# ── famapp ──────────────────────────────────────────────────────────────────── # These vars are consumed by the famapp service in docker-compose.yml. # Image tag to deploy. Pin to a specific version after first deploy # (e.g. ghcr.io/ginnoir/famapp:v0.1.0). `latest` is fine for staging/initial. FAMAPP_IMAGE=ghcr.io/ginnoir/famapp:latest FAMAPP_PULL_POLICY=always AUTHENTIK_IMAGE_TAG=2024.12.3 RUN_MIGRATIONS=true # Public URL for the app AUTH_URL=https://fam.yourdomain.com # famapp Postgres FAMAPP_DB_USER=famapp FAMAPP_DB_PASSWORD=replace-with-strong-password FAMAPP_DB_NAME=famapp # Auth.js session secret — generate with: openssl rand -base64 32 # NOTE: Reactive Resume uses RESUME_AUTH_SECRET; AUTH_SECRET is famapp-only. AUTH_SECRET=replace-with-openssl-rand-base64-32 # OIDC provider (Authentik) — fill in after bootstrapping Authentik AUTH_OIDC_ISSUER=https://auth.yourdomain.com/application/o/famapp/ AUTH_OIDC_CLIENT_ID=replace-me AUTH_OIDC_CLIENT_SECRET=replace-me # Web Push VAPID keys — generate with: pnpm vapid:generate VAPID_PUBLIC_KEY= VAPID_PRIVATE_KEY= VAPID_SUBJECT=mailto:your-email@example.com # ntfy push fallback NTFY_URL=https://ntfy.yourdomain.com NTFY_TOPIC=famapp # Log level: error | warn | info | debug LOG_LEVEL=info # MinIO object storage (garden image uploads) famapp_MINIO_ROOT_USER=famapp famapp_MINIO_ROOT_PASSWORD=replace-with-strong-password famapp_MINIO_BUCKET=garden # OpenPlantBook API (optional — used for plant species lookup) famapp_OPENPLANTBOOK_CLIENT_ID= famapp_OPENPLANTBOOK_CLIENT_SECRET= # ── Authentik ───────────────────────────────────────────────────────────────── AUTHENTIK_DB_USER=authentik AUTHENTIK_DB_PASSWORD=replace-with-strong-password AUTHENTIK_DB_NAME=authentik AUTHENTIK_SECRET_KEY=replace-with-openssl-rand-base64-60 # ── Cloudflare (Caddy DNS-01 TLS) ───────────────────────────────────────────── CF_API_TOKEN=replace-with-cloudflare-api-token