Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 6 additions & 0 deletions services/arcane/.env
Original file line number Diff line number Diff line change
Expand Up @@ -21,4 +21,10 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim
# for example: tail-scale
TAILNET_NAME=

# Required: a 32-byte key. Generate it with: openssl rand -base64 32
ENCRYPTION_KEY=

# Required: generate it with: openssl rand -base64 32
JWT_SECRET=

#EXAMPLE_VAR="Environment variable"
9 changes: 8 additions & 1 deletion services/arcane/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ This stack runs Arcane with a Tailscale sidecar, as described in [the standard s
## Before you start

- **Set your Tailnet name.** Set `TAILNET_NAME` in `.env` to your Tailnet name, without `.ts.net`. `compose.yaml` builds the address of the application, `APP_URL`, from it.
- **Replace the secrets.** `ENCRYPTION_KEY` and `JWT_SECRET` in `compose.yaml` have a public sample value. Replace both with your own random values.
- **Set the secrets.** Set `ENCRYPTION_KEY` and `JWT_SECRET` in `.env` to two different random values. Generate each with `openssl rand -base64 32`. Compose stops with an error if one of them is empty.

## Deviations from the standard setup

Expand All @@ -28,6 +28,13 @@ This stack runs Arcane with a Tailscale sidecar, as described in [the standard s

Open the web interface and log in with username `arcane` and password `arcane-admin`. Arcane creates this account at the first start and asks you to change the password at the first login.

## Upgrading

Earlier versions of this stack had sample values for `ENCRYPTION_KEY` and `JWT_SECRET` in `compose.yaml`. Both are now empty in `.env`, and you must set them.

- If you replaced the values in `compose.yaml` before, move your values to `.env`.
- If you still used the sample values, set new ones. With a new `JWT_SECRET`, everyone has to log in again. Arcane cannot decrypt what it encrypted with the previous `ENCRYPTION_KEY`, so keep the previous value if you need that data.

## Links

- [Arcane documentation](https://getarcane.app/docs)
Expand Down
4 changes: 2 additions & 2 deletions services/arcane/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -56,8 +56,8 @@ services:
- APP_URL=https://arcane.${TAILNET_NAME}.ts.net
- PUID=1000
- PGID=1000
- ENCRYPTION_KEY=verysecretkeythatshouldbereplaced # ENCRYPTION_KEY must be 32 bytes (raw/base64/hex). Use 'openssl rand -base64 32' in your CLI to generate a secure random key.
- JWT_SECRET=verysecretkeythatshouldbereplaced # JWT_SECRET should be a secure random string. Use 'openssl rand -base64 32' in your CLI to generate another secure random key.
- ENCRYPTION_KEY=${ENCRYPTION_KEY:?Set ENCRYPTION_KEY in .env}
- JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env}
- LOG_LEVEL=info # Optional
- LOG_JSON=false # Optional
- OIDC_ENABLED=false # Optional
Expand Down
3 changes: 3 additions & 0 deletions services/convertx/.env
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,7 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim
# Optional Service variables
# PUID=1000

# Required: signs the login tokens. Generate it with: openssl rand -hex 32
JWT_SECRET=

#EXAMPLE_VAR="Environment variable"
6 changes: 5 additions & 1 deletion services/convertx/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ This stack runs ConvertX with a Tailscale sidecar, as described in [the standard

## Before you start

Replace the value of `JWT_SECRET` in `compose.yaml` with your own long random string. The sample value is public, and ConvertX uses it to sign the login tokens.
Set `JWT_SECRET` in `.env` to a long random value. Generate one with `openssl rand -hex 32`. ConvertX uses it to sign the login tokens, and Compose stops with an error if it is empty.

## Deviations from the standard setup

Expand All @@ -25,6 +25,10 @@ None.

Open the web interface. ConvertX sends you to the setup page, where you create your account. Do this right after the first start, because anyone who can reach the service can register the first account. After that, registration is closed.

## Upgrading

Earlier versions of this stack had a sample value for `JWT_SECRET` in `compose.yaml`. It is now empty in `.env`, and you must set it. With a new value, everyone has to log in again.

