Skip to content

Arcane, ConvertX, Formbricks, Hemmelig, Karakeep: require your own secrets - #367

Merged
crypt0rr merged 1 commit into
mainfrom
require-own-secrets
Oct 8, 2026
Merged

crypt0rr merged 1 commit into
mainfrom
require-own-secrets

Conversation

@jackspiering

Copy link
Copy Markdown
Collaborator

Description

Five stacks shipped public sample values for their secrets. A stack started with them unless the user replaced each one by hand, so an installation could run with a signing or encryption key that anyone can read in this repository.

This pull request leaves the secrets empty in .env and makes Compose stop with an error when one is missing. Homarr, Docmost, and Speedtest Tracker already work this way.

Stack Secrets Where the sample value was
Arcane ENCRYPTION_KEY, JWT_SECRET compose.yaml
ConvertX JWT_SECRET compose.yaml
Hemmelig BETTER_AUTH_SECRET compose.yaml
Formbricks NEXTAUTH_SECRET, ENCRYPTION_KEY, CRON_SECRET .env
Karakeep NEXTAUTH_SECRET, MEILI_MASTER_KEY .env
  • compose.yaml: read each secret as ${VAR:?Set VAR in .env}. Karakeep passes its settings through env_file, so its two secrets are also listed under environment to get the same check.
  • .env: an empty entry for each secret, with the command that generates a value.
  • README.md (service): the "Before you start" section names the secrets and the command, and a new "Upgrading" section explains what to do with an existing installation.

Related Issues

  • None.

Verification

With the empty .env from this branch, docker compose config --quiet stops in each of the five directories, for example:

error while interpolating services.application.environment.[]: required variable JWT_SECRET is missing a value: Set JWT_SECRET in .env

Each stack then ran from a scratch copy with generated values. A stand-in container replaced Tailscale, because the change does not concern the network.

Stack Values from Result
Arcane openssl rand -base64 32 Healthy after 10 seconds, / answers 200
ConvertX openssl rand -hex 32 Healthy after 10 seconds, / redirects to the setup page
Hemmelig openssl rand -hex 32 Healthy after 15 seconds, / answers 200
Karakeep openssl rand -base64 36 Healthy after 10 seconds, /signin answers 200
Formbricks openssl rand -hex 32 Healthy after 125 seconds, /health answers 200

No container restarted in any of the runs. Karakeep and Formbricks also had their address set (NEXTAUTH_URL, TS_URL), which they need to start.

  • rumdl check --config .markdownlint.yml on the five READMEs: passed.
  • git diff --check: passed.

Not tested: an upgrade of an installation with existing data. The "Upgrading" sections state what follows from a changed signing or encryption key and do not describe a tested migration.

Checklist

  • I have performed a self-review of my code and followed the templates structure.
  • I have added verification that the stack works as expected.
  • I have updated necessary documentation (e.g. frontpage README.md ).
  • I have selected the correct label(s) for this PR.

Additional Context

  • This changes behaviour for existing installations. After an update, Arcane, ConvertX, and Hemmelig do not start until the secret is in .env, also for users who had replaced the sample value in compose.yaml. Formbricks and Karakeep are unaffected when the user's .env already has values. The READMEs explain this under "Upgrading".
  • docker compose config --quiet fails for these five directories until the secrets are set, as it already does for Docmost, Homarr, Homebox, NetBox, Seafile, SearXNG, and Speedtest Tracker. A validator such as the one in Add service contract enforcement workflow #330 has to allow for that.
  • This pull request is stacked on All services: standardize the service READMEs #363 and targets its branch, because it edits the new READMEs. Merge All services: standardize the service READMEs #363 first.
  • Not included: the address placeholders in the same stacks, such as BETTER_AUTH_URL in Hemmelig, and the fixed database password in Formbricks.

@jackspiering jackspiering added the enhancement New feature, change or request label Oct 7, 2026
@jackspiering
jackspiering requested a review from crypt0rr October 7, 2026 18:51
Base automatically changed from t3code/standardize-service-readmes to main October 8, 2026 15:23
…crets

These stacks shipped public sample values for their secrets, in
compose.yaml or in .env. A stack started with them unless the user
replaced each one by hand.

Leave the secrets empty in .env and make Compose stop with an error when
one is missing, as Homarr and Docmost already do. Document the values and
the upgrade steps in each README.
@crypt0rr
crypt0rr merged commit ee8b28e into main Oct 8, 2026
1 check passed
@crypt0rr
crypt0rr deleted the require-own-secrets branch October 8, 2026 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature, change or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants