-
Notifications
You must be signed in to change notification settings - Fork 9
Expand file tree
/
Copy pathenv.example
More file actions
94 lines (77 loc) 路 4.29 KB
/
Copy pathenv.example
File metadata and controls
94 lines (77 loc) 路 4.29 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
# LogDeck Environment Configuration
#
# Everything here can also be set in the Settings UI, which persists to
# /data/config.json. An environment variable always wins: a value set here
# shows up in the UI as "Set via environment variable" and cannot be edited
# there.
# =============================================================================
# Authentication (set all three to require a login; omit them to run open)
# =============================================================================
# JWT Secret Key - Use a strong, random string (minimum 32 characters)
# Generate one with: openssl rand -base64 32
JWT_SECRET=your-super-secret-key-change-this-to-something-random-min-32-chars
# Admin User Credentials
ADMIN_USERNAME=admin
# Admin Password - MUST be a bcrypt hash (plain text is not supported)
# Generate hash with: htpasswd -bnBC 10 '' yourPassword | tr -d ':'
# (htpasswd ships with apache2-utils on Debian/Ubuntu, httpd-tools on RHEL,
# and is preinstalled on macOS)
# Example output: $2a$10$N9qo8uLOickgx2ZMRZoMyeIjZAgcfl7p92ldGxad68LJZdL17lhWy
ADMIN_PASSWORD=$2a$10$YourBcryptHashHere
# Legacy alternative to bcrypt: SHA256(password + salt). Only set this if you
# are already using it; new installs should use the bcrypt hash above.
# ADMIN_PASSWORD_SALT=
# =============================================================================
# Docker / Podman hosts (optional)
# =============================================================================
# Hosts to connect to, comma-separated as name=address. When unset, LogDeck
# auto-detects the local Docker or Podman socket.
#
# Podman works through its Docker-compatible API socket (see podman.md):
# Rootless: unix:///run/user/1000/podman/podman.sock
# Rootful: unix:///run/podman/podman.sock
# Remote hosts over SSH are supported: prod=ssh://user@example.com
#
# DOCKER_HOSTS=local=unix:///var/run/docker.sock,prod=ssh://user@example.com
#
# Note: DOCKER_HOST (singular) is not a LogDeck setting. Use DOCKER_HOSTS.
# =============================================================================
# Storage (optional)
# =============================================================================
# Path to the config file. Its directory also holds the log database (logs.db)
# and the alert history, so it must live on a persistent volume.
# Default: /data/config.json
# CONFIG_PATH=/data/config.json
# Log persistence keeps container logs readable after a container is removed or
# rebuilt. Enabled by default; the caps are also editable in Settings.
# LOG_STORE_ENABLED=true
# LOG_STORE_PER_CONTAINER_MB=50
# LOG_STORE_TOTAL_MB=1024
# =============================================================================
# Server (optional)
# =============================================================================
# Block every mutating action: start, stop, restart, remove, env and resource
# edits, compose actions, the web terminal, and deleting stored logs.
# READONLY_MODE=true
# Allowed CORS origins (comma-separated). Only needed when the frontend is
# served from a different origin than the backend (e.g. a dev server).
# Default: http://localhost:5173,http://127.0.0.1:5173
# CORS_ALLOWED_ORIGINS=http://localhost:5173,http://127.0.0.1:5173
# Trust X-Forwarded-For / X-Real-IP headers for client IP detection (used by
# login rate limiting). Enable ONLY when LogDeck runs behind a reverse proxy
# (Coolify, Traefik, nginx, ...); on a directly exposed server clients could
# spoof these headers to bypass the rate limit.
# TRUST_PROXY_HEADERS=true
# =============================================================================
# Coolify Integration (Optional)
# =============================================================================
# Enable this to persist env var changes across Coolify redeployments.
# Format: hostName|apiURL|apiToken,hostName|apiURL|apiToken,...
# Host names must match names defined in DOCKER_HOSTS.
# COOLIFY_CONFIGS=local|https://your-coolify-instance.com|your-api-token
# Go runtime profiles (heap, goroutines) for debugging memory or CPU use.
# Off unless set. Unauthenticated, so only a loopback address is accepted.
# Inside Docker, reach it from the container's network namespace:
# docker run --rm --network container:<name> curlimages/curl -s \
# http://127.0.0.1:6060/debug/pprof/heap > heap.pprof
# PPROF_ADDR=127.0.0.1:6060