diff --git a/.github/workflows/compose-validation.yml b/.github/workflows/compose-validation.yml new file mode 100644 index 00000000..23297007 --- /dev/null +++ b/.github/workflows/compose-validation.yml @@ -0,0 +1,61 @@ +name: Validate Compose files +on: + workflow_dispatch: + push: + branches: + - main + paths: + - 'services/**' + - '.github/workflows/compose-validation.yml' + pull_request: + branches: + - main + paths: + - 'services/**' + - '.github/workflows/compose-validation.yml' + +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + +jobs: + validate: + runs-on: ubuntu-latest + timeout-minutes: 15 + steps: + - name: Clone this repo + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + + # Some stacks require the user to set their own secrets and stop with + # "required variable X is missing". Supply a dummy value for those and + # retry, so that the rest of the file is still checked. + - name: Run docker compose config + run: | + status=0 + for dir in services/*/; do + vars=() + ok=0 + for attempt in $(seq 1 30); do + if out=$(cd "$dir" && env "${vars[@]/%/=dummy}" docker compose config --quiet 2>&1); then + ok=1 + break + fi + missing=$(grep -oE 'required variable [A-Za-z0-9_]+' <<<"$out" | awk '{print $3}' | sort -u | grep -vxFf <(printf '%s\n' "${vars[@]}") || true) + if [ -z "$missing" ]; then + echo "::error file=${dir}compose.yaml::docker compose config failed in ${dir}" + echo "$out" + status=1 + ok=2 + break + fi + vars+=($missing) + done + if [ "$ok" = 0 ]; then + echo "::error file=${dir}compose.yaml::too many required variables in ${dir}" + status=1 + fi + done + exit $status diff --git a/.github/workflows/linting.yml b/.github/workflows/linting.yml index 95c90496..b0a9ed7e 100644 --- a/.github/workflows/linting.yml +++ b/.github/workflows/linting.yml @@ -5,7 +5,6 @@ on: branches: - main paths-ignore: - - '.github/**' # - 'README.md' - 'LICENSE' - '.gitignore' @@ -15,23 +14,31 @@ on: branches: - main paths-ignore: - - '.github/**' # - 'README.md' - 'LICENSE' - '.gitignore' - '.gitattributes' - '.editorconfig' +permissions: + contents: read + +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: ${{ github.event_name == 'pull_request' }} + jobs: lint: runs-on: ubuntu-latest + timeout-minutes: 10 steps: - name: Clone this repo - uses: actions/checkout@v7 - + uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 + - name: Lint Markdown - uses: rvben/rumdl@v0.2.73 + uses: rvben/rumdl@9c4cc2a2ebe176de68e1788106e25af8a9bd3899 # v0.2.78 with: + version: "0.2.78" # Keep in line with the pinned action above path: "." config: ".markdownlint.yml" report-type: annotations diff --git a/services/adguardhome-sync/.env b/services/adguardhome-sync/.env index 5743c44a..abeab231 100644 --- a/services/adguardhome-sync/.env +++ b/services/adguardhome-sync/.env @@ -19,4 +19,10 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Optional Service variables # PUID=1000 +# AdGuard Home Sync Configuration +# Required: password of the AdGuard Home instance to copy from. +ORIGIN_PASSWORD= +# Required: password of the AdGuard Home instance to copy to. +REPLICA1_PASSWORD= + #EXAMPLE_VAR="Environment variable" diff --git a/services/adguardhome-sync/README.md b/services/adguardhome-sync/README.md index 528ac4f2..41cfba00 100644 --- a/services/adguardhome-sync/README.md +++ b/services/adguardhome-sync/README.md @@ -17,17 +17,21 @@ This stack runs AdGuard Home Sync with a Tailscale sidecar, as described in [the Replace the sample values in the `environment` block of `compose.yaml`: -- **`ORIGIN_URL`, `ORIGIN_USERNAME`, `ORIGIN_PASSWORD`.** The AdGuard Home instance to copy from. -- **`REPLICA1_URL`, `REPLICA1_USERNAME`, `REPLICA1_PASSWORD`.** The instance to copy to. +- **`ORIGIN_URL` and `ORIGIN_USERNAME`.** The AdGuard Home instance to copy from. +- **`REPLICA1_URL` and `REPLICA1_USERNAME`.** The instance to copy to. - **`CRON`.** The schedule. The sample value runs a sync every minute. +Set the passwords in `.env`: + +- **`ORIGIN_PASSWORD` and `REPLICA1_PASSWORD`.** The passwords of the two instances. Compose stops with an error if one of them is empty. + To reach an AdGuard Home instance on your Tailnet, see the [DNS section of the standard setup](../../documentation/standard-setup.md#dns). ## Deviations from the standard setup - **No Tailscale Serve.** The stack has no Serve configuration. The tool only makes outgoing connections to your AdGuard Home instances. - **Start command.** The stack starts the tool with the `run` command. -- **No data folder.** The tool stores nothing on disk. All settings are in `compose.yaml`. +- **No data folder.** The tool stores nothing on disk. The settings are in `compose.yaml`, and the passwords are in `.env`. ## First run @@ -37,6 +41,10 @@ Check the log to see whether the sync works: docker logs app-adguardhome-sync ``` +## Upgrading + +Earlier versions of this stack had the sample value `password` for `ORIGIN_PASSWORD` and `REPLICA1_PASSWORD` in `compose.yaml`. The passwords are now in `.env`. They are empty, and Compose stops with an error until you set them. If you already run the stack, move your passwords from `compose.yaml` to `.env`. + ## Links - [AdGuard Home Sync documentation and source code](https://github.com/bakito/adguardhome-sync) diff --git a/services/adguardhome-sync/compose.yaml b/services/adguardhome-sync/compose.yaml index 85723b2e..f152eafb 100644 --- a/services/adguardhome-sync/compose.yaml +++ b/services/adguardhome-sync/compose.yaml @@ -46,12 +46,12 @@ services: # Origin AdGuardHome - ORIGIN_URL=http://192.168.1.1:3000 #Your origin Adguard Home instance -> change as necessary - ORIGIN_USERNAME=username #change as necessary - - ORIGIN_PASSWORD=password #change as necessary + - ORIGIN_PASSWORD=${ORIGIN_PASSWORD:?Set ORIGIN_PASSWORD in .env} # First replication target - REPLICA1_URL=http://192.168.1.2 #Your destination Adguard Home instance change as necessary - REPLICA1_USERNAME=dbtech #change as necessary - - REPLICA1_PASSWORD=password #change as necessary + - REPLICA1_PASSWORD=${REPLICA1_PASSWORD:?Set REPLICA1_PASSWORD in .env} # Second replication target (optional) #- REPLICA2_URL=http://192.168.1.3 #change as necessary diff --git a/services/affine/.env b/services/affine/.env index e7d3c64d..a85325eb 100644 --- a/services/affine/.env +++ b/services/affine/.env @@ -30,5 +30,6 @@ AFFINE_SERVER_EXTERNAL_URL=https://affine..ts.net # database credentials DB_USERNAME=affine -DB_PASSWORD=affine +# Required: password of the database. Use letters and digits only, because the database address contains it. +DB_PASSWORD= DB_DATABASE=affine diff --git a/services/affine/README.md b/services/affine/README.md index bf652986..36a086cf 100644 --- a/services/affine/README.md +++ b/services/affine/README.md @@ -22,7 +22,7 @@ This stack runs AFFiNE with a Tailscale sidecar, as described in [the standard s Set these values in `.env`: - **`AFFINE_SERVER_EXTERNAL_URL`.** The address of the web interface, `https://affine..ts.net`. AFFiNE does not start with the sample value, because the `affine_migration` container fails. -- **`DB_PASSWORD`.** The password of the database. The default is `affine`. +- **`DB_PASSWORD`.** The password of the database. Use letters and digits only, because the database address contains it. It is empty, and Compose stops with an error until you set it. ## Deviations from the standard setup @@ -35,6 +35,10 @@ Set these values in `.env`: Open the web interface. AFFiNE sends you to its setup page, where you create the administrator account. +## Upgrading + +Earlier versions of this stack had a sample value for `DB_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `DB_PASSWORD=affine` again. The database still uses it. + ## Links - [AFFiNE self-hosting documentation](https://docs.affine.pro/self-host-affine) diff --git a/services/affine/compose.yaml b/services/affine/compose.yaml index da408e3d..4197bc02 100644 --- a/services/affine/compose.yaml +++ b/services/affine/compose.yaml @@ -70,7 +70,7 @@ services: environment: # Variables are declared in .env file. - REDIS_SERVER_HOST=redis - - DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${DB_DATABASE:-affine} + - DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD:?Set DB_PASSWORD in .env}@postgres:5432/${DB_DATABASE:-affine} - AFFINE_INDEXER_ENABLED=false #- EXAMPLE_VAR=${EXAMPLE_VAR} healthcheck: @@ -95,7 +95,7 @@ services: environment: # Variables are declared in .env file. - REDIS_SERVER_HOST=redis - - DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD}@postgres:5432/${DB_DATABASE:-affine} + - DATABASE_URL=postgresql://${DB_USERNAME}:${DB_PASSWORD:?Set DB_PASSWORD in .env}@postgres:5432/${DB_DATABASE:-affine} - AFFINE_INDEXER_ENABLED=false #- EXAMPLE_VAR=${EXAMPLE_VAR} depends_on: @@ -122,12 +122,9 @@ services: environment: # Variables are declared in .env file. POSTGRES_USER: ${DB_USERNAME} - POSTGRES_PASSWORD: ${DB_PASSWORD} + POSTGRES_PASSWORD: ${DB_PASSWORD:?Set DB_PASSWORD in .env} POSTGRES_DB: ${DB_DATABASE:-affine} POSTGRES_INITDB_ARGS: '--data-checksums' - # you better set a password for you database - # or you may add 'POSTGRES_HOST_AUTH_METHOD=trust' to ignore postgres security policy - POSTGRES_HOST_AUTH_METHOD: trust #- EXAMPLE_VAR=${EXAMPLE_VAR} healthcheck: test: [ 'CMD', 'pg_isready', '-h', '127.0.0.1', '-U', "${DB_USERNAME}", '-d', "${DB_DATABASE:-affine}" ] # Check if PostgreSQL accepts connections diff --git a/services/artisttrackarr/.env b/services/artisttrackarr/.env index 124a66e0..51930123 100644 --- a/services/artisttrackarr/.env +++ b/services/artisttrackarr/.env @@ -23,9 +23,12 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Any Container environment variables are declared below. See https://docs.docker.com/compose/how-tos/environment-variables/ PUBLIC_URL=http://localhost:8080 -SETUP_TOKEN=replace-with-at-least-32-random-characters -APP_ENCRYPTION_KEY=replace-with-at-least-32-random-characters -SESSION_SECRET=replace-with-at-least-32-random-characters +# Required: at least 32 characters. Generate it with: openssl rand -hex 32 +SETUP_TOKEN= +# Required: at least 32 characters. Generate it with: openssl rand -hex 32 +APP_ENCRYPTION_KEY= +# Required: at least 32 characters. Generate it with: openssl rand -hex 32 +SESSION_SECRET= MUSICBRAINZ_CONTACT=you@example.com POLL_INTERVAL=6h TRUST_PROXY=false diff --git a/services/artisttrackarr/README.md b/services/artisttrackarr/README.md index 488fb34c..c1395036 100644 --- a/services/artisttrackarr/README.md +++ b/services/artisttrackarr/README.md @@ -24,7 +24,7 @@ This stack runs ArtistTrackarr with a Tailscale sidecar, as described in [the st 2. Set these values in `.env`: - - **`SETUP_TOKEN`, `APP_ENCRYPTION_KEY`, and `SESSION_SECRET`.** Three different random values of at least 32 characters each. + - **`SETUP_TOKEN`, `APP_ENCRYPTION_KEY`, and `SESSION_SECRET`.** Three different random values of at least 32 characters each. Generate each with `openssl rand -hex 32`. - **`MUSICBRAINZ_CONTACT`.** A real email address or project address. ArtistTrackarr sends it to MusicBrainz with each request. - **`PUBLIC_URL`.