All checks were successful
CD / Build and push images (push) Successful in 1m7s
CD / Deploy to Test (push) Successful in 10s
CD / Smoke tests against Test (push) Successful in 1m8s
CD / Promote to Int (push) Successful in 10s
CI / Lint, typecheck, test (push) Successful in 3m13s
CI / Build container images (push) Has been skipped
CI / Auth e2e pack (push) Successful in 5m18s
CI / Import/export fidelity gate (push) Successful in 46s
docs/self-hosting/README.md is the complete operator contract: install from the two reference files, first-run wizard walkthrough, update procedure with the one-release downgrade window, backup/restore with the sidecar, readyz-based troubleshooting (incl. the classic proxy/WebSocket and APP_BASE_URL/CSRF mistakes), and a build-from-source note; linked from the repository README; English-only by documented decision. The reference compose gains a `caddy` profile (new Caddyfile) that publishes 80/443 and terminates TLS via Let's Encrypt for $DOMAIN — localhost uses Caddy's internal CA for smoke tests. deploy/self-hosting-verify.sh scripts the clean-machine test: a fresh directory with only the published files boots to the wizard answering over TLS, then removes itself; verified green on the stage host. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01EwZ4jR4KFAPvpjWevfUGX1
91 lines
4.0 KiB
Plaintext
91 lines
4.0 KiB
Plaintext
# Dorfteich stage configuration. Copy to `.env` (mode 600, never in git)
|
|
# next to docker-compose.yml and adjust the values.
|
|
|
|
# --- required ---------------------------------------------------------------
|
|
# PostgreSQL password for the `dorfteich` database user.
|
|
POSTGRES_PASSWORD=change-me
|
|
|
|
# Secret that signs/verifies the short-lived collaboration tokens (issue #34).
|
|
# The api and collab services share this one value; use a long random string
|
|
# (e.g. `openssl rand -base64 32`). Min length 16.
|
|
COLLAB_TOKEN_SECRET=change-me-to-a-long-random-string
|
|
|
|
# --- images -----------------------------------------------------------------
|
|
# Image name prefix. Stages pull from the Gitea registry, e.g.
|
|
# gitea.101010.cloud/stwaidele/dorfteich — local builds use the default.
|
|
IMAGE_PREFIX=dorfteich
|
|
# Image tag to run: a git SHA, `test`, `int`, or a release tag like v1.2.0.
|
|
TAG=latest
|
|
|
|
# --- ports (localhost only; the host reverse proxy routes to these) ---------
|
|
# Suggested per stage on the shared host (ONE): test 8100/8101/8102,
|
|
# int 8110/8111/8112, prod 8120/8121/8122 (web/api/collab).
|
|
WEB_PORT=8100
|
|
API_PORT=8101
|
|
# collab (Hocuspocus) WebSocket server; the proxy routes /collab here.
|
|
COLLAB_PORT=8102
|
|
|
|
# --- behavior ----------------------------------------------------------------
|
|
# pino log level: fatal|error|warn|info|debug|trace
|
|
LOG_LEVEL=info
|
|
|
|
# Compose project name; set per stage (dorfteich-test, dorfteich-int, …).
|
|
COMPOSE_PROJECT_NAME=dorfteich
|
|
|
|
# --- public URL + mail --------------------------------------------------------
|
|
# Public base URL of the stage (scheme + host). E-mail links and the CSRF
|
|
# origin check are derived from it — it must match what browsers use.
|
|
APP_BASE_URL=https://test.dorfteich.cloud
|
|
|
|
# SMTP relay for outgoing mail (verification, password reset). Optional:
|
|
# leave everything unset and configure the relay in the browser during the
|
|
# first-run setup wizard instead (stored on the `secrets` volume, issue #80).
|
|
# Values set here always win over wizard-stored ones.
|
|
SMTP_HOST=mail.example.com
|
|
SMTP_PORT=465
|
|
SMTP_SECURE=true
|
|
SMTP_USER=wiki@example.com
|
|
SMTP_PASS=change-me
|
|
SMTP_FROM=Dorfteich <wiki@example.com>
|
|
|
|
# --- optional TLS ingress (`caddy` profile, issue #88) -------------------------
|
|
# Only when you have no reverse proxy of your own: start with
|
|
# `docker compose --profile caddy up -d`. Caddy terminates TLS for DOMAIN
|
|
# via Let's Encrypt (80+443 must be reachable from the internet; keep
|
|
# APP_BASE_URL=https://<DOMAIN> in sync). The `localhost` default issues
|
|
# an internal-CA certificate instead — good for smoke tests only.
|
|
#DOMAIN=wiki.example.com
|
|
# Published ports; change only when 80/443 are taken on the host.
|
|
#CADDY_HTTP_PORT=80
|
|
#CADDY_HTTPS_PORT=443
|
|
|
|
# --- backups (ADR 0015, issue #83) --------------------------------------------
|
|
# The backup sidecar dumps the database and archives the uploads/plugins
|
|
# volumes nightly onto the `backups` volume; restore via
|
|
# deploy/backup/restore.sh <backup-id>. All values optional.
|
|
# Daily run time HH:MM in TZ (default 03:00; set TZ for stage-local time,
|
|
# e.g. TZ=Europe/Berlin — unset means UTC).
|
|
#TZ=Europe/Berlin
|
|
#BACKUP_TIME=03:00
|
|
# Local retention in days: 30 (default) for Prod, 7 for Test/Int (ADR 0015).
|
|
#BACKUP_RETENTION_DAYS=30
|
|
# Failure alert: recipient (unset = no mail, failures only in the logs and
|
|
# status.json), mail language (de|en), and the label used in the subject
|
|
# (defaults to the compose project name).
|
|
#BACKUP_MAIL_TO=ops@example.com
|
|
#BACKUP_MAIL_LOCALE=en
|
|
#BACKUP_INSTANCE_LABEL=dorfteich-test
|
|
|
|
# --- first-run setup (optional pre-seeding, issue #80) ------------------------
|
|
# A fresh (empty) database makes the instance require the browser setup
|
|
# wizard. Automated deploys can skip it entirely by pre-seeding the Site
|
|
# Admin here; the wizard then completes and locks itself at first boot.
|
|
# All three SETUP_ADMIN_* values are required for pre-seeding to trigger.
|
|
#SETUP_ADMIN_USERNAME=admin
|
|
#SETUP_ADMIN_EMAIL=admin@example.com
|
|
#SETUP_ADMIN_PASSWORD=change-me-please
|
|
#SETUP_ADMIN_DISPLAY_NAME=Admin
|
|
#SETUP_INSTANCE_NAME=Dorfteich
|
|
#SETUP_DEFAULT_LOCALE=en
|
|
#SETUP_REGISTRATION_MODE=open
|