-
Notifications
You must be signed in to change notification settings - Fork 1
Expand file tree
/
Copy path.env.example
More file actions
86 lines (75 loc) · 4.45 KB
/
Copy path.env.example
File metadata and controls
86 lines (75 loc) · 4.45 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
# keepIT — environment variables (example). Copy to `.env`.
#
# This file is consumed in two different ways depending on how you run keepIT:
#
# 1) Docker Compose (docker-compose.yml): Compose reads ONLY the four interpolation vars in the
# "Docker Compose" section below. The stack sets every other app setting itself, so the
# `Foo__Bar` app vars further down do NOT reach the Compose containers.
# 2) Single-container image via `docker run --env-file .env …` (or the Unraid template fields):
# there the `Foo__Bar` app vars ARE injected into the container and override appsettings.json.
# ASP.NET maps "__" to config nesting, so Jwt__Issuer == the "Jwt": { "Issuer": … } setting.
# =============================================================================
# Docker Compose — the ONLY vars the Compose stack reads from this file.
# =============================================================================
# REQUIRED: a random secret of at least 32 characters (the stack refuses to start without it).
JWT_KEY=
# Postgres password, shared by the db and api services (defaults to "keepit" if unset).
POSTGRES_PASSWORD=keepit
# Refresh-cookie Secure flag for the stack (default true; also works on http://localhost). Set
# false only to reach the stack over plain HTTP on a non-localhost address (e.g. a LAN IP).
# Requests over HTTPS get a Secure cookie either way.
# REFRESH_COOKIE_SECURE=true
# Trusted reverse-proxy hops in front of the API (per-IP rate limiting). MUST match your topology:
# 1 = bare stack (browser → nginx → api) [default]
# 2 = behind another proxy, e.g. Traefik (Traefik → nginx → api)
# FORWARDED_PROXY_HOPS=1
# Whether new accounts may be created (default true). On an internet-exposed personal instance,
# register your accounts first, then set this false to close public sign-up.
# ALLOW_REGISTRATION=true
# =============================================================================
# App config — for the single-container image (`docker run --env-file` / Unraid), NOT Compose.
# Uncomment and set when injecting these straight into a container; each overrides appsettings.json.
# =============================================================================
# Runtime: Production (default), or Development for verbose logs + the Scalar API explorer at /scalar/v1.
# ASPNETCORE_ENVIRONMENT=Production
# JWT — Jwt__Key is REQUIRED in production (a long random secret, >= 32 chars).
# Jwt__Key=
# Jwt__Issuer=keepITCore
# Jwt__Audience=keepIT.api
# Jwt__AccessTokenMinutes=15
# Jwt__RefreshTokenDays=14
# Database — set a Postgres connection to use Postgres; otherwise the API falls back to SQLite.
# Either a full connection string...
# ConnectionStrings__Postgres=Host=db;Port=5432;Database=keepit;Username=keepit;Password=change-me
# ...or the discrete parts (used only if ConnectionStrings__Postgres is empty; POSTGRES_HOST is the switch):
# POSTGRES_HOST=db
# POSTGRES_PORT=5432
# POSTGRES_DB=keepit
# POSTGRES_USER=keepit
# POSTGRES_PASSWORD=change-me
# Data folder (SQLite db, media, Data Protection keys).
# App__DataRoot=/data
# Refresh cookie: always HTTPS-only for requests over HTTPS; true forces it on plain HTTP too.
# Keep true behind TLS / on localhost; false for plain-HTTP LAN access.
# Auth__RefreshCookie__Secure=true
# Trusted reverse-proxy hops (the single-container equivalent of FORWARDED_PROXY_HOPS above).
# App__ForwardedProxyHops=1
# Allow new sign-ups (the single-container equivalent of ALLOW_REGISTRATION above; default true).
# App__AllowRegistration=true
# Outgoing email for password-reset links. Leave Email__SmtpHost empty to write the links to the
# server log instead (docker logs), where the operator can pass them on.
# Email__SmtpHost=smtp.example.com
# Email__From=keepIT <no-reply@example.com>
# Email__SmtpUsername=
# Email__SmtpPassword=
# Email__SmtpPort=587
# Email__UseStartTls=true
# Mail is never sent unencrypted: with STARTTLS the server must offer it. Only for a relay on a
# network you trust that can't do TLS, allow plain text:
# Email__AllowUnencrypted=false
# The address users open keepIT at. REQUIRED once Email__SmtpHost is set: emailed reset links point
# here, and no reset email is sent while it's empty, because a link built from the incoming request
# could point anywhere. Optional without SMTP.
# App__PublicBaseUrl=https://notes.example.com
# CORS — only when the frontend is served from a different origin than the API (not the bundled setups).
# Cors__AllowedOrigins__0=https://app.keepit.example