** The address of the web interface, `https://artist-trackarr..ts.net`. @@ -45,6 +45,10 @@ Open `https://artist-trackarr..ts.net/setup`, enter the value of `SETUP - **Client addresses.** Tailscale Serve is the reverse proxy of this stack. Set `TRUST_PROXY=true` in `.env` only if ArtistTrackarr should trust the client addresses that the proxy forwards. - **Backups.** Stop the stack before you back up `./artist-trackarr-data`, so that the copy of the database is consistent. +## Upgrading + +Earlier versions of this stack had sample values for `SETUP_TOKEN`, `APP_ENCRYPTION_KEY`, and `SESSION_SECRET` in `.env`. They are now empty, and ArtistTrackarr stops with `SETUP_TOKEN must be at least 32 characters` until you set them. If you already run the stack, keep the values that you use now. If you kept the sample value, set `APP_ENCRYPTION_KEY=replace-with-at-least-32-random-characters` again. A new key cannot decrypt the data that ArtistTrackarr stored with the old one. + ## Links - [ArtistTrackarr documentation and source code](https://github.com/crypt0rr/ArtistTrackarr) diff --git a/services/beszel-agent/README.md b/services/beszel-agent/README.md index 3c533c6b..e476f738 100644 --- a/services/beszel-agent/README.md +++ b/services/beszel-agent/README.md @@ -25,7 +25,7 @@ Without a valid key, the `application` container keeps restarting. ## Deviations from the standard setup - **No web interface.** The stack has no Tailscale Serve configuration and no `./config` folder. The hub connects to the agent on port `45876` of its Tailscale IP address. -- **Docker socket.** The agent mounts `/var/run/docker.sock` read-only to read the statistics of the containers on the Docker host. +- **Docker socket.** The agent mounts `/var/run/docker.sock` read-only to read the statistics of the containers on the Docker host. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. - **No data folder.** The agent stores nothing on disk. ## First run diff --git a/services/beszel-agent/compose.yaml b/services/beszel-agent/compose.yaml index 4aa14933..0abc3f74 100644 --- a/services/beszel-agent/compose.yaml +++ b/services/beszel-agent/compose.yaml @@ -42,7 +42,7 @@ services: PORT: 45876 KEY: "ssh-ed25519 " volumes: - - /var/run/docker.sock:/var/run/docker.sock:ro # Read-only access to the docker.sock + - /var/run/docker.sock:/var/run/docker.sock:ro # The :ro flag does not limit Docker API access: the service can control Docker on the host depends_on: tailscale: condition: service_healthy diff --git a/services/booklore/README.md b/services/booklore/README.md index 6403a9f9..dc9975bf 100644 --- a/services/booklore/README.md +++ b/services/booklore/README.md @@ -18,7 +18,7 @@ This stack runs BookLore with a Tailscale sidecar, as described in [the standard ## Before you start -- **Set the database passwords.** `MYSQL_ROOT_PASSWORD` and `MYSQL_PASSWORD` in `.env` are empty. Give both a random value. +- **Set the database passwords.** `MYSQL_ROOT_PASSWORD` and `MYSQL_PASSWORD` in `.env` are empty. Give both a random value. Compose stops with an error until you set them. - **Choose your book folder.** To use an existing collection, point the `/books1` volume in `compose.yaml` at your own folder. Otherwise the stack starts with an empty `./books` folder. ## Deviations from the standard setup diff --git a/services/booklore/compose.yaml b/services/booklore/compose.yaml index aa81e4ae..afdc290a 100644 --- a/services/booklore/compose.yaml +++ b/services/booklore/compose.yaml @@ -57,7 +57,7 @@ services: - PGID=1000 - DATABASE_URL=jdbc:mariadb://mariadb:3306/booklore # Only modify this if you're familiar with JDBC and your database setup - DATABASE_USERNAME=${MYSQL_USER} # Must match MYSQL_USER defined in the mariadb container - - DATABASE_PASSWORD=${MYSQL_PASSWORD} # Use a strong password; must match MYSQL_PASSWORD defined in the mariadb container + - DATABASE_PASSWORD=${MYSQL_PASSWORD:?Set MYSQL_PASSWORD in .env} # Use a strong password; must match MYSQL_PASSWORD defined in the mariadb container - SWAGGER_ENABLED=false # Swagger UI (API docs). - TZ=${TZ} volumes: @@ -81,10 +81,10 @@ services: environment: - PUID=1000 - PGID=1000 - - MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD} # Use a strong password for the database's root user, should be different from MYSQL_PASSWORD + - MYSQL_ROOT_PASSWORD=${MYSQL_ROOT_PASSWORD:?Set MYSQL_ROOT_PASSWORD in .env} # Use a strong password for the database's root user, should be different from MYSQL_PASSWORD - MYSQL_DATABASE=${MYSQL_DATABASE} - MYSQL_USER=${MYSQL_USER} # Must match DATABASE_USERNAME defined in the booklore container - - MYSQL_PASSWORD=${MYSQL_PASSWORD} # Use a strong password; must match DATABASE_PASSWORD defined in the booklore container + - MYSQL_PASSWORD=${MYSQL_PASSWORD:?Set MYSQL_PASSWORD in .env} # Use a strong password; must match DATABASE_PASSWORD defined in the booklore container volumes: - ./mariadb_config:/config restart: always diff --git a/services/coder/.env b/services/coder/.env index d2705617..b4f4dfdc 100644 --- a/services/coder/.env +++ b/services/coder/.env @@ -21,7 +21,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim CODER_VERSION=latest POSTGRES_USER=username -POSTGRES_PASSWORD=strongpassword +# Required: password of the database. Use letters and digits only, because the database address contains it. +POSTGRES_PASSWORD= POSTGRES_DB=coder CODER_ACCESS_URL=https://coder..ts.net diff --git a/services/coder/README.md b/services/coder/README.md index bd6684da..32657888 100644 --- a/services/coder/README.md +++ b/services/coder/README.md @@ -27,18 +27,22 @@ This stack runs Coder with a Tailscale sidecar, as described in [the standard se 2. Set these values in `.env`: - **`CODER_ACCESS_URL`.** The address of the web interface, `https://coder..ts.net`. - - **`POSTGRES_PASSWORD`.** The password of the database. + - **`POSTGRES_PASSWORD`.** The password of the database. Use letters and digits only, because the database address contains it. Compose stops with an error if it is empty. ## Deviations from the standard setup - **Extra container.** The stack runs a `database` container with PostgreSQL. It uses the network of the `tailscale` container as well, so Coder reaches it at `localhost`. PostgreSQL therefore also listens on port `5432` of the Tailscale IP address of the device. -- **Docker socket.** Coder mounts `/var/run/docker.sock` read-only, so that templates can use Docker on the host. +- **Docker socket.** Coder mounts `/var/run/docker.sock` read-only, so that templates can use Docker on the host. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. - **Image version.** `CODER_VERSION` in `.env` selects the version of the Coder image. ## First run Open the web interface and create the first account, which becomes the administrator. +## Upgrading + +Earlier versions of this stack had a sample value for `POSTGRES_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=strongpassword` again. The database still uses it. + ## Links - [Coder documentation](https://coder.com/docs) diff --git a/services/coder/compose.yaml b/services/coder/compose.yaml index ad5f2240..e4ce92d2 100644 --- a/services/coder/compose.yaml +++ b/services/coder/compose.yaml @@ -53,7 +53,7 @@ services: network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale container_name: app-${SERVICE} # Name for local container management environment: - CODER_PG_CONNECTION_URL: "postgresql://${POSTGRES_USER:-username}:${POSTGRES_PASSWORD:-password}@localhost/${POSTGRES_DB:-coder}?sslmode=disable" + CODER_PG_CONNECTION_URL: "postgresql://${POSTGRES_USER:-username}:${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env}@localhost/${POSTGRES_DB:-coder}?sslmode=disable" CODER_HTTP_ADDRESS: "0.0.0.0:7080" CODER_ACCESS_URL: "${CODER_ACCESS_URL}" TZ: ${TZ} @@ -81,7 +81,7 @@ services: image: "postgres:17" environment: POSTGRES_USER: ${POSTGRES_USER:-username} # The PostgreSQL user (useful to connect to the database) - POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-password} # The PostgreSQL password (useful to connect to the database) + POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} # The PostgreSQL password (useful to connect to the database) POSTGRES_DB: ${POSTGRES_DB:-coder} # The PostgreSQL default database (automatically created at first launch) volumes: - ./${SERVICE}-data/coder-data:/var/lib/postgresql/data # Use "docker volume rm coder_coder_data" to reset Coder diff --git a/services/dozzle/README.md b/services/dozzle/README.md index f9c8697a..9efdeb39 100644 --- a/services/dozzle/README.md +++ b/services/dozzle/README.md @@ -19,7 +19,7 @@ Nothing beyond the [Quick Start](../../README.md#quick-start). ## Deviations from the standard setup -- **Docker socket.** Dozzle mounts `/var/run/docker.sock` read-only to read the logs of all containers on the Docker host. +- **Docker socket.** Dozzle mounts `/var/run/docker.sock` read-only to read the logs of all containers on the Docker host. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. ## First run diff --git a/services/espocrm/.env b/services/espocrm/.env index 7998a830..3a333613 100644 --- a/services/espocrm/.env +++ b/services/espocrm/.env @@ -26,15 +26,19 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim TS_DOMAIN=.ts.net -MARIADB_ROOT_PASSWORD=password +# Required: root password of the database. +MARIADB_ROOT_PASSWORD= MARIADB_DATABASE=espocrm MARIADB_USER=espocrm -MARIADB_PASSWORD=password +# Required: password of the database user. Must equal ESPOCRM_DATABASE_PASSWORD. +MARIADB_PASSWORD= ESPOCRM_DEFAULT_CURRENCY=EUR ESPOCRM_DATABASE_PLATFORM=Mysql ESPOCRM_DATABASE_HOST=database # Compose service name of the MariaDB container ESPOCRM_DATABASE_USER=espocrm -ESPOCRM_DATABASE_PASSWORD=password +# Required: password of the database user. Must equal MARIADB_PASSWORD. +ESPOCRM_DATABASE_PASSWORD= ESPOCRM_ADMIN_USERNAME=admin -ESPOCRM_ADMIN_PASSWORD=password +# Required: password of the first administrator. +ESPOCRM_ADMIN_PASSWORD= ESPOCRM_SITE_URL=https://${SERVICE}.${TS_DOMAIN} diff --git a/services/espocrm/README.md b/services/espocrm/README.md index 42e782c7..cde316c9 100644 --- a/services/espocrm/README.md +++ b/services/espocrm/README.md @@ -21,8 +21,8 @@ This stack runs EspoCRM with a Tailscale sidecar, as described in [the standard Set these values in `.env`: - **`TS_DOMAIN`.** Your Tailnet name with `.ts.net`. The stack builds the address of the site, `ESPOCRM_SITE_URL`, from `SERVICE` and this value. -- **`ESPOCRM_ADMIN_USERNAME` and `ESPOCRM_ADMIN_PASSWORD`.** The administrator account that EspoCRM creates at the first start. The defaults are `admin` and `password`. -- **`MARIADB_ROOT_PASSWORD`, `MARIADB_PASSWORD`, and `ESPOCRM_DATABASE_PASSWORD`.** The passwords of the database. The default is `password`. `MARIADB_PASSWORD` and `ESPOCRM_DATABASE_PASSWORD` must be the same. +- **`ESPOCRM_ADMIN_USERNAME` and `ESPOCRM_ADMIN_PASSWORD`.