A personal finance management web app to track income, expenses, budgets and visualize financial health.
✔️ Add and manage multiple accounts
✔️ Track income and expenses
✔️ Categorize transactions
✔️ Budget creation & alerts
✔️ Financial summary dashboard
✔️ Export reports (CSV / Excel)
✔️ Optional authentication (if implemented)
This project is built with:
- Python – backend logic
- (Flask / Django / FastAPI) – web framework (replace with whichever your app uses)
- HTML, CSS, JavaScript – frontend
- SQLite / PostgreSQL – database (adjust accordingly)
- Docker – containerization
- docker-compose – multi-container setup
my-finance/
├── app/ # Application source code
├── Dockerfile # Docker container specification
├── docker-compose.yml # Compose services
├── requirements.txt # Python dependencies
├── .gitignore
├── LICENSE
└── README.md
- Clone the repository
git clone https://github.com/HarpyTech/my-finance.git
cd my-finance- Create a Python virtual environment
python3 -m venv venv
source venv/bin/activate # Linux / macOS
venv\Scripts\activate # Windows- Install dependencies
pip install -r requirements.txt- Configure environment variables
Copy the example environment file and configure your settings:
cp .env.example .envUpdate the .env file with your actual configuration. See SECRET-MANAGEMENT.md for secure credential management options.
Required Variables:
SECRET_KEY- JWT signing key (generate withopenssl rand -hex 32)MONGODB_URI- MongoDB connection stringDEFAULT_LOGIN_PASSWORD- Default user passwordACCESS_TOKEN_EXPIRE_MINUTES- JWT token expiration timeDEFAULT_USER_EMAIL- Default user emailDEFAULT_USER_NAME- Default user name
For production deployments, use credential managers instead of .env files. See 🔐 Secret Management below.
- Run the app
uvicorn app.main:app --reloadYour app should now be running at: http://localhost:8000 (or configured port)
If you prefer containerized setup:
docker build -t my-finance:latest .
docker-compose upEnvironment Configuration:
- Docker Compose automatically loads from
.envfile if present - If
.envis not found, it falls back to default values specified indocker-compose.yml - For production, use credential managers (see 🔐 Secret Management)
Using Credential Managers:
Windows (PowerShell):
.\load-secrets.ps1
docker-compose upLinux/macOS (Bash):
./load-secrets.sh
docker-compose upThe application will be available at http://localhost:8000 (if exposed via compose)
For secure credential management in production environments, this project supports multiple approaches:
-
Credential Managers (Recommended for Production)
- Windows: Credential Manager
- macOS: Keychain
- Linux: Secret Service (secret-tool)
-
Azure Key Vault (Enterprise)
-
Docker Secrets (Container Orchestration)
-
Environment Variables (Development Only)
Quick Start:
Windows:
# Load secrets from Windows Credential Manager
.\load-secrets.ps1Linux/macOS:
# Load secrets from system credential manager
./load-secrets.shFull Documentation:
See SECRET-MANAGEMENT.md for comprehensive setup instructions, examples, and best practices for each platform.
This repository includes branch-specific Cloud Run workflows:
.github/workflows/dev_deploy.ymldeploys pushes fromdevelop.github/workflows/prod_deploy.ymldeploys pushes frommain
Deployment flow:
- Build Docker image
- Push image to Artifact Registry
- Deploy image to Cloud Run
- Bind runtime environment variables from Google Secret Manager
Add these in GitHub: Settings -> Secrets and variables -> Actions -> Secrets.
Deployment Secrets
GCP_SA_KEY= full JSON of your GCP service account keyGCP_PROJECT_ID= your Google Cloud project IDGCP_REGION= Cloud Run region (optional)CLOUD_RUN_SERVICE= base Cloud Run service name, for examplefinance(the workflows append-devand-prodwhen needed)
Only deployment-scoped values should live in GitHub secrets.
The workflows no longer read application runtime values from GitHub secrets. Cloud Run now binds these directly from Google Secret Manager using the same names as the application environment variables.
Required Secret Manager secrets
SECRET_KEYDEFAULT_LOGIN_PASSWORDMONGODB_URI
Optional Secret Manager secrets
PROJECT_NAMEAPI_V1_STRACCESS_TOKEN_EXPIRE_MINUTESALGORITHMCORS_ORIGINSWEBAUTHN_RP_IDWEBAUTHN_RP_NAMEWEBAUTHN_ORIGINMONGODB_DBGEMINI_API_KEYGEMINI_MODELSMTP_HOSTSMTP_PORTSMTP_USERNAMESMTP_PASSWORDSMTP_USE_TLSSMTP_USE_SSLSMTP_TIMEOUT_SECONDSSMTP_FROM_EMAILSMTP_BCC_EMAILSSIGNUP_OTP_EXPIRY_MINUTESSIGNUP_OTP_LENGTH
Example:
echo -n "mongodb+srv://user:pass@cluster.example.mongodb.net/" | gcloud secrets create MONGODB_URI --data-file=-
echo -n "replace-with-a-long-random-secret" | gcloud secrets create SECRET_KEY --data-file=-
echo -n "replace-default-password" | gcloud secrets create DEFAULT_LOGIN_PASSWORD --data-file=-If a secret already exists, add a new version instead:
echo -n "new-value" | gcloud secrets versions add SECRET_KEY --data-file=-After the deployment secrets and Secret Manager entries are set, push to develop or main and the matching workflow will build and deploy to Cloud Run.
We welcome contributions! To contribute:
- Fork the repo
- Create your feature branch (
git checkout -b feature/xyz) - Commit your changes (
git commit -m "Add xyz") - Push to your fork (
git push origin feature/xyz) - Open a Pull Request
Please follow the code style and add tests where applicable.
This project is licensed under the MIT License — see the LICENSE file for details.
Created by HarpyTech – feel free to reach out with questions or suggestions!
[1] https://github.com/HarpyTech/my-finance "GitHub - HarpyTech/my-finance"