-
-
Notifications
You must be signed in to change notification settings - Fork 774
Expand file tree
/
Copy path.env.docker.example
More file actions
199 lines (162 loc) · 6.99 KB
/
Copy path.env.docker.example
File metadata and controls
199 lines (162 loc) · 6.99 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
# ============================================================================
# Docker Environment Configuration (Example)
# ============================================================================
# Copy this file to .env.docker and replace with your actual values
#
# NOTE: Build-time placeholders are set in each service's dofigen.yml file.
# Values in this file override those placeholders at runtime via docker compose.
# Required values are marked with [REQUIRED]
# DATABASE
# ============================================================================
# LibSQL database connection - points to the libsql container
DATABASE_URL=http://libsql:8080
DATABASE_AUTH_TOKEN=
# REDIS & QUEUE
# ============================================================================
# Redis (optional) - for caching
UPSTASH_REDIS_REST_URL=http://localhost:6379
UPSTASH_REDIS_REST_TOKEN=placeholder
# QStash (optional - for background jobs)
QSTASH_CURRENT_SIGNING_KEY=
QSTASH_NEXT_SIGNING_KEY=
QSTASH_TOKEN=
QSTASH_URL=https