** The administrator account that EspoCRM creates at the first start. The default user is `admin`. The password is empty, and Compose stops with an error until you set it. +- **`MARIADB_ROOT_PASSWORD`, `MARIADB_PASSWORD`, and `ESPOCRM_DATABASE_PASSWORD`.** The passwords of the database. They are empty, and Compose stops with an error until you set them. `MARIADB_PASSWORD` and `ESPOCRM_DATABASE_PASSWORD` must be the same. ## Deviations from the standard setup @@ -41,6 +41,10 @@ From EspoCRM 10, the upstream Docker setup no longer mounts the whole `/var/www/ 2. Run `docker compose down`, then `docker compose pull` and `docker compose up -d`. 3. Optionally, remove the files that older images copied into `./espocrm-data`, such as `application`, `vendor`, and `bootstrap.php`. The [EspoCRM 10 migration guide](https://docs.espocrm.com/administration/docker/installation/#migration-to-espocrm-10) lists them all. +Earlier versions of this stack had sample values for `ESPOCRM_ADMIN_PASSWORD`, `MARIADB_ROOT_PASSWORD`, `MARIADB_PASSWORD`, and `ESPOCRM_DATABASE_PASSWORD` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample values, set `MARIADB_ROOT_PASSWORD`, `MARIADB_PASSWORD`, and `ESPOCRM_DATABASE_PASSWORD` to `password` again. The database still uses it. + +`ESPOCRM_ADMIN_PASSWORD` only creates the administrator at the first start. A new value does not change an existing account. If you still log in as `admin` with the password `password`, change the password in the web interface. + ## Links - [EspoCRM documentation](https://docs.espocrm.com/) diff --git a/services/espocrm/compose.yaml b/services/espocrm/compose.yaml index 8b7b363a..85bdaebf 100644 --- a/services/espocrm/compose.yaml +++ b/services/espocrm/compose.yaml @@ -52,10 +52,10 @@ services: image: mariadb:12.2 container_name: db-${SERVICE} environment: - - MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD} + - MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD:?Set MARIADB_ROOT_PASSWORD in .env} - MARIADB_DATABASE=${MARIADB_DATABASE} - MARIADB_USER=${MARIADB_USER} - - MARIADB_PASSWORD=${MARIADB_PASSWORD} + - MARIADB_PASSWORD=${MARIADB_PASSWORD:?Set MARIADB_PASSWORD in .env} volumes: - ./${SERVICE}-db:/var/lib/mysql restart: always @@ -73,9 +73,9 @@ services: - ESPOCRM_DATABASE_PLATFORM=${ESPOCRM_DATABASE_PLATFORM} - ESPOCRM_DATABASE_HOST=${ESPOCRM_DATABASE_HOST} - ESPOCRM_DATABASE_USER=${ESPOCRM_DATABASE_USER} - - ESPOCRM_DATABASE_PASSWORD=${ESPOCRM_DATABASE_PASSWORD} + - ESPOCRM_DATABASE_PASSWORD=${ESPOCRM_DATABASE_PASSWORD:?Set ESPOCRM_DATABASE_PASSWORD in .env} - ESPOCRM_ADMIN_USERNAME=${ESPOCRM_ADMIN_USERNAME} - - ESPOCRM_ADMIN_PASSWORD=${ESPOCRM_ADMIN_PASSWORD} + - ESPOCRM_ADMIN_PASSWORD=${ESPOCRM_ADMIN_PASSWORD:?Set ESPOCRM_ADMIN_PASSWORD in .env} - ESPOCRM_SITE_URL=${ESPOCRM_SITE_URL} - ESPOCRM_DEFAULT_CURRENCY=${ESPOCRM_DEFAULT_CURRENCY} - TZ=${TZ} diff --git a/services/flatnotes/.env b/services/flatnotes/.env index 0e23715b..bdc568df 100644 --- a/services/flatnotes/.env +++ b/services/flatnotes/.env @@ -22,7 +22,9 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Flatnotes environment FLATNOTES_AUTH_TYPE=password FLATNOTES_USERNAME=user -FLATNOTES_PASSWORD=changeMe! -FLATNOTES_SECRET_KEY=aLongRandomSeriesOfCharacters +# Required: password of the web interface. +FLATNOTES_PASSWORD= +# Required: signs the login tokens. Generate it with: openssl rand -hex 32 +FLATNOTES_SECRET_KEY= #EXAMPLE_VAR="Environment variable" diff --git a/services/flatnotes/README.md b/services/flatnotes/README.md index 2b24f470..35f8ab1c 100644 --- a/services/flatnotes/README.md +++ b/services/flatnotes/README.md @@ -17,8 +17,8 @@ This stack runs flatnotes with a Tailscale sidecar, as described in [the standar Change these values in `.env`: -- **`FLATNOTES_USERNAME` and `FLATNOTES_PASSWORD`.** The login of the web interface. The defaults are `user` and `changeMe!`. -- **`FLATNOTES_SECRET_KEY`.** A long random value that flatnotes uses to sign the login tokens. +- **`FLATNOTES_USERNAME` and `FLATNOTES_PASSWORD`.** The login of the web interface. The default user is `user`. The password is empty, and Compose stops with an error until you set it. +- **`FLATNOTES_SECRET_KEY`.** A long random value that flatnotes uses to sign the login tokens. Generate one with `openssl rand -hex 32`. Compose stops with an error if it is empty. ## Deviations from the standard setup @@ -28,6 +28,10 @@ None. Open the web interface and log in with the username and password from `.env`. +## Upgrading + +Earlier versions of this stack had sample values for `FLATNOTES_PASSWORD` and `FLATNOTES_SECRET_KEY` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. + ## Links - [flatnotes documentation and source code](https://github.com/dullage/flatnotes) diff --git a/services/flatnotes/compose.yaml b/services/flatnotes/compose.yaml index b77288c4..46ff5f0f 100644 --- a/services/flatnotes/compose.yaml +++ b/services/flatnotes/compose.yaml @@ -58,8 +58,8 @@ services: - TZ=${TZ} - FLATNOTES_AUTH_TYPE=${FLATNOTES_AUTH_TYPE} - FLATNOTES_USERNAME=${FLATNOTES_USERNAME} - - FLATNOTES_PASSWORD=${FLATNOTES_PASSWORD} - - FLATNOTES_SECRET_KEY=${FLATNOTES_SECRET_KEY} + - FLATNOTES_PASSWORD=${FLATNOTES_PASSWORD:?Set FLATNOTES_PASSWORD in .env} + - FLATNOTES_SECRET_KEY=${FLATNOTES_SECRET_KEY:?Set FLATNOTES_SECRET_KEY in .env} volumes: - ./${SERVICE}-data:/data depends_on: diff --git a/services/formbricks/.env b/services/formbricks/.env index acf6f59b..cee55dc3 100644 --- a/services/formbricks/.env +++ b/services/formbricks/.env @@ -37,8 +37,11 @@ NEXTAUTH_URL=${WEBAPP_URL} # Set the below to your public domain (default is WEBAPP_URL) PUBLIC_URL=${WEBAPP_URL} +# Required: password of the database. Use letters and digits only, because DATABASE_URL contains it. +POSTGRES_PASSWORD= + # PostgreSQL DB for Formbricks to connect to -DATABASE_URL="postgresql://postgres:postgres@postgres:5432/formbricks?schema=public" +DATABASE_URL="postgresql://postgres:${POSTGRES_PASSWORD}@postgres:5432/formbricks?schema=public" # NextJS Auth # @see: https://next-auth.js.org/configuration/options#nextauth_secret @@ -158,7 +161,7 @@ S3_FORCE_PATH_STYLE="0" # OIDC_SIGNING_ALGORITHM="" # Set the below to SAML Provider if you want to enable SAML -# SAML_DATABASE_URL="postgresql://postgres:postgres@postgres:5432/formbricks-saml?sslmode=disable" +# SAML_DATABASE_URL="postgresql://postgres:${POSTGRES_PASSWORD}@postgres:5432/formbricks-saml?sslmode=disable" ########################################## OPTIONAL (THIRD PARTY INTEGRATIONS) ########################################### diff --git a/services/formbricks/README.md b/services/formbricks/README.md index 4cf584da..0fad2bf5 100644 --- a/services/formbricks/README.md +++ b/services/formbricks/README.md @@ -23,6 +23,7 @@ Set these values in `.env`: - **`TS_URL`.** The name of the device on your Tailnet, `formbricks..ts.net`. - **`WEBAPP_URL`.** The address that you use to open Formbricks. The sample value is `http://${TS_URL}:3000`, which is the direct port on the Tailnet. To use the HTTPS address of Tailscale Serve, change it to `https://${TS_URL}`. `NEXTAUTH_URL` and `PUBLIC_URL` follow this value. +- **`POSTGRES_PASSWORD`.** The password of the database, with letters and digits only. `DATABASE_URL` in `.env` contains it. Compose stops with an error if it is empty. - **`NEXTAUTH_SECRET`, `ENCRYPTION_KEY`, and `CRON_SECRET`.** Three different random values. Generate each with `openssl rand -hex 32`. Compose stops with an error if one of them is empty. - **The `SMTP_*` and `MAIL_FROM` values.** The details of your mail server, if Formbricks should send email. The sample values do not work. @@ -30,7 +31,6 @@ Set these values in `.env`: - **Service name.** The application service is called `formbricks`, not `application`. - **Extra containers.** The stack runs `postgres` and `redis` (Valkey). They use the default Compose network, and Formbricks reaches them by their service name through Docker's DNS. Keep `TS_ACCEPT_DNS` disabled, because MagicDNS cannot resolve these names. -- **Database password.** The password of the database is `postgres`, set in `compose.yaml` and in `DATABASE_URL` in `.env`. Change both to the same value before the first start. - **Pinned version.** The stack pins Formbricks to `4.9.7`. Formbricks 5.0 and later also need the Cube, Hub, and SpiceDB services, which this stack does not include. See the [upstream Compose file](https://github.com/formbricks/formbricks/blob/main/docker/docker-compose.yml) before you upgrade. - **Email verification and password reset are off.** `.env` sets `EMAIL_VERIFICATION_DISABLED="1"` and `PASSWORD_RESET_DISABLED="1"`, so Formbricks works without a mail server. @@ -45,6 +45,8 @@ Earlier versions of this stack shipped sample values for `NEXTAUTH_SECRET`, `ENC - If you already replaced the sample values, keep your own. - If your `.env` still has the sample values, set new ones. With a new `NEXTAUTH_SECRET`, everyone has to log in again. Formbricks uses `ENCRYPTION_KEY` for two-factor authentication and for single-use links of link surveys, so existing ones stop working with a new key. +Earlier versions also had the database password `postgres` in `compose.yaml` and in `DATABASE_URL`. The password is now `POSTGRES_PASSWORD` in `.env`. It is empty, and Compose stops with an error until you set it. If you already run the stack, set it to the password that you use now, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=postgres` again. The database still uses it. If your `.env` is older, also replace the password in `DATABASE_URL` with `${POSTGRES_PASSWORD}`. + ## Links - [Formbricks self-hosting documentation](https://formbricks.com/docs/self-hosting/overview) diff --git a/services/formbricks/compose.yaml b/services/formbricks/compose.yaml index a287f060..fae4e783 100644 --- a/services/formbricks/compose.yaml +++ b/services/formbricks/compose.yaml @@ -60,7 +60,7 @@ services: volumes: - ./${SERVICE}-data/postgres:/var/lib/postgresql/data environment: - - POSTGRES_PASSWORD=postgres + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} redis: container_name: app-${SERVICE}-redis # Name for local container management healthcheck: diff --git a/services/freshrss/README.md b/services/freshrss/README.md index dbb6e693..e24686d8 100644 --- a/services/freshrss/README.md +++ b/services/freshrss/README.md @@ -20,7 +20,7 @@ Set these values in `.env` before the first start. FreshRSS uses them only while - **`TAILNET_NAME`.** Your Tailnet name with `.ts.net`. `compose.yaml` builds the base address of FreshRSS as `https://.`. - **`ADMIN_USERNAME`, `ADMIN_PASSWORD`, and `ADMIN_EMAIL`.** The administrator account. -- **`ADMIN_API_PASSWORD`.** The password for clients that use the API. +- **`ADMIN_API_PASSWORD`.** The password for clients that use the API. Compose stops with an error if `ADMIN_PASSWORD` or `ADMIN_API_PASSWORD` is empty. Do not use `$`, backticks, or backslashes in these values. diff --git a/services/freshrss/compose.yaml b/services/freshrss/compose.yaml index 995c5bca..d7eb71e6 100644 --- a/services/freshrss/compose.yaml +++ b/services/freshrss/compose.yaml @@ -58,7 +58,7 @@ services: - TRUSTED_PROXY=127.0.0.1 # Tailscale Serve reaches FreshRSS over the shared loopback, so trust it for X-Forwarded-For # The two variables below are only read on the very first start (empty data volume). - FRESHRSS_INSTALL=--api-enabled --base-url https://${SERVICE}.