Files
apcupsd-client/.env.example
T

52 lines
2.0 KiB
Bash

# APC UPS Dashboard environment template
# Copy to `.env` and fill in values. Never commit real .env files.
# --- Required in production ---
# Random 32+ byte string. Generate with:
# python -c "import secrets; print(secrets.token_urlsafe(48))"
SESSION_SECRET=change-me-to-a-random-string
# Admin password hash (argon2). Generate with:
# python -c "from passlib.hash import argon2; print(argon2.hash('mysecret'))"
# If unset and no admin stored in Redis, the app shows a first-run setup page
# (recommended — the wizard stores the hash in Redis and avoids the $-escaping trap below).
ADMIN_USERNAME=admin
# ADMIN_PASSWORD_HASH=
#
# IMPORTANT: argon2 hashes start with `$argon2id$v=19$m=...` and contain many `$`
# characters. Docker Compose interprets `$word` as variable substitution, so pasting
# a raw hash here will produce warnings like
# WARN The "argon2id" variable is not set. Defaulting to a blank string.
# and the container will receive a mangled hash (and you will not be able to log in).
# Quoting (single or double) does NOT escape `$` in .env — you must double every `$`:
# ADMIN_PASSWORD_HASH=$$argon2id$$v=19$$m=65536,t=3,p=4$$<salt>$$<hash>
# Or just leave this unset and use the /setup wizard on first boot.
# --- Redis ---
REDIS_URL=redis://redis:6379/0
# REDIS_PASSWORD= # only used if you enable --requirepass in docker-compose
# --- SMTP (optional; configure via Settings UI for host/port/etc) ---
# SMTP password is read from env only; never stored in Redis.
# SMTP_PASSWORD=
# --- Networking / validation ---
# Set false to block all RFC1918 IPs in UPS host field (default true for homelab).
ALLOW_PRIVATE_IPS=true
# Set true when behind an HTTPS reverse proxy (enables Secure cookie + HSTS).
TRUST_PROXY=false
# --- Observability ---
LOG_LEVEL=INFO
# Session expiry (seconds). Default 14 days.
SESSION_MAX_AGE_SECONDS=1209600
# --- Locale ---
TZ=UTC
# --- Rate limiting (set false in tests) ---
RATE_LIMIT_ENABLED=true
# --- Legacy YAML migration (unused unless you bind-mount /config) ---
# UPS_CONFIG_PATH=/config/ups.yaml