## Links

- [ConvertX documentation and source code](https://github.com/C4illin/ConvertX)
2 changes: 1 addition & 1 deletion services/convertx/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,7 @@ services:
network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale
container_name: app-${SERVICE} # Name for local container management
environment:
- JWT_SECRET=aLongAndSecretStringUsedToSignTheJSONWebToken1234 # will use randomUUID() if unset
- JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env}
- TZ=${TZ}
volumes:
- ./${SERVICE}-data:/app/data
Expand Down
12 changes: 6 additions & 6 deletions services/formbricks/.env
Original file line number Diff line number Diff line change
Expand Up @@ -42,16 +42,16 @@ DATABASE_URL="postgresql://postgres:postgres@postgres:5432/formbricks?schema=pub

# NextJS Auth
# @see: https://next-auth.js.org/configuration/options#nextauth_secret
# You can use: `openssl rand -hex 32` to generate a new one
NEXTAUTH_SECRET="7b62c37371798cf96dc019f3d4f712a27d1b05d0755ffcf96481b8504697f532"
# Required. Generate it with: openssl rand -hex 32
NEXTAUTH_SECRET=

# Encryption Key is used for 2FA & Single use URLs for Link Surveys
# You can use: `openssl rand -hex 32` to generate a new one
ENCRYPTION_KEY="i1e284266e3f7ace4772e329e0494aa1d6110fba48db06bd9652e7a9fdd167281"
# Required. Generate it with: openssl rand -hex 32
ENCRYPTION_KEY=

# API Secret for running cron jobs.
# You can use: `openssl rand -hex 32` to generate a new one
CRON_SECRET="b5af3d39789e7730004a01bb84922914ea0b478fe67784ce3fa8e4c35096d6b4"
# Required. Generate it with: openssl rand -hex 32
CRON_SECRET=

# Redis URL for caching, rate limiting, and audit logging
# To use external Redis/Valkey: remove the redis service below and update this URL
Expand Down
9 changes: 8 additions & 1 deletion services/formbricks/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ Set these values in `.env`:

- **`TS_URL`.** The name of the device on your Tailnet, `formbricks.<tailnet>.ts.net`.
- **`WEBAPP_URL`.** The address that you use to open Formbricks. The sample value is `http://${TS_URL}:3000`, which is the direct port on the Tailnet. To use the HTTPS address of Tailscale Serve, change it to `https://${TS_URL}`. `NEXTAUTH_URL` and `PUBLIC_URL` follow this value.
- **`NEXTAUTH_SECRET`, `ENCRYPTION_KEY`, and `CRON_SECRET`.** The sample values are public. Replace each with its own random value from `openssl rand -hex 32`.
- **`NEXTAUTH_SECRET`, `ENCRYPTION_KEY`, and `CRON_SECRET`.** Three different random values. Generate each with `openssl rand -hex 32`. Compose stops with an error if one of them is empty.
- **The `SMTP_*` and `MAIL_FROM` values.** The details of your mail server, if Formbricks should send email. The sample values do not work.

## Deviations from the standard setup
Expand All @@ -38,6 +38,13 @@ Set these values in `.env`:

The first start takes about three minutes, because Formbricks prepares its database. Then open the web interface at the address from `WEBAPP_URL` and create the first account, which becomes the owner of the organisation.

## Upgrading

Earlier versions of this stack shipped sample values for `NEXTAUTH_SECRET`, `ENCRYPTION_KEY`, and `CRON_SECRET` in `.env`. They are now empty, and you must set them.

- If you already replaced the sample values, keep your own.
- If your `.env` still has the sample values, set new ones. With a new `NEXTAUTH_SECRET`, everyone has to log in again. Formbricks uses `ENCRYPTION_KEY` for two-factor authentication and for single-use links of link surveys, so existing ones stop working with a new key.

## Links

- [Formbricks self-hosting documentation](https://formbricks.com/docs/self-hosting/overview)
Expand Down
6 changes: 3 additions & 3 deletions services/formbricks/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -86,9 +86,9 @@ services:
- WEBAPP_URL=${WEBAPP_URL}
- NEXTAUTH_URL=${NEXTAUTH_URL}
- DATABASE_URL=${DATABASE_URL}
- NEXTAUTH_SECRET=${NEXTAUTH_SECRET}
- ENCRYPTION_KEY=${ENCRYPTION_KEY}
- CRON_SECRET=${CRON_SECRET}
- NEXTAUTH_SECRET=${NEXTAUTH_SECRET:?Set NEXTAUTH_SECRET in .env}
- ENCRYPTION_KEY=${ENCRYPTION_KEY:?Set ENCRYPTION_KEY in .env}
- CRON_SECRET=${CRON_SECRET:?Set CRON_SECRET in .env}
- REDIS_URL=${REDIS_URL}
- LOG_LEVEL=${LOG_LEVEL}
- ENTERPRISE_LICENSE_KEY=${ENTERPRISE_LICENSE_KEY}
Expand Down
3 changes: 3 additions & 0 deletions services/hemmelig/.env
Original file line number Diff line number Diff line change
Expand Up @@ -19,4 +19,7 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim
# Optional Service variables
# PUID=1000

# Required: at least 32 characters. Generate it with: openssl rand -hex 32
BETTER_AUTH_SECRET=

#EXAMPLE_VAR="Environment variable"
10 changes: 6 additions & 4 deletions services/hemmelig/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,10 +18,8 @@ This stack runs Hemmelig with a Tailscale sidecar, as described in [the standard