${TAILNET_NAME} --db-type sqlite --default-user ${ADMIN_USERNAME} --language en - - FRESHRSS_USER=--api-password ${ADMIN_API_PASSWORD} --email ${ADMIN_EMAIL} --language en --password ${ADMIN_PASSWORD} --user ${ADMIN_USERNAME} + - FRESHRSS_USER=--api-password ${ADMIN_API_PASSWORD:?Set ADMIN_API_PASSWORD in .env} --email ${ADMIN_EMAIL} --language en --password ${ADMIN_PASSWORD:?Set ADMIN_PASSWORD in .env} --user ${ADMIN_USERNAME} volumes: - ./${SERVICE}-data/app/data:/var/www/FreshRSS/data # Configuration, SQLite database, feeds and articles - ./${SERVICE}-data/app/extensions:/var/www/FreshRSS/extensions # Optional third-party extensions diff --git a/services/frigate/.env b/services/frigate/.env index a5e70557..ea82fe36 100644 --- a/services/frigate/.env +++ b/services/frigate/.env @@ -20,4 +20,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Optional Service variables # PUID=1000 +# Frigate Configuration +# Optional: password of your cameras. Use it in config.yml as {FRIGATE_RTSP_PASSWORD}. +FRIGATE_RTSP_PASSWORD= + #EXAMPLE_VAR="Environment variable" diff --git a/services/frigate/README.md b/services/frigate/README.md index e5e27374..059d4bc6 100644 --- a/services/frigate/README.md +++ b/services/frigate/README.md @@ -17,7 +17,7 @@ This stack runs Frigate with a Tailscale sidecar, as described in [the standard ## Before you start -Change `FRIGATE_RTSP_PASSWORD` in `compose.yaml`. The sample value is `password`. +Set `FRIGATE_RTSP_PASSWORD` in `.env` to the password of your cameras, if you want to keep it out of the Frigate configuration. Frigate replaces `{FRIGATE_RTSP_PASSWORD}` in the camera addresses in `config.yml` with this value. The value is optional and empty by default. ## Deviations from the standard setup @@ -38,6 +38,10 @@ Change `FRIGATE_RTSP_PASSWORD` in `compose.yaml`. The sample value is `password` 2. Open the web interface and log in. 3. Add your cameras in the configuration editor of the web interface. Frigate stores the configuration in `./frigate-data/config/config.yml`. +## Upgrading + +Earlier versions of this stack set `FRIGATE_RTSP_PASSWORD=password` in `compose.yaml`. The value is now empty in `.env`. If your `config.yml` uses `{FRIGATE_RTSP_PASSWORD}`, set the password of your cameras in `.env`. + ## Links - [Frigate documentation](https://docs.frigate.video/) diff --git a/services/frigate/compose.yaml b/services/frigate/compose.yaml index 287715d3..bda115e7 100644 --- a/services/frigate/compose.yaml +++ b/services/frigate/compose.yaml @@ -68,7 +68,7 @@ services: - PUID=1000 - PGID=1000 - TZ=${TZ} - - FRIGATE_RTSP_PASSWORD=password + - FRIGATE_RTSP_PASSWORD=${FRIGATE_RTSP_PASSWORD} # Optional: password of your cameras, for use as {FRIGATE_RTSP_PASSWORD} in config.yml volumes: - /etc/localtime:/etc/localtime:ro - ./${SERVICE}-data/config:/config diff --git a/services/ghost/.env b/services/ghost/.env index 5471dd32..9f493731 100644 --- a/services/ghost/.env +++ b/services/ghost/.env @@ -22,4 +22,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Public URL used by Ghost to build links and redirects. Replace the placeholder with your Tailnet hostname. GHOST_URL=https://ghost..ts.net +# Database (MySQL) +# Required: password of the MySQL root user, which Ghost uses to connect. +MYSQL_ROOT_PASSWORD= + #EXAMPLE_VAR="Environment variable" diff --git a/services/ghost/README.md b/services/ghost/README.md index cc83c869..72b07370 100644 --- a/services/ghost/README.md +++ b/services/ghost/README.md @@ -18,7 +18,7 @@ This stack runs Ghost with a Tailscale sidecar, as described in [the standard se ## Before you start - **Set `GHOST_URL` in `.env`.** Use the address of the site, `https://ghost..ts.net`. Ghost does not start with the sample value and reports `Invalid URL`. -- **Change the database password.** `compose.yaml` uses the password `example` for the MySQL `root` user, in `database__connection__password` and in `MYSQL_ROOT_PASSWORD`. Replace both with the same value of your own before the first start. +- **Set `MYSQL_ROOT_PASSWORD` in `.env`.** The password of the MySQL `root` user, which Ghost uses to connect to the database. Compose stops with an error if it is empty. ## Deviations from the standard setup @@ -29,6 +29,10 @@ This stack runs Ghost with a Tailscale sidecar, as described in [the standard se Open `https://ghost..ts.net/ghost` and create the first account, which becomes the owner of the site. +## Upgrading + +Earlier versions of this stack had the password `example` for the MySQL `root` user in `compose.yaml`. The password is now `MYSQL_ROOT_PASSWORD` in `.env`. It is empty, and Compose stops with an error until you set it. If you already run the stack, set it to the password that you use now, because the database applies it only at the first start. If you kept the sample value, set `MYSQL_ROOT_PASSWORD=example` again. The database still uses it. + ## Links - [Ghost documentation](https://ghost.org/docs/) diff --git a/services/ghost/compose.yaml b/services/ghost/compose.yaml index 9bab8e8f..e3c375eb 100644 --- a/services/ghost/compose.yaml +++ b/services/ghost/compose.yaml @@ -57,7 +57,7 @@ services: database__client: mysql database__connection__host: db database__connection__user: root - database__connection__password: example + database__connection__password: ${MYSQL_ROOT_PASSWORD:?Set MYSQL_ROOT_PASSWORD in .env} database__connection__database: ghost # this url value is just an example, and is likely wrong for your environment! @@ -85,7 +85,7 @@ services: image: mysql:8.0 container_name: db-${SERVICE} # Name for local container management environment: - MYSQL_ROOT_PASSWORD: example + MYSQL_ROOT_PASSWORD: ${MYSQL_ROOT_PASSWORD:?Set MYSQL_ROOT_PASSWORD in .env} volumes: - ./${SERVICE}-data/db:/var/lib/mysql healthcheck: diff --git a/services/gitsave/.env b/services/gitsave/.env index c68b4216..48512b35 100644 --- a/services/gitsave/.env +++ b/services/gitsave/.env @@ -19,9 +19,10 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Optional Service variables # PUID=1000 -# You can generate a JWT_SECRET here: https://jwtsecrets.com/#generator -JWT_SECRET="REPLACE_THIS" +# Required: signs the login tokens. Generate it with: openssl rand -hex 32 +JWT_SECRET= DISABLE_AUTH=false -ENCRYPTION_SECRET="REPLACE_THIS_WITH_32_CHARACTERS_SECRET" +# Required: encrypts stored data. Exactly 32 characters. Generate it with: openssl rand -hex 16 +ENCRYPTION_SECRET= #EXAMPLE_VAR="Environment variable" diff --git a/services/gitsave/README.md b/services/gitsave/README.md index 0ec06e86..79102fb1 100644 --- a/services/gitsave/README.md +++ b/services/gitsave/README.md @@ -18,8 +18,8 @@ This stack runs GitSave with a Tailscale sidecar, as described in [the standard Replace these values in `.env`: -- **`JWT_SECRET`.** A long random value. -- **`ENCRYPTION_SECRET`.** A random value of exactly 32 characters, for example from `openssl rand -hex 16`. GitSave does not start with the sample value and reports `ENCRYPTION_SECRET must be 32 bytes`. +- **`JWT_SECRET`.** A long random value. Generate one with `openssl rand -hex 32`. +- **`ENCRYPTION_SECRET`.** A random value of exactly 32 characters, for example from `openssl rand -hex 16`. Compose stops with an error if `JWT_SECRET` or `ENCRYPTION_SECRET` is empty. ## Deviations from the standard setup @@ -29,6 +29,10 @@ None. Open the web interface and create the first account. +## Upgrading + +Earlier versions of this stack had sample values for `JWT_SECRET` and `ENCRYPTION_SECRET` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. + ## Links - [GitSave documentation and source code](https://github.com/TimWitzdam/GitSave) diff --git a/services/gitsave/compose.yaml b/services/gitsave/compose.yaml index 1b177964..cad6b9f8 100644 --- a/services/gitsave/compose.yaml +++ b/services/gitsave/compose.yaml @@ -56,9 +56,9 @@ services: - PUID=1000 - PGID=1000 - TZ=${TZ} - - JWT_SECRET=${JWT_SECRET:?error} + - JWT_SECRET=${JWT_SECRET:?Set JWT_SECRET in .env} - DISABLE_AUTH=${DISABLE_AUTH:?error} - - ENCRYPTION_SECRET=${ENCRYPTION_SECRET:?error} + - ENCRYPTION_SECRET=${ENCRYPTION_SECRET:?Set ENCRYPTION_SECRET in .env} volumes: - ./${SERVICE}-data/gitsave:/app/data - ./${SERVICE}-data/backups:/app/backups diff --git a/services/gotify/.env b/services/gotify/.env index 27805bd6..bb456dc9 100644 --- a/services/gotify/.env +++ b/services/gotify/.env @@ -19,4 +19,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Optional Service variables # PUID=1000 +# Gotify Configuration +# Required: password of the user admin that Gotify creates at the first start. +GOTIFY_DEFAULTUSER_PASS= + #EXAMPLE_VAR="Environment variable" diff --git a/services/gotify/README.md b/services/gotify/README.md index b8f0ab46..ec75f073 100644 --- a/services/gotify/README.md +++ b/services/gotify/README.md @@ -15,7 +15,7 @@ This stack runs Gotify with a Tailscale sidecar, as described in [the standard s ## Before you start -Change `GOTIFY_DEFAULTUSER_PASS` in `compose.yaml`. It sets the password of the user `admin` that Gotify creates at the first start, and the sample value is `admin`. +Set `GOTIFY_DEFAULTUSER_PASS` in `.env`. It is the password of the user `admin` that Gotify creates at the first start. Compose stops with an error if it is empty. ## Deviations from the standard setup @@ -27,6 +27,10 @@ Open the web interface and log in with username `admin` and the password from `G In the Gotify app, use `https://gotify..ts.net` as the server address. The device must be connected to your Tailnet. +## Upgrading + +Earlier versions of this stack set `GOTIFY_DEFAULTUSER_PASS=admin` in `compose.yaml`. The value is now empty in `.env`, and Compose stops with an error until you set it. Gotify reads it only at the first start, so a new value does not change the password of an existing installation. If you still log in as `admin` with the password `admin`, change the password in the web interface. + ## Links - [Gotify documentation](https://gotify.net/docs/) diff --git a/services/gotify/compose.yaml b/services/gotify/compose.yaml index 945715f3..9f32c2c8 100644 --- a/services/gotify/compose.yaml +++ b/services/gotify/compose.yaml @@ -53,7 +53,7 @@ services: network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale container_name: app-${SERVICE} # Name for local container management environment: - - GOTIFY_DEFAULTUSER_PASS=admin + - GOTIFY_DEFAULTUSER_PASS=${GOTIFY_DEFAULTUSER_PASS:?Set GOTIFY_DEFAULTUSER_PASS in .env} # Password of the user admin; only read at the first start - TZ=${TZ} volumes: - ./${SERVICE}-data/app/data:/app/data diff --git a/services/homepage/README.md b/services/homepage/README.md index 319a538b..487b9d4c 100644 --- a/services/homepage/README.md +++ b/services/homepage/README.md @@ -20,7 +20,7 @@ Set `TAILNET_NAME` in `.env` to your Tailnet name, without `.ts.net`. Homepage o ## Deviations from the standard setup - **Allowed host.