Files
rustpad/.env.example

136 lines
3.9 KiB
Bash

# Application
APP_HOST=0.0.0.0
APP_PORT=3000
# Port exposed by Docker Compose
RUSTPAD_PORT=8200
# Database
# SQLite — default
DATABASE_URL=sqlite:///data/db/rustpad.db?mode=rwc
# PostgreSQL
# DATABASE_URL=postgres://rustpad:rustpad@postgres:5432/rustpad
# MySQL
# DATABASE_URL=mysql://rustpad:rustpad@mysql:3306/rustpad
DATABASE_MAX_CONNECTIONS=8
# Session lifetime in days
# Anonymous pad/workspace access tokens
ANONYMOUS_ACCESS_TOKEN_TTL_DAYS=3
# Logged-in user sessions
USER_SESSION_TTL_DAYS=3
UNCONFIRMED_ACCOUNT_TTL_DAYS=3
# Logging
# available: warn, debug, info
FRONTEND_DEBUG=false
RUST_LOG=rustpad=info,tower_http=warn
# Maximum upload size
UPLOAD_MAX_SIZE_MB=20
GUEST_UPLOAD_ENABLED=false
GUEST_UPLOAD_MAX_SIZE_MB=5
# Attachment storage: local or s3
STORAGE_DRIVER=local
FILES_DIR=/data/files
# Optional attachment origin. A bare domain is normalized to HTTPS.
# The administrator must proxy or serve /f/* on this domain.
# FILES_PUBLIC_URL=files.note.example.com
# S3-compatible storage (AWS S3, Garage, Ceph, OpenStack, MinIO, R2...)
# For Docker Garage run: docker compose --profile s3 up -d
# STORAGE_DRIVER=s3
# S3_ENDPOINT=http://garage:3900
# S3_REGION=garage
# S3_BUCKET=attachments
# S3_ACCESS_KEY=GK0123456789abcdef0123456789abcdef
# S3_SECRET_KEY=0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef
# S3_FORCE_PATH_STYLE=true
# GARAGE_S3_PORT=3900
# GARAGE_ADMIN_PORT=3903
# Browser cache lifetime in seconds
ASSET_CACHE_MAX_AGE_SECONDS=600
FILE_CACHE_MAX_AGE_SECONDS=300
# Optional PostgreSQL container configuration
POSTGRES_DB=rustpad
POSTGRES_USER=rustpad
POSTGRES_PASSWORD=rustpad
# Optional MySQL container configuration
MYSQL_DATABASE=rustpad
MYSQL_USER=rustpad
MYSQL_PASSWORD=rustpad
MYSQL_ROOT_PASSWORD=rustpad_root
# Optional settings
REGISTRATION_ENABLED=false
ACCOUNT_CONFIRMATION_REQUIRED=false
SHARE_CONFIRMATION_REQUIRED=true
# smtp mailing
# port 465 → tls
# port 587 → starttls
# SMTP_SECURITY not req.
PUBLIC_URL=https://pad.example.com
# SMTP_HOST=smtp.example.com
#SMTP_SECURITY=none
SMTP_SECURITY=starttls
#SMTP_SECURITY=tls
SMTP_PORT=587
SMTP_USERNAME=
SMTP_PASSWORD=
SMTP_FROM="RustPad <no-reply@example.com>"
# Authentication mode: local, ldap, or ad
# local: built-in registration/login
# ldap/ad: organization directory login; local registration and guest access are disabled
AUTHORIZATION_TYPE=local
# Shared LDAP / Active Directory connection settings
# LDAP_URL=ldap://10.0.0.22:389
# LDAP_STARTTLS=false
# Verify the LDAP server certificate for LDAPS/StartTLS.
# Set false only for trusted internal/test servers with a self-signed certificate.
# This allows encrypted TLS without mounting a custom CA certificate.
LDAP_TLS_VERIFY=true
# Connection and LDAP operation timeouts.
LDAP_CONNECT_TIMEOUT_SECONDS=5
LDAP_OPERATION_TIMEOUT_SECONDS=10
# For LDAPS: LDAP_URL=ldaps://ldap.example.org:636 and LDAP_STARTTLS=false
# For StartTLS: LDAP_URL=ldap://ldap.example.org:389 and LDAP_STARTTLS=true
# LDAP_BIND_DN=cn=admin,dc=example,dc=org
# LDAP_BIND_PASSWORD=admin
# LDAP_BASE_DN=ou=people,dc=example,dc=org
# LDAP_ORGANIZATION=example
# LDAP_EMAIL_ATTRIBUTE=mail
# LDAP_DISPLAY_NAME_ATTRIBUTE=displayName
# Stable directory identifier. Defaults:
# ldap: entryUUID
# ad: objectGUID
# LDAP_EXTERNAL_ID_ATTRIBUTE=entryUUID
# Reject directory users without a valid mail attribute.
LDAP_EMAIL_REQUIRED=true
# Link an existing account with the same e-mail on first directory login.
# Keep false unless you intentionally migrate existing local/legacy LDAP accounts.
LDAP_LINK_EXISTING_BY_EMAIL=false
# Optional overrides. Defaults depend on AUTHORIZATION_TYPE:
# ldap: LDAP_USER_FILTER=(uid={username}), LDAP_USERNAME_ATTRIBUTE=uid
# ad: LDAP_USER_FILTER=(|(sAMAccountName={username})(userPrincipalName={username}))
# LDAP_USERNAME_ATTRIBUTE=sAMAccountName
# LDAP_USER_FILTER=(uid={username})
# LDAP_USERNAME_ATTRIBUTE=uid
# To allow login by either username or e-mail:
# LDAP_USER_FILTER=(|(uid={username})(mail={username}))