (optional) # If empty or unset — token auth is disabled (open mode, protected by IP allowlist only) # Generate with: openssl rand -hex 32 PROXY_SECRET= # Allowed source CIDRs (comma-separated), leave empty to allow all (dev mode) # Example: "10.0.0.0/8,172.16.0.0/12" ALLOWED_CIDR=