** `HOMEPAGE_ALLOWED_HOSTS` contains the fixed name `homepage`. If you change `SERVICE` in `.env`, change this value in `compose.yaml` as well. -- **Docker socket.** Homepage mounts `/var/run/docker.sock` read-only for its Docker integration. Remove the line if you do not use it. +- **Docker socket.** Homepage mounts `/var/run/docker.sock` read-only for its Docker integration. Remove the line if you do not use it. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. ## First run diff --git a/services/immich/.env b/services/immich/.env index aab430db..b9fa5900 100644 --- a/services/immich/.env +++ b/services/immich/.env @@ -35,7 +35,8 @@ IMMICH_VERSION=release # Connection secret for postgres. You should change it to a random password # Please use only the characters `A-Za-z0-9`, without special characters or spaces -DB_PASSWORD=postgres +# Required: password of the database. Use only the characters A-Z, a-z and 0-9. +DB_PASSWORD= # The values below this line do not need to be changed ################################################################################### diff --git a/services/immich/README.md b/services/immich/README.md index 55c78f2e..0fdcc09d 100644 --- a/services/immich/README.md +++ b/services/immich/README.md @@ -20,7 +20,7 @@ This stack runs Immich with a Tailscale sidecar, as described in [the standard s ## Before you start -* **Set a database password.** Change `DB_PASSWORD` in `.env` to a random value. Use only the characters `A-Za-z0-9`. +* **Set a database password.** Set `DB_PASSWORD` in `.env` to a random value. Use only the characters `A-Za-z0-9`. It is empty, and Compose stops with an error until you set it. * **Choose where your media is stored.** To keep your photos and videos on another disk, set `UPLOAD_LOCATION` before the first start. See [Storage locations](#storage-locations). * **Compare with upstream.** Immich changes its [Compose file](https://docs.immich.app/install/docker-compose) often. We try to keep this stack in line with it, but check for yourself before you deploy. @@ -59,6 +59,8 @@ Immich connects to the hostnames `database` and `redis` by default. If you renam Earlier versions of this stack ignored `UPLOAD_LOCATION` and `DB_DATA_LOCATION` and always used the default folders. If your `.env` still contains `UPLOAD_LOCATION=./library` or `DB_DATA_LOCATION=./postgres`, replace them with the defaults from [Storage locations](#storage-locations) before you restart. Otherwise Immich starts with an empty library and a new database. Your existing files stay untouched in `./immich-data`. +Earlier versions of this stack had a sample value for `DB_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `DB_PASSWORD=postgres` again. The database still uses it. + ## Links * [Immich documentation](https://docs.immich.app/) diff --git a/services/immich/compose.yaml b/services/immich/compose.yaml index 505e54ec..3c8162ae 100644 --- a/services/immich/compose.yaml +++ b/services/immich/compose.yaml @@ -98,7 +98,7 @@ services: container_name: app-${SERVICE}-postgres image: ghcr.io/immich-app/postgres:14-vectorchord0.4.3-pgvectors0.2.0@sha256:bcf63357191b76a916ae5eb93464d65c07511da41e3bf7a8416db519b40b1c23 environment: - POSTGRES_PASSWORD: ${DB_PASSWORD} + POSTGRES_PASSWORD: ${DB_PASSWORD:?Set DB_PASSWORD in .env} POSTGRES_USER: ${DB_USERNAME} POSTGRES_DB: ${DB_DATABASE_NAME} POSTGRES_INITDB_ARGS: "--data-checksums" diff --git a/services/kaneo/.env b/services/kaneo/.env index e5ed3255..64fd2d09 100644 --- a/services/kaneo/.env +++ b/services/kaneo/.env @@ -32,12 +32,14 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim KANEO_CLIENT_URL="https://kaneo..ts.net" # AUTH Configuration +# Required: signs the sessions. Generate it with: openssl rand -hex 32 AUTH_SECRET= # Kaneo trusts only loopback proxies by default (TRUSTED_PROXIES), which covers Tailscale Serve. # DB Configuration DB_USERNAME=kaneo DB_DATABASE_NAME=kaneo +# Required: password of the database. Generate it with: openssl rand -hex 32 DB_PASSWORD= #EXAMPLE_VAR="Environment variable" diff --git a/services/kaneo/README.md b/services/kaneo/README.md index 5a2ee592..4ba3a161 100644 --- a/services/kaneo/README.md +++ b/services/kaneo/README.md @@ -19,7 +19,7 @@ This stack runs Kaneo with a Tailscale sidecar, as described in [the standard se Set these values in `.env`: - **`KANEO_CLIENT_URL`.** The address of the web interface, `https://kaneo..ts.net`. Kaneo derives the address of its API from it and does not start with the sample value. Recreate the container after you change it. -- **`AUTH_SECRET` and `DB_PASSWORD`.** Two different random values. Generate each with `openssl rand -hex 32`. +- **`AUTH_SECRET` and `DB_PASSWORD`.** Two different random values. Generate each with `openssl rand -hex 32`. Compose stops with an error if one of them is empty. ## Deviations from the standard setup diff --git a/services/kaneo/compose.yaml b/services/kaneo/compose.yaml index 5d4775ea..b788f526 100644 --- a/services/kaneo/compose.yaml +++ b/services/kaneo/compose.yaml @@ -56,7 +56,7 @@ services: env_file: - .env environment: - POSTGRES_PASSWORD: ${DB_PASSWORD} + POSTGRES_PASSWORD: ${DB_PASSWORD:?Set DB_PASSWORD in .env} POSTGRES_USER: ${DB_USERNAME} POSTGRES_DB: ${DB_DATABASE_NAME} volumes: @@ -77,7 +77,8 @@ services: env_file: - .env environment: - DATABASE_URL: "postgresql://${DB_USERNAME}:${DB_PASSWORD}@localhost:${SERVICEPORT_DATABASE}/${DB_DATABASE_NAME}" + AUTH_SECRET: ${AUTH_SECRET:?Set AUTH_SECRET in .env} + DATABASE_URL: "postgresql://${DB_USERNAME}:${DB_PASSWORD:?Set DB_PASSWORD in .env}@localhost:${SERVICEPORT_DATABASE}/${DB_DATABASE_NAME}" depends_on: tailscale: condition: service_healthy diff --git a/services/kitchenowl/.env b/services/kitchenowl/.env index 7473b23d..8639605e 100755 --- a/services/kitchenowl/.env +++ b/services/kitchenowl/.env @@ -22,7 +22,7 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim #EXAMPLE_VAR="Environment variable" -# Generate a random string for JWT secret key, e.g., using: openssl rand -base64 32 +# Required: signs the login tokens. Generate it with: openssl rand -hex 32 JWT_SECRET_KEY= FRONT_URL=https://kitchenowl..ts.net # the exact URL of your kitchenowl instance, required when using OIDC authentication, e.g https://kitchenowl.example.com diff --git a/services/kitchenowl/README.md b/services/kitchenowl/README.md index f2aca7c7..8fe60076 100644 --- a/services/kitchenowl/README.md +++ b/services/kitchenowl/README.md @@ -15,7 +15,7 @@ This stack runs KitchenOwl with a Tailscale sidecar, as described in [the standa ## Before you start -Set `JWT_SECRET_KEY` in `.env` to a long random value, for example from `openssl rand -hex 32`. +Set `JWT_SECRET_KEY` in `.env` to a long random value, for example from `openssl rand -hex 32`. Compose stops with an error if it is empty. ## Deviations from the standard setup diff --git a/services/kitchenowl/compose.yaml b/services/kitchenowl/compose.yaml index ee3e406c..0262fee6 100755 --- a/services/kitchenowl/compose.yaml +++ b/services/kitchenowl/compose.yaml @@ -56,7 +56,7 @@ services: volumes: - ./${SERVICE}-data/:/data environment: - - JWT_SECRET_KEY=${JWT_SECRET_KEY} # JWT secret key for authentication - make sure to set this in the .env file + - JWT_SECRET_KEY=${JWT_SECRET_KEY:?Set JWT_SECRET_KEY in .env} # JWT secret key for authentication - make sure to set this in the .env file ## Optional for OIDC support - make sure to set these in the .env file if required! #- FRONT_URL=${FRONT_URL} #- OIDC_ISSUER=${OIDC_ISSUER} diff --git a/services/mattermost/.env b/services/mattermost/.env index ce744d1d..0e024cd0 100644 --- a/services/mattermost/.env +++ b/services/mattermost/.env @@ -57,9 +57,10 @@ POSTGRES_IMAGE_TAG=17-alpine POSTGRES_DATA_PATH=./${SERVICE}-data/postgres/data POSTGRES_USER=MMus3r ##Please Change -POSTGRES_PASSWORD=MMus3r_P4ssword ##Please Change +# Required: password of the database. Use letters and digits only, because the database address contains it. +POSTGRES_PASSWORD= POSTGRES_DB=mattermost MM_SQLSETTINGS_DRIVERNAME=postgres -MM_SQLSETTINGS_DATASOURCE=postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@db-${SERVICE}:5432/${POSTGRES_DB}?sslmode=disable&connect_timeout=10 +MM_SQLSETTINGS_DATASOURCE=postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env}@db-${SERVICE}:5432/${POSTGRES_DB}?sslmode=disable&connect_timeout=10 #EXAMPLE_VAR="Environment variable" diff --git a/services/mattermost/README.md b/services/mattermost/README.md index 3891dfa2..9dc2e5f1 100644 --- a/services/mattermost/README.md +++ b/services/mattermost/README.md @@ -30,7 +30,7 @@ This stack runs Mattermost with a Tailscale sidecar, as described in [the standa 2. Set these values in `.env`: - **`DOMAIN`.** The name of the device on your Tailnet, `mattermost..ts.net`. The stack builds the site address, `MM_SERVICESETTINGS_SITEURL`, from it. - - **`POSTGRES_USER` and `POSTGRES_PASSWORD`.** The login of the database. Replace the sample values. + - **`POSTGRES_USER` and `POSTGRES_PASSWORD`.** The login of the database. `POSTGRES_PASSWORD` is empty, and Compose stops with an error until you set it. Use letters and digits only, because the database address contains it. ## Deviations from the standard setup @@ -43,6 +43,10 @@ This stack runs Mattermost with a Tailscale sidecar, as described in [the standa Open the web interface and create the first account, which becomes the system administrator. Then create your team. +## Upgrading + +Earlier versions of this stack had a sample value for `POSTGRES_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=MMus3r_P4ssword` again. The database still uses it. + ## Links - [Mattermost documentation](https://docs.mattermost.com/) diff --git a/services/mattermost/compose.yaml b/services/mattermost/compose.yaml index 3c8545ab..61482a38 100644 --- a/services/mattermost/compose.yaml +++ b/services/mattermost/compose.yaml @@ -111,5 +111,5 @@ services: - TZ=${TZ} # necessary Postgres options/variables defined in the .env file - POSTGRES_USER - - POSTGRES_PASSWORD + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} - POSTGRES_DB diff --git a/services/miniflux/.env b/services/miniflux/.env index 68f9808e..a0294aaa 100644 --- a/services/miniflux/.env +++ b/services/miniflux/.env @@ -24,6 +24,7 @@ ADMIN_USERNAME=admin ADMIN_PASSWORD= # Database configuration POSTGRES_USER=miniflux +# Required: password of the database. Use letters and digits only, because the database address contains it. POSTGRES_PASSWORD= POSTGRES_DB=miniflux diff --git a/services/miniflux/README.md b/services/miniflux/README.md index c1b9ce8e..8480950f 100644 --- a/services/miniflux/README.md +++ b/services/miniflux/README.md @@ -20,7 +20,7 @@ Set these values in `.env`: - **`TAILNET_NAME`.** Your Tailnet name with `.ts.net`. `compose.yaml` builds the base address of Miniflux as `https://.`. - **`ADMIN_USERNAME` and `ADMIN_PASSWORD`.** The administrator account that Miniflux creates at the first start. The password needs at least six characters. -- **`POSTGRES_PASSWORD`.