## Before you start

Change these values in `compose.yaml`:

- **`BETTER_AUTH_URL` and `HEMMELIG_BASE_URL`.** The address of the web interface, `https://hemmelig.<tailnet>.ts.net`. The sample value is `https://secrets.example.com`.
- **`BETTER_AUTH_SECRET`.** A random value of at least 32 characters. The sample value is public.
- **Set the addresses in `compose.yaml`.** Change `BETTER_AUTH_URL` and `HEMMELIG_BASE_URL` to the address of the web interface, `https://hemmelig.<tailnet>.ts.net`. The sample value is `https://secrets.example.com`.
- **Set the secret in `.env`.** Set `BETTER_AUTH_SECRET` to a random value of at least 32 characters. Generate one with `openssl rand -hex 32`. Compose stops with an error if it is empty.

## Deviations from the standard setup

Expand All @@ -31,6 +29,10 @@ None.

Open the web interface. Hemmelig asks you to create the first account.

## Upgrading

Earlier versions of this stack had a sample value for `BETTER_AUTH_SECRET` in `compose.yaml`. It is now empty in `.env`, and you must set it. With a new value, everyone has to log in again.

## Links

- [Hemmelig documentation and source code](https://github.com/HemmeligOrg/Hemmelig.app)
2 changes: 1 addition & 1 deletion services/hemmelig/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -57,7 +57,7 @@ services:
- PGID=1000
- TZ=${TZ}
- DATABASE_URL=file:/app/database/hemmelig.db
- BETTER_AUTH_SECRET=change-this-to-a-secure-secret-min-32-chars
- BETTER_AUTH_SECRET=${BETTER_AUTH_SECRET:?Set BETTER_AUTH_SECRET in .env}
- BETTER_AUTH_URL=https://secrets.example.com
- NODE_ENV=production
- HEMMELIG_BASE_URL=https://secrets.example.com
Expand Down
5 changes: 3 additions & 2 deletions services/karakeep/.env
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,9 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim
# PUID=1000

KARAKEEP_VERSION=release
NEXTAUTH_SECRET=super_random_string
MEILI_MASTER_KEY=another_random_string
# Required: two different random values. Generate each with: openssl rand -base64 36
NEXTAUTH_SECRET=
MEILI_MASTER_KEY=
NEXTAUTH_URL=https://<YOUR_TAILNET_URL>
MAX_ASSET_SIZE_MB=50
DISABLE_SIGNUPS=false
Expand Down
6 changes: 5 additions & 1 deletion services/karakeep/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -21,7 +21,7 @@ This stack runs Karakeep with a Tailscale sidecar, as described in [the standard
Set these values in `.env`:

- **`NEXTAUTH_URL`.** The address of the web interface, `https://karakeep.<tailnet>.ts.net`. Karakeep does not start with the sample value.
- **`NEXTAUTH_SECRET` and `MEILI_MASTER_KEY`.** Two different random values, for example from `openssl rand -base64 36`. The sample values are public.
- **`NEXTAUTH_SECRET` and `MEILI_MASTER_KEY`.** Two different random values. Generate each with `openssl rand -base64 36`. Compose stops with an error if one of them is empty.

## Deviations from the standard setup

Expand All @@ -34,6 +34,10 @@ Set these values in `.env`:

Open the web interface and sign up. The first account becomes the administrator. To stop others from registering afterwards, set `DISABLE_SIGNUPS=true` in `.env` and restart the stack.

## Upgrading

Earlier versions of this stack shipped sample values for `NEXTAUTH_SECRET` and `MEILI_MASTER_KEY` in `.env`. They are now empty, and you must set them. If you already replaced the sample values, keep your own. With a new `NEXTAUTH_SECRET`, everyone has to log in again.

## Links

- [Karakeep documentation](https://docs.karakeep.app/)
Expand Down
3 changes: 3 additions & 0 deletions services/karakeep/compose.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -56,6 +56,8 @@ services:
- .env
environment:
MEILI_ADDR: http://meilisearch:7700
NEXTAUTH_SECRET: ${NEXTAUTH_SECRET:?Set NEXTAUTH_SECRET in .env}
MEILI_MASTER_KEY: ${MEILI_MASTER_KEY:?Set MEILI_MASTER_KEY in .env}
BROWSER_WEB_URL: http://chrome:9222
# OPENAI_API_KEY: ...

Expand Down Expand Up @@ -105,5 +107,6 @@ services:
- .env
environment:
MEILI_NO_ANALYTICS: "true"
MEILI_MASTER_KEY: ${MEILI_MASTER_KEY:?Set MEILI_MASTER_KEY in .env}
volumes:
- ./${SERVICE}-data/meilisearch:/meili_data
Loading