# APC UPS Dashboard environment template # Copy to `.env` and fill in values. Never commit real .env files. # --- Required in production --- # Random 32+ byte string. Generate with: # python -c "import secrets; print(secrets.token_urlsafe(48))" SESSION_SECRET=change-me-to-a-random-string # Admin password hash (argon2). Generate with: # python -c "from passlib.hash import argon2; print(argon2.hash('mysecret'))" # If unset and no admin stored in Redis, the app shows a first-run setup page # (recommended — the wizard stores the hash in Redis and avoids the $-escaping trap below). ADMIN_USERNAME=admin # ADMIN_PASSWORD_HASH= # # IMPORTANT: argon2 hashes start with `$argon2id$v=19$m=...` and contain many `$` # characters. Docker Compose interprets `$word` as variable substitution, so pasting # a raw hash here will produce warnings like # WARN The "argon2id" variable is not set. Defaulting to a blank string. # and the container will receive a mangled hash (and you will not be able to log in). # Quoting (single or double) does NOT escape `$` in .env — you must double every `$`: # ADMIN_PASSWORD_HASH=$$argon2id$$v=19$$m=65536,t=3,p=4$$$$ # Or just leave this unset and use the /setup wizard on first boot. # --- Redis --- REDIS_URL=redis://redis:6379/0 # REDIS_PASSWORD= # only used if you enable --requirepass in docker-compose # --- SMTP (optional; configure via Settings UI for host/port/etc) --- # SMTP password is read from env only; never stored in Redis. # SMTP_PASSWORD= # --- Networking / validation --- # Set false to block all RFC1918 IPs in UPS host field (default true for homelab). ALLOW_PRIVATE_IPS=true # Set true when behind an HTTPS reverse proxy (enables Secure cookie + HSTS). TRUST_PROXY=false # --- Observability --- LOG_LEVEL=INFO # Session expiry (seconds). Default 14 days. SESSION_MAX_AGE_SECONDS=1209600 # --- Locale --- TZ=UTC # --- Rate limiting (set false in tests) --- RATE_LIMIT_ENABLED=true # --- Legacy YAML migration (unused unless you bind-mount /config) --- # UPS_CONFIG_PATH=/config/ups.yaml