** The password of the database. +- **`POSTGRES_PASSWORD`.** The password of the database. Use letters and digits only, because the database address contains it. Compose stops with an error if `ADMIN_PASSWORD` or `POSTGRES_PASSWORD` is empty. ## Deviations from the standard setup diff --git a/services/miniflux/compose.yaml b/services/miniflux/compose.yaml index cddef7a8..b424c487 100644 --- a/services/miniflux/compose.yaml +++ b/services/miniflux/compose.yaml @@ -53,11 +53,11 @@ services: network_mode: service:tailscale # Sidecar configuration to route the service through Tailscale container_name: app-${SERVICE} # Name for local container management environment: - - DATABASE_URL=postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD}@localhost/${POSTGRES_DB}?sslmode=disable + - DATABASE_URL=postgres://${POSTGRES_USER}:${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env}@localhost/${POSTGRES_DB}?sslmode=disable - RUN_MIGRATIONS=1 - CREATE_ADMIN=1 - ADMIN_USERNAME=${ADMIN_USERNAME} - - ADMIN_PASSWORD=${ADMIN_PASSWORD} + - ADMIN_PASSWORD=${ADMIN_PASSWORD:?Set ADMIN_PASSWORD in .env} - BASE_URL=https://${SERVICE}.${TAILNET_NAME} # Change to your tailnet name - TZ=${TZ} depends_on: @@ -80,7 +80,7 @@ services: container_name: app-${SERVICE}-db environment: - POSTGRES_USER=${POSTGRES_USER} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD} + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} - POSTGRES_DB=${POSTGRES_DB} volumes: - ./${SERVICE}-data/db:/var/lib/postgresql/data diff --git a/services/nanote/.env b/services/nanote/.env index 4bd55a6d..e3be42c6 100644 --- a/services/nanote/.env +++ b/services/nanote/.env @@ -19,4 +19,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Optional Service variables # PUID=1000 +# Nanote Configuration +# Required: the key that you log in with. Generate it with: openssl rand -hex 32 +SECRET_KEY= + #EXAMPLE_VAR="Environment variable" diff --git a/services/nanote/README.md b/services/nanote/README.md index 80483fd8..c7d23e80 100644 --- a/services/nanote/README.md +++ b/services/nanote/README.md @@ -15,7 +15,7 @@ This stack runs Nanote with a Tailscale sidecar, as described in [the standard s ## Before you start -Replace `` in `SECRET_KEY` in `compose.yaml` with your own secret. Nanote uses it as the key to log in. +Set `SECRET_KEY` in `.env` to your own secret, for example from `openssl rand -hex 32`. Nanote uses it as the key to log in. Compose stops with an error if it is empty. ## Deviations from the standard setup @@ -25,6 +25,10 @@ None. Open the web interface and log in with the value of `SECRET_KEY`. +## Upgrading + +Earlier versions of this stack had the sample value `` for `SECRET_KEY` in `compose.yaml`. The key is now in `.env`. It is empty, and Compose stops with an error until you set it. If you already run the stack, set it to the key that you use now. If you kept the sample value, choose a new key. Nanote does not store the key, so you only have to log in again. + ## Links - [Nanote documentation and source code](https://github.com/omarmir/nanote) diff --git a/services/nanote/compose.yaml b/services/nanote/compose.yaml index 768ff696..f62735c3 100644 --- a/services/nanote/compose.yaml +++ b/services/nanote/compose.yaml @@ -57,7 +57,7 @@ services: - PGID=1000 - TZ=${TZ} - NOTES_PATH=/notes - - SECRET_KEY= + - SECRET_KEY=${SECRET_KEY:?Set SECRET_KEY in .env} # The key that you log in with volumes: - ./${SERVICE}-data:/notes depends_on: diff --git a/services/next-explorer/.env b/services/next-explorer/.env index 2e4ee85c..5dcfe8c5 100644 --- a/services/next-explorer/.env +++ b/services/next-explorer/.env @@ -24,7 +24,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Any Container environment variables are declared below. See https://docs.docker.com/compose/how-tos/environment-variables/ ACCESS_PATH=/home/root/data # Change this to the path you want to share with Tailscale. This should be an absolute path on the host machine. For example, if you want to share the /home/user/files directory, set ACCESS_PATH=/home/user/files. -SESSION_SECRET=your-super-secret # Use 'openssl rand -base64 32' in your CLI to generate a secure random key. +# Required: signs the sessions. Generate it with: openssl rand -base64 32 +SESSION_SECRET= PUBLIC_URL=https://file-explorer..ts.net # Optional: Set this to the public URL of your service if needed for correct URL generation in the app. For example, if you are exposing the service at https://example.com, set PUBLIC_URL=https://example.com. #EXAMPLE_VAR="Environment variable" diff --git a/services/next-explorer/README.md b/services/next-explorer/README.md index f4c91d5b..266cf9fe 100644 --- a/services/next-explorer/README.md +++ b/services/next-explorer/README.md @@ -20,7 +20,7 @@ This stack runs NextExplorer with a Tailscale sidecar, as described in [the stan Set these values in `.env`: - **`ACCESS_PATH`.** The absolute path of the folder on the Docker host that NextExplorer should show. -- **`SESSION_SECRET`.** A long random value. Generate one with `openssl rand -base64 32`. +- **`SESSION_SECRET`.** A long random value. Generate one with `openssl rand -base64 32`. Compose stops with an error if it is empty. - **`PUBLIC_URL`.** The address of the web interface, `https://file-explorer..ts.net`. NextExplorer uses it for its cookies, so use this address to open the web interface. ## Deviations from the standard setup @@ -34,6 +34,10 @@ Set these values in `.env`: Open the web interface. NextExplorer asks you to create the first account. +## Upgrading + +Earlier versions of this stack had a sample value for `SESSION_SECRET` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. + ## Links - [NextExplorer documentation and source code](https://github.com/nxzai/NextExplorer) diff --git a/services/next-explorer/compose.yaml b/services/next-explorer/compose.yaml index 17c4ca08..b40e0a0c 100644 --- a/services/next-explorer/compose.yaml +++ b/services/next-explorer/compose.yaml @@ -62,7 +62,7 @@ services: - PUBLIC_URL=${PUBLIC_URL} # Optional: Set this to the public URL of your service if needed for correct URL generation in the app. For example, if you are exposing the service at https://example.com, set PUBLIC_URL=https://example.com. # Optional: lock sessions to a known secret - - SESSION_SECRET=${SESSION_SECRET} + - SESSION_SECRET=${SESSION_SECRET:?Set SESSION_SECRET in .env} # Optional host UID/GID mapping - PUID=${PUID} # Change according to your customization if needed diff --git a/services/paperless/.env b/services/paperless/.env index 1916ab28..52e4f79e 100644 --- a/services/paperless/.env +++ b/services/paperless/.env @@ -22,10 +22,13 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim PAPERLESS_TIME_ZONE=Europe/Amsterdam PAPERLESS_OCR_LANGUAGE=eng -PAPERLESS_SECRET_KEY='change this to any random sting' #https://docs.paperless-ngx.com/configuration/#PAPERLESS_SECRET_KEY +# Required: signs the sessions. Generate it with: openssl rand -hex 32 +PAPERLESS_SECRET_KEY= PAPERLESS_ADMIN_USER=admin -PAPERLESS_ADMIN_PASSWORD=changeme +# Required: password of the first administrator. +PAPERLESS_ADMIN_PASSWORD= POSTGRES_USER=paperless -POSTGRES_PASSWORD=paperless +# Required: password of the database. +POSTGRES_PASSWORD= #EXAMPLE_VAR="Environment variable" diff --git a/services/paperless/README.md b/services/paperless/README.md index db90c2f1..787b8ad4 100644 --- a/services/paperless/README.md +++ b/services/paperless/README.md @@ -24,9 +24,9 @@ This stack runs Paperless-ngx with a Tailscale sidecar, as described in [the sta Change these values in `.env`: -- **`PAPERLESS_SECRET_KEY`.** A long random value. Paperless-ngx uses it to sign session tokens. -- **`PAPERLESS_ADMIN_USER` and `PAPERLESS_ADMIN_PASSWORD`.** The administrator account that Paperless-ngx creates at the first start. The defaults are `admin` and `changeme`. -- **`POSTGRES_PASSWORD`.** The password of the database. +- **`PAPERLESS_SECRET_KEY`.** A long random value. Generate one with `openssl rand -hex 32`. Paperless-ngx uses it to sign session tokens. Compose stops with an error if it is empty. +- **`PAPERLESS_ADMIN_USER` and `PAPERLESS_ADMIN_PASSWORD`.** The administrator account that Paperless-ngx creates at the first start. The default user is `admin`. The password is empty, and Compose stops with an error until you set it. +- **`POSTGRES_PASSWORD`.** The password of the database. Compose stops with an error if it is empty. - **`PAPERLESS_OCR_LANGUAGE`.** The language of your documents as a three-letter code, such as `eng` or `nld`. - **`PAPERLESS_TIME_ZONE`.** Your time zone. @@ -40,6 +40,12 @@ Change these values in `.env`: Open the web interface and log in with the administrator account from `.env`. To import documents, upload them in the web interface or put them in `./paperless-data/consume`. +## Upgrading + +Earlier versions of this stack had sample values for `PAPERLESS_SECRET_KEY`, `PAPERLESS_ADMIN_PASSWORD`, and `POSTGRES_PASSWORD` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=paperless` again. The database still uses it. + +`PAPERLESS_ADMIN_PASSWORD` only creates the administrator at the first start. A new value does not change an existing account. If you still log in as `admin` with the password `changeme`, change the password in the web interface. + ## Links - [Paperless-ngx documentation](https://docs.paperless-ngx.com/) diff --git a/services/paperless/compose.yaml b/services/paperless/compose.yaml index 420feeb5..b5551d58 100644 --- a/services/paperless/compose.yaml +++ b/services/paperless/compose.yaml @@ -76,11 +76,11 @@ services: - TZ=${TZ} - PAPERLESS_TIME_ZONE=${PAPERLESS_TIME_ZONE} - PAPERLESS_OCR_LANGUAGE=${PAPERLESS_OCR_LANGUAGE} - - PAPERLESS_SECRET_KEY=${PAPERLESS_SECRET_KEY} + - PAPERLESS_SECRET_KEY=${PAPERLESS_SECRET_KEY:?Set PAPERLESS_SECRET_KEY in .env} - PAPERLESS_PORT=80 - PAPERLESS_PROXY_SSL_HEADER=["HTTP_X_FORWARDED_PROTO", "https"] - PAPERLESS_ADMIN_USER=${PAPERLESS_ADMIN_USER} - - PAPERLESS_ADMIN_PASSWORD=${PAPERLESS_ADMIN_PASSWORD} + - PAPERLESS_ADMIN_PASSWORD=${PAPERLESS_ADMIN_PASSWORD:?Set PAPERLESS_ADMIN_PASSWORD in .env} - PAPERLESS_REDIS=redis://broker:6379 - PAPERLESS_DBHOST=db db: @@ -101,7 +101,7 @@ services: - TZ=${TZ} - POSTGRES_DB=paperless - POSTGRES_USER=${POSTGRES_USER} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD} + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} broker: image: docker.io/library/redis:8 container_name: app-${SERVICE}-broker # Name for local container management diff --git a/services/portracker/README.md b/services/portracker/README.md index 8aeaad57..810c7901 100644 --- a/services/portracker/README.md +++ b/services/portracker/README.md @@ -19,7 +19,7 @@ Nothing beyond the [Quick Start](../../README.md#quick-start). ## Deviations from the standard setup -- **Docker socket.** Portracker mounts `/var/run/docker.sock` read-only to discover the containers on the Docker host. +- **Docker socket.** Portracker mounts `/var/run/docker.sock` read-only to discover the containers on the Docker host. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. - **No access to host processes.