136 lines
3.9 KiB
Bash
136 lines
3.9 KiB
Bash
# Application
|
|
APP_HOST=0.0.0.0
|
|
APP_PORT=3000
|
|
|
|
# Port exposed by Docker Compose
|
|
RUSTPAD_PORT=8200
|
|
|
|
# Database
|
|
|
|
# SQLite — default
|
|
DATABASE_URL=sqlite:///data/db/rustpad.db?mode=rwc
|
|
|
|
# PostgreSQL
|
|
# DATABASE_URL=postgres://rustpad:rustpad@postgres:5432/rustpad
|
|
|
|
# MySQL
|
|
# DATABASE_URL=mysql://rustpad:rustpad@mysql:3306/rustpad
|
|
|
|
DATABASE_MAX_CONNECTIONS=8
|
|
|
|
# Session lifetime in days
|
|
# Anonymous pad/workspace access tokens
|
|
ANONYMOUS_ACCESS_TOKEN_TTL_DAYS=3
|
|
# Logged-in user sessions
|
|
USER_SESSION_TTL_DAYS=3
|
|
UNCONFIRMED_ACCOUNT_TTL_DAYS=3
|
|
|
|
# Logging
|
|
# available: warn, debug, info
|
|
FRONTEND_DEBUG=false
|
|
RUST_LOG=rustpad=info,tower_http=warn
|
|
|
|
# Maximum upload size
|
|
UPLOAD_MAX_SIZE_MB=20
|
|
GUEST_UPLOAD_ENABLED=false
|
|
GUEST_UPLOAD_MAX_SIZE_MB=5
|
|
|
|
# Attachment storage: local or s3
|
|
STORAGE_DRIVER=local
|
|
FILES_DIR=/data/files
|
|
# Optional attachment origin. A bare domain is normalized to HTTPS.
|
|
# The administrator must proxy or serve /f/* on this domain.
|
|
# FILES_PUBLIC_URL=files.note.example.com
|
|
|
|
# S3-compatible storage (AWS S3, Garage, Ceph, OpenStack, MinIO, R2...)
|
|
# For Docker Garage run: docker compose --profile s3 up -d
|
|
# STORAGE_DRIVER=s3
|
|
# S3_ENDPOINT=http://garage:3900
|
|
# S3_REGION=garage
|
|
# S3_BUCKET=attachments
|
|
# S3_ACCESS_KEY=GK0123456789abcdef0123456789abcdef
|
|
# S3_SECRET_KEY=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
|
|
# S3_FORCE_PATH_STYLE=true
|
|
# GARAGE_S3_PORT=3900
|
|
# GARAGE_ADMIN_PORT=3903
|
|
|
|
# Browser cache lifetime in seconds
|
|
ASSET_CACHE_MAX_AGE_SECONDS=600
|
|
FILE_CACHE_MAX_AGE_SECONDS=300
|
|
|
|
# Optional PostgreSQL container configuration
|
|
POSTGRES_DB=rustpad
|
|
POSTGRES_USER=rustpad
|
|
POSTGRES_PASSWORD=rustpad
|
|
|
|
# Optional MySQL container configuration
|
|
MYSQL_DATABASE=rustpad
|
|
MYSQL_USER=rustpad
|
|
MYSQL_PASSWORD=rustpad
|
|
MYSQL_ROOT_PASSWORD=rustpad_root
|
|
|
|
# Optional settings
|
|
REGISTRATION_ENABLED=false
|
|
ACCOUNT_CONFIRMATION_REQUIRED=false
|
|
SHARE_CONFIRMATION_REQUIRED=true
|
|
|
|
# smtp mailing
|
|
# port 465 → tls
|
|
# port 587 → starttls
|
|
# SMTP_SECURITY not req.
|
|
PUBLIC_URL=https://pad.example.com
|
|
# SMTP_HOST=smtp.example.com
|
|
#SMTP_SECURITY=none
|
|
SMTP_SECURITY=starttls
|
|
#SMTP_SECURITY=tls
|
|
SMTP_PORT=587
|
|
SMTP_USERNAME=
|
|
SMTP_PASSWORD=
|
|
SMTP_FROM="RustPad <no-reply@example.com>"
|
|
|
|
# Authentication mode: local, ldap, or ad
|
|
# local: built-in registration/login
|
|
# ldap/ad: organization directory login; local registration and guest access are disabled
|
|
AUTHORIZATION_TYPE=local
|
|
|
|
# Shared LDAP / Active Directory connection settings
|
|
# LDAP_URL=ldap://10.0.0.22:389
|
|
# LDAP_STARTTLS=false
|
|
|
|
# Verify the LDAP server certificate for LDAPS/StartTLS.
|
|
# Set false only for trusted internal/test servers with a self-signed certificate.
|
|
# This allows encrypted TLS without mounting a custom CA certificate.
|
|
LDAP_TLS_VERIFY=true
|
|
|
|
# Connection and LDAP operation timeouts.
|
|
LDAP_CONNECT_TIMEOUT_SECONDS=5
|
|
LDAP_OPERATION_TIMEOUT_SECONDS=10
|
|
# For LDAPS: LDAP_URL=ldaps://ldap.example.org:636 and LDAP_STARTTLS=false
|
|
# For StartTLS: LDAP_URL=ldap://ldap.example.org:389 and LDAP_STARTTLS=true
|
|
# LDAP_BIND_DN=cn=admin,dc=example,dc=org
|
|
# LDAP_BIND_PASSWORD=admin
|
|
# LDAP_BASE_DN=ou=people,dc=example,dc=org
|
|
# LDAP_ORGANIZATION=example
|
|
# LDAP_EMAIL_ATTRIBUTE=mail
|
|
# LDAP_DISPLAY_NAME_ATTRIBUTE=displayName
|
|
|
|
# Stable directory identifier. Defaults:
|
|
# ldap: entryUUID
|
|
# ad: objectGUID
|
|
# LDAP_EXTERNAL_ID_ATTRIBUTE=entryUUID
|
|
|
|
# Reject directory users without a valid mail attribute.
|
|
LDAP_EMAIL_REQUIRED=true
|
|
|
|
# Link an existing account with the same e-mail on first directory login.
|
|
# Keep false unless you intentionally migrate existing local/legacy LDAP accounts.
|
|
LDAP_LINK_EXISTING_BY_EMAIL=false
|
|
|
|
# Optional overrides. Defaults depend on AUTHORIZATION_TYPE:
|
|
# ldap: LDAP_USER_FILTER=(uid={username}), LDAP_USERNAME_ATTRIBUTE=uid
|
|
# ad: LDAP_USER_FILTER=(|(sAMAccountName={username})(userPrincipalName={username}))
|
|
# LDAP_USERNAME_ATTRIBUTE=sAMAccountName
|
|
# LDAP_USER_FILTER=(uid={username})
|
|
# LDAP_USERNAME_ATTRIBUTE=uid
|
|
# To allow login by either username or e-mail:
|
|
# LDAP_USER_FILTER=(|(uid={username})(mail={username})) |