Configuration
Everything is set in one file, .env, copied from the .env.example the repository
ships. Docker Compose puts that copy in its place in the
sequence; this page is what goes in the file.
The three secrets
Section titled “The three secrets”Three values ship empty and have to be set before the first start. The stack refuses to come up while any of them is empty, naming every empty variable in one pass and the command that fills it.
They ship empty rather than pre-generated on purpose. An example file carrying real keys is a set of keys that is public and identical on every installation, and anyone who forgets to replace them runs on those.
openssl rand -hex 24 # paste after POSTGRES_PASSWORD=openssl rand -hex 32 # paste after JWT_ACCESS_SECRET=openssl rand -base64 32 # paste after SECRET_ENCRYPTION_KEY=| Variable | What it is for | Constraint |
|---|---|---|
POSTGRES_PASSWORD |
the database password | letters and digits only |
JWT_ACCESS_SECRET |
signs the session token | at least 16 characters |
SECRET_ENCRYPTION_KEY |
encrypts your 2FA secret and stored provider API keys | must decode to exactly 32 bytes |
A passphrase-sealed JSON export is deliberately not tied to that key: the file carries its own derivation parameters, so it survives a key you no longer have.
Two things about the database password. It is interpolated into the connection URL as
written, so a /, a ? or a # in it makes that URL unparsable and the application
never starts. And it is read once and only once, when the database directory is created:
changing it later locks the application out of its own database instead of changing
anything.
The rest of the file
Section titled “The rest of the file”| Variable | Default | What it decides |
|---|---|---|
WEB_PORT |
8080 |
the port the whole app is reached on |
BIND_ADDRESS |
0.0.0.0 |
which host interfaces that port is published on; 127.0.0.1 keeps it on the machine |
PUBLIC_URL |
http://localhost:8080 |
the address password-reset links are built from, and the cookie origin |
COOKIE_SECURE |
false |
marks the session cookie HTTPS-only; set it behind a proxy terminating TLS |
TRUSTED_PROXY_HOPS |
0 |
how many reverse proxies of yours stand in front (see Behind a proxy) |
REGISTRATION_ENABLED |
true |
whether public sign-up is open, as a fallback only |
DEMO_SEED_ENABLED |
false |
seeds the read-only demonstration account on boot |
ACCESS_TOKEN_TTL |
15m |
how long a session token lives before it is refreshed |
REFRESH_TOKEN_TTL_DAYS |
7 |
how long a session survives without being used |
COINGECKO_DEMO_KEY, OPENFIGI_API_KEY |
empty | optional free integration keys; both sources work without one |
The last two are the operator’s and are set here only: the settings screen has no field
for either. REGISTRATION_ENABLED and DEMO_SEED_ENABLED are fallbacks: the equivalent
toggles in Settings → Administration are stored in the database and win over these
values from the moment either is first used.