** Upstream also uses `pid: host` and the `SYS_PTRACE` and `SYS_ADMIN` capabilities to discover the ports of processes on the host. This stack does not set them. See the upstream documentation if you need these ports. ## First run diff --git a/services/seafile/.env b/services/seafile/.env index 9a6aa72e..514648b9 100644 --- a/services/seafile/.env +++ b/services/seafile/.env @@ -28,16 +28,19 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim SEAFILE_VOLUME=./seafile-data SEAFILE_MYSQL_VOLUME=./db SEAFILE_MYSQL_DB_HOST=db -INIT_SEAFILE_MYSQL_ROOT_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD +# Required: root password of the database. +INIT_SEAFILE_MYSQL_ROOT_PASSWORD= SEAFILE_MYSQL_DB_USER=seafile -SEAFILE_MYSQL_DB_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD +# Required: password of the database user. +SEAFILE_MYSQL_DB_PASSWORD= TIME_ZONE=Etc/UTC #A random string with a length of no less than 32 characters, generate example: pwgen -s 40 1 or use openssl rand -base64 40 JWT_PRIVATE_KEY= SEAFILE_SERVER_HOSTNAME=seafile..ts.net # update with specific MagicDNS suffix SEAFILE_SERVER_PROTOCOL=https INIT_SEAFILE_ADMIN_EMAIL=ADD_EMAIL_ADDRESS_HERE -INIT_SEAFILE_ADMIN_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD +# Required: password of the first administrator. +INIT_SEAFILE_ADMIN_PASSWORD= ENABLE_SEADOC=false ENABLE_NOTIFICATION_SERVER=false CACHE_PROVIDER=memcached diff --git a/services/seafile/README.md b/services/seafile/README.md index 79d2e356..59092042 100644 --- a/services/seafile/README.md +++ b/services/seafile/README.md @@ -21,8 +21,8 @@ This stack runs Seafile with a Tailscale sidecar, as described in [the standard Set these values in `.env`: - **`SEAFILE_SERVER_HOSTNAME`.** The name of the device on your Tailnet, `seafile..ts.net`. -- **`INIT_SEAFILE_MYSQL_ROOT_PASSWORD` and `SEAFILE_MYSQL_DB_PASSWORD`.** The passwords of the database. Use random values of letters and digits. -- **`INIT_SEAFILE_ADMIN_EMAIL` and `INIT_SEAFILE_ADMIN_PASSWORD`.** The administrator account that Seafile creates at the first start. The address does not need to exist, unless you configure email notifications later. +- **`INIT_SEAFILE_MYSQL_ROOT_PASSWORD` and `SEAFILE_MYSQL_DB_PASSWORD`.** The passwords of the database. Use random values of letters and digits. Compose stops with an error if either is empty. +- **`INIT_SEAFILE_ADMIN_EMAIL` and `INIT_SEAFILE_ADMIN_PASSWORD`.** The administrator account that Seafile creates at the first start. The password is empty, and Compose stops with an error until you set it. The address does not need to exist, unless you configure email notifications later. - **`JWT_PRIVATE_KEY`.** A random value. Generate one with `openssl rand -base64 40`. - **`SEAFILE_VOLUME` and `SEAFILE_MYSQL_VOLUME`.** The data folders. Change them to store the data elsewhere. @@ -56,6 +56,12 @@ If the command prints nothing, comment out `TS_ACCEPT_DNS` in `compose.yaml` and **The database passwords changed after the first start.** Later changes in `.env` do not reach the existing database, so Seafile can no longer log in, and `docker logs app-seafile-db` shows `Access denied for user`. Restore the original passwords. On a new installation without data, you can instead stop the stack, delete the folders from `SEAFILE_MYSQL_VOLUME` and `SEAFILE_VOLUME`, and start again. +## Upgrading + +Earlier versions of this stack had sample values for `INIT_SEAFILE_MYSQL_ROOT_PASSWORD`, `SEAFILE_MYSQL_DB_PASSWORD`, and `INIT_SEAFILE_ADMIN_PASSWORD` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `SEAFILE_MYSQL_DB_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD` again. The database still uses it. + +`INIT_SEAFILE_ADMIN_PASSWORD` only creates the administrator at the first start. A new value does not change an existing account. If you kept the sample value, change the password of the administrator in the web interface. + ## Links - [Seafile Docker setup](https://manual.seafile.com/latest/setup/setup_ce_by_docker/) diff --git a/services/seafile/compose.yaml b/services/seafile/compose.yaml index 508dcfd2..03b72b9b 100644 --- a/services/seafile/compose.yaml +++ b/services/seafile/compose.yaml @@ -54,7 +54,7 @@ services: container_name: app-${SERVICE}-db restart: always environment: - - MYSQL_ROOT_PASSWORD=${INIT_SEAFILE_MYSQL_ROOT_PASSWORD:-} + - MYSQL_ROOT_PASSWORD=${INIT_SEAFILE_MYSQL_ROOT_PASSWORD:?Set INIT_SEAFILE_MYSQL_ROOT_PASSWORD in .env} - MYSQL_LOG_CONSOLE=true - MARIADB_AUTO_UPGRADE=1 volumes: @@ -97,13 +97,13 @@ services: - SEAFILE_MYSQL_DB_PORT=${SEAFILE_MYSQL_DB_PORT:-3306} - SEAFILE_MYSQL_DB_USER=${SEAFILE_MYSQL_DB_USER:-seafile} - SEAFILE_MYSQL_DB_PASSWORD=${SEAFILE_MYSQL_DB_PASSWORD:?Variable is not set or empty} - - INIT_SEAFILE_MYSQL_ROOT_PASSWORD=${INIT_SEAFILE_MYSQL_ROOT_PASSWORD:-} + - INIT_SEAFILE_MYSQL_ROOT_PASSWORD=${INIT_SEAFILE_MYSQL_ROOT_PASSWORD:?Set INIT_SEAFILE_MYSQL_ROOT_PASSWORD in .env} - SEAFILE_MYSQL_DB_CCNET_DB_NAME=${SEAFILE_MYSQL_DB_CCNET_DB_NAME:-ccnet_db} - SEAFILE_MYSQL_DB_SEAFILE_DB_NAME=${SEAFILE_MYSQL_DB_SEAFILE_DB_NAME:-seafile_db} - SEAFILE_MYSQL_DB_SEAHUB_DB_NAME=${SEAFILE_MYSQL_DB_SEAHUB_DB_NAME:-seahub_db} - TIME_ZONE=${TIME_ZONE:-Etc/UTC} - INIT_SEAFILE_ADMIN_EMAIL=${INIT_SEAFILE_ADMIN_EMAIL:-me@example.com} - - INIT_SEAFILE_ADMIN_PASSWORD=${INIT_SEAFILE_ADMIN_PASSWORD:-asecret} + - INIT_SEAFILE_ADMIN_PASSWORD=${INIT_SEAFILE_ADMIN_PASSWORD:?Set INIT_SEAFILE_ADMIN_PASSWORD in .env} - SEAFILE_SERVER_HOSTNAME=${SEAFILE_SERVER_HOSTNAME:?Variable is not set or empty} - SEAFILE_SERVER_PROTOCOL=${SEAFILE_SERVER_PROTOCOL:-https} - SITE_ROOT=${SITE_ROOT:-/} diff --git a/services/sure/.env b/services/sure/.env index 6750b9f8..8554ba3e 100755 --- a/services/sure/.env +++ b/services/sure/.env @@ -24,7 +24,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Database (PostgreSQL) POSTGRES_USER=sure_user -POSTGRES_PASSWORD=sure_password +# Required: password of the database. +POSTGRES_PASSWORD= POSTGRES_DB=sure_production DB_HOST=172.28.0.10 # Static IP of db on sure_net (web/worker share tailscale namespace where Docker DNS is overridden by MagicDNS) DB_PORT=5432 @@ -34,7 +35,7 @@ POSTGRES_HOST=db # Used by the backup service (on sure_net, Docker DNS works) REDIS_URL=redis://172.28.0.11:6379/1 # Static IP of redis on sure_net (web/worker share tailscale namespace where Docker DNS is overridden by MagicDNS) # Sure Application -#openssl rand -hex 64 +# Required: signs the sessions. Generate it with: openssl rand -hex 64 SECRET_KEY_BASE= SELF_HOSTED=true RAILS_FORCE_SSL=true diff --git a/services/sure/README.md b/services/sure/README.md index 358b4294..bd14191d 100644 --- a/services/sure/README.md +++ b/services/sure/README.md @@ -29,8 +29,8 @@ This stack runs Sure with a Tailscale sidecar, as described in [the standard set 2. Set these values in `.env`: - - **`SECRET_KEY_BASE`.** Required and empty by default. Generate a value with `openssl rand -hex 64`. - - **`POSTGRES_USER`, `POSTGRES_PASSWORD`, and `POSTGRES_DB`.** The defaults `sure_user`, `sure_password`, and `sure_production` are samples. Change them before you use Sure with real data. + - **`SECRET_KEY_BASE`.** Required and empty by default. Generate a value with `openssl rand -hex 64`. Compose stops with an error until you set it. + - **`POSTGRES_USER`, `POSTGRES_PASSWORD`, and `POSTGRES_DB`.** The defaults for the user and the database are `sure_user` and `sure_production`. `POSTGRES_PASSWORD` is empty, and Compose stops with an error until you set it. - **`DB_HOST`, `REDIS_URL`, and `POSTGRES_HOST`.** Leave these as they are, unless you change the IP addresses of the network that the deviations describe. ## Deviations from the standard setup @@ -79,6 +79,10 @@ If a sync fails with `Failed to open TCP connection to fc.yahoo.com`, DNS probab If you open Sure over plain HTTP and get redirect errors, set `RAILS_FORCE_SSL` and `RAILS_ASSUME_SSL` in `.env` to `false`. +## Upgrading + +Earlier versions of this stack had a sample value for `POSTGRES_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=sure_password` again. The database still uses it. + ## Links - [Sure Docker guide](https://github.com/we-promise/sure/blob/main/docs/hosting/docker.md) diff --git a/services/sure/compose.yaml b/services/sure/compose.yaml index 245740c0..cfbbf5ff 100755 --- a/services/sure/compose.yaml +++ b/services/sure/compose.yaml @@ -60,9 +60,9 @@ services: restart: always environment: - POSTGRES_USER=${POSTGRES_USER:-sure_user} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-sure_password} + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} - POSTGRES_DB=${POSTGRES_DB:-sure_production} - - SECRET_KEY_BASE=${SECRET_KEY_BASE} + - SECRET_KEY_BASE=${SECRET_KEY_BASE:?Set SECRET_KEY_BASE in .env} - SELF_HOSTED=${SELF_HOSTED:-true} - RAILS_FORCE_SSL=${RAILS_FORCE_SSL:-false} - RAILS_ASSUME_SSL=${RAILS_ASSUME_SSL:-false} @@ -107,9 +107,9 @@ services: condition: service_healthy environment: - POSTGRES_USER=${POSTGRES_USER:-sure_user} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-sure_password} + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} - POSTGRES_DB=${POSTGRES_DB:-sure_production} - - SECRET_KEY_BASE=${SECRET_KEY_BASE} + - SECRET_KEY_BASE=${SECRET_KEY_BASE:?Set SECRET_KEY_BASE in .env} - SELF_HOSTED=${SELF_HOSTED:-true} - RAILS_FORCE_SSL=${RAILS_FORCE_SSL:-false} - RAILS_ASSUME_SSL=${RAILS_ASSUME_SSL:-false} @@ -127,7 +127,7 @@ services: - ./postgres-data:/var/lib/postgresql/data environment: - POSTGRES_USER=${POSTGRES_USER:-sure_user} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-sure_password} + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} - POSTGRES_DB=${POSTGRES_DB:-sure_production} healthcheck: test: [ "CMD-SHELL", "pg_isready -h 127.0.0.1 -U $$POSTGRES_USER -d $$POSTGRES_DB" ] # Check if PostgreSQL accepts connections @@ -152,7 +152,7 @@ services: - POSTGRES_HOST=${POSTGRES_HOST:-db} - POSTGRES_DB=${POSTGRES_DB:-sure_production} - POSTGRES_USER=${POSTGRES_USER:-sure_user} - - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:-sure_password} # pipelock:ignore + - POSTGRES_PASSWORD=${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} # pipelock:ignore - SCHEDULE=${SCHEDULE:-@daily} - BACKUP_KEEP_DAYS=${BACKUP_KEEP_DAYS:-7} - BACKUP_KEEP_WEEKS=${BACKUP_KEEP_WEEKS:-4} diff --git a/services/tandoor/.env b/services/tandoor/.env index 0abb304c..9d8da1ec 100644 --- a/services/tandoor/.env +++ b/services/tandoor/.env @@ -19,9 +19,9 @@ TS_AUTHKEY= TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_time_zones # Tandoor Configuration -# Generate with: base64 /dev/urandom | head -c50 # Do not commit a real production secret to Git. -SECRET_KEY=REPLACE_WITH_RANDOM_SECRET +# Required: signs the sessions. Generate it with: openssl rand -hex 32 +SECRET_KEY= # Allowed hosts should match your Tailscale Serve hostname. ALLOWED_HOSTS=tandoor.example.ts.net @@ -31,7 +31,8 @@ DB_ENGINE=django.db.backends.postgresql POSTGRES_HOST=127.0.0.1 POSTGRES_PORT=5432 POSTGRES_USER=postgres -POSTGRES_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD +# Required: password of the database. +POSTGRES_PASSWORD= POSTGRES_DB=tandoor # Optional Service variables diff --git a/services/tandoor/README.md b/services/tandoor/README.md index 98da2d31..e92a2368 100644 --- a/services/tandoor/README.md +++ b/services/tandoor/README.md @@ -20,8 +20,8 @@ This stack runs Tandoor Recipes with a Tailscale sidecar, as described in [the s Set these values in `.env`: -- **`SECRET_KEY`.** A long random value. Generate one with `base64 /dev/urandom | head -c50`. -- **`POSTGRES_PASSWORD`.** A random password of letters and digits. +- **`SECRET_KEY`.** A long random value. Generate one with `openssl rand -hex 32`. Compose stops with an error if it is empty. +- **`POSTGRES_PASSWORD`.** A random password of letters and digits. Compose stops with an error if it is empty. - **`ALLOWED_HOSTS`.** The name of the device on your Tailnet, `tandoor..ts.net`. Tandoor answers requests for other host names with error `400`. ## Deviations from the standard setup @@ -34,6 +34,10 @@ Set these values in `.env`: The first start can take a few minutes, because Tandoor prepares its database. Then open the web interface. Tandoor sends you to the setup page, where you create the first account. +## Upgrading + +Earlier versions of this stack had sample values for `SECRET_KEY` and `POSTGRES_PASSWORD` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample value, set `POSTGRES_PASSWORD=REPLACE_WITH_RANDOM_ALPHANUMERIC_PASSWORD` again. The database still uses it. + ## Links - [Tandoor Recipes documentation](https://docs.tandoor.dev/) diff --git a/services/tandoor/compose.yaml b/services/tandoor/compose.yaml index 6426d841..f6f37417 100644 --- a/services/tandoor/compose.yaml +++ b/services/tandoor/compose.yaml @@ -55,6 +55,7 @@ services: environment: - TZ=${TZ} - TANDOOR_PORT=${SERVICEPORT} + - SECRET_KEY=${SECRET_KEY:?Set SECRET_KEY in .env} volumes: - ./${SERVICE}-data/staticfiles:/opt/recipes/staticfiles - ./${SERVICE}-data/mediafiles:/opt/recipes/mediafiles @@ -78,7 +79,7 @@ services: network_mode: service:tailscale container_name: app-${SERVICE}-database environment: - POSTGRES_PASSWORD: ${POSTGRES_PASSWORD} + POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:?Set POSTGRES_PASSWORD in .env} POSTGRES_USER: ${POSTGRES_USER} POSTGRES_DB: ${POSTGRES_DB} volumes: diff --git a/services/technitium/.env b/services/technitium/.env index cdfb6fcb..0f1cb843 100644 --- a/services/technitium/.env +++ b/services/technitium/.env @@ -21,6 +21,7 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim DNS_SERVER1=9.9.9.9 DNS_SERVER2=8.8.4.4 -ADMIN_PASSWORD=ChangeME +# Required: password of the admin user of the web console. +ADMIN_PASSWORD= #EXAMPLE_VAR="Environment variable" diff --git a/services/technitium/README.md b/services/technitium/README.md index 70b818e7..773ac914 100644 --- a/services/technitium/README.md +++ b/services/technitium/README.md @@ -16,13 +16,13 @@ This stack runs Technitium DNS Server with a Tailscale sidecar, as described in ## Before you start -- **Set the administrator password.** Change `ADMIN_PASSWORD` in `.env`. The default is `ChangeME`. Technitium reads it only at the first start. +- **Set the administrator password.** Set `ADMIN_PASSWORD` in `.env`. It is empty, and Compose stops with an error until you set it. Technitium reads it only at the first start. - **Free port 53.** The stack publishes port `53` on the Docker host. On a host that runs `systemd-resolved`, this port is in use. See [Free up port 53 on the Docker host](../../documentation/free-up-port-53.md). - **Choose the forwarders.** `DNS_SERVER1` and `DNS_SERVER2` in `.env` set the DNS servers that Technitium forwards to. ## Deviations from the standard setup -- **Published host ports.** The `ports` block is active. It publishes the web interface on port `5380`, DNS on port `53`, DNS-over-TLS and DNS-over-QUIC on port `853`, and DNS-over-HTTPS on port `443` of the Docker host. Devices in your local network can therefore reach Technitium without Tailscale. Remove the lines that you do not need. +- **Published host ports.** The `ports` block is active. It publishes the web interface on port `5380`, DNS on port `53`, DNS-over-TLS and DNS-over-QUIC on port `853`, and DNS-over-HTTPS on port `443` of the Docker host. Devices in your local network can therefore reach Technitium without Tailscale. The web interface on port `5380` uses plain HTTP, so anyone on your local network can reach its login page and the password travels unencrypted. If you only use the web interface through Tailscale, remove the `5380:5380/tcp` line from `compose.yaml`. Remove the other lines that you do not need. - **Settings through environment variables.** `compose.yaml` sets the server name, recursion, and forwarders. Technitium reads these variables only at the first start, when it has no configuration yet. ## First run @@ -60,6 +60,8 @@ If you run an earlier version, copy your settings to the host before you start t docker compose up -d ``` +Earlier versions of this stack had a sample value for `ADMIN_PASSWORD` in `.env`. It is now empty, and Compose stops with an error until you set it. If you already run the stack, keep the values that you use now. Technitium reads `ADMIN_PASSWORD` only at the first start, so a new value does not change an existing account. If you still log in with the password `ChangeME`, change the password in the web interface. + ## Links - [Technitium DNS Server help](https://technitium.com/dns/help.html) diff --git a/services/technitium/compose.yaml b/services/technitium/compose.yaml index 8ba3799a..205d634d 100644 --- a/services/technitium/compose.yaml +++ b/services/technitium/compose.yaml @@ -61,7 +61,7 @@ services: container_name: app-${SERVICE} # Name for local container management environment: - DNS_SERVER_DOMAIN=${SERVICE}.local #The primary domain name used by this DNS Server to identify itself. - - DNS_SERVER_ADMIN_PASSWORD=${ADMIN_PASSWORD} #DNS web console admin user password. + - DNS_SERVER_ADMIN_PASSWORD=${ADMIN_PASSWORD:?Set ADMIN_PASSWORD in .env} #DNS web console admin user password. # - DNS_SERVER_ADMIN_PASSWORD_FILE=password.txt #The path to a file that contains a plain text password for the DNS web console admin user. - DNS_SERVER_PREFER_IPV6=false #DNS Server will use IPv6 for querying whenever possible with this option enabled. # - DNS_SERVER_WEB_SERVICE_LOCAL_ADDRESSES=172.17.0.1,127.0.0.1 #Comma separated list of network interface IP addresses that you want the web service to listen on for requests. The "172.17.0.1" address is the built-in Docker bridge. The "[::]" is the default value if not specified. Note! This must be used only with "host" network mode. diff --git a/services/uptime-kuma/README.md b/services/uptime-kuma/README.md index 3c788eb4..2595b44a 100644 --- a/services/uptime-kuma/README.md +++ b/services/uptime-kuma/README.md @@ -19,7 +19,7 @@ Nothing beyond the [Quick Start](../../README.md#quick-start). ## Deviations from the standard setup -- **Docker socket.** Uptime Kuma mounts `/var/run/docker.sock` read-only, so that it can monitor the containers on the Docker host. Remove the line if you do not use this monitor type. +- **Docker socket.** Uptime Kuma mounts `/var/run/docker.sock` read-only, so that it can monitor the containers on the Docker host. Remove the line if you do not use this monitor type. The `:ro` flag only makes the socket file read-only. It does not limit what the service can do through the Docker API, so treat access to the socket as root access to the Docker host. ## First run diff --git a/services/uptime-kuma/compose.yaml b/services/uptime-kuma/compose.yaml index 072ebde1..b27eae18 100644 --- a/services/uptime-kuma/compose.yaml +++ b/services/uptime-kuma/compose.yaml @@ -56,7 +56,7 @@ services: - TZ=${TZ} volumes: - ./${SERVICE}-data/uptime-kuma-data:/app/data # uptime-kuma data/configuration folder - - /var/run/docker.sock:/var/run/docker.sock:ro # Read-only access to the docker.sock + - /var/run/docker.sock:/var/run/docker.sock:ro # The :ro flag does not limit Docker API access: the service can control Docker on the host depends_on: tailscale: condition: service_healthy diff --git a/services/xwiki/.env b/services/xwiki/.env index 5f752538..9007f329 100644 --- a/services/xwiki/.env +++ b/services/xwiki/.env @@ -26,6 +26,8 @@ TZ=Europe/Amsterdam # See: https://en.wikipedia.org/wiki/List_of_tz_database_tim # Default environment values XWIKI_VERSION=18.2.1 DB_USER=xwiki -DB_PASSWORD=xwiki +# Required: password of the database user. +DB_PASSWORD= DB_DATABASE=xwiki -MARIADB_ROOT_PASSWORD=xwiki +# Required: root password of the database. +MARIADB_ROOT_PASSWORD= diff --git a/services/xwiki/README.md b/services/xwiki/README.md index b9112e18..79836419 100644 --- a/services/xwiki/README.md +++ b/services/xwiki/README.md @@ -17,7 +17,7 @@ This stack runs XWiki with a Tailscale sidecar, as described in [the standard se ## Before you start -Change `DB_PASSWORD` and `MARIADB_ROOT_PASSWORD` in `.env` before the first start. The default for both is `xwiki`. +Set `DB_PASSWORD` and `MARIADB_ROOT_PASSWORD` in `.env` before the first start. Both are empty, and Compose stops with an error until you set them. Use random values of letters and digits. ## Deviations from the standard setup @@ -29,6 +29,10 @@ Change `DB_PASSWORD` and `MARIADB_ROOT_PASSWORD` in `.env` before the first star Open the web interface. The first start takes a few minutes. XWiki then shows its distribution wizard, where you create the administrator account and install the standard flavor. +## Upgrading + +Earlier versions of this stack had sample values for `DB_PASSWORD` and `MARIADB_ROOT_PASSWORD` in `.env`. They are now empty, and Compose stops with an error until you set them. If you already run the stack, keep the values that you use now. This is required for the database password, because the database applies it only at the first start. If you kept the sample values, set `DB_PASSWORD` and `MARIADB_ROOT_PASSWORD` to `xwiki` again. The database still uses them. + ## Links - [XWiki documentation](https://www.xwiki.org/xwiki/bin/view/Documentation/) diff --git a/services/xwiki/compose.yaml b/services/xwiki/compose.yaml index 7948f8a2..39635ffa 100644 --- a/services/xwiki/compose.yaml +++ b/services/xwiki/compose.yaml @@ -60,7 +60,7 @@ services: environment: # Variables are declared in .env file. - XWIKI_VERSION=${XWIKI_VERSION} - DB_USER=${DB_USER} - - DB_PASSWORD=${DB_PASSWORD} + - DB_PASSWORD=${DB_PASSWORD:?Set DB_PASSWORD in .env} - DB_DATABASE=${DB_DATABASE} - DB_HOST=db-${SERVICE} - TZ=${TZ} @@ -82,9 +82,9 @@ services: source: ./init.sql target: /docker-entrypoint-initdb.d/init.sql environment: - - MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD} + - MARIADB_ROOT_PASSWORD=${MARIADB_ROOT_PASSWORD:?Set MARIADB_ROOT_PASSWORD in .env} - MARIADB_USER=${DB_USER} - - MARIADB_PASSWORD=${DB_PASSWORD} + - MARIADB_PASSWORD=${DB_PASSWORD:?Set DB_PASSWORD in .env} - MARIADB_DATABASE=${DB_DATABASE} command: - "--character-set-server=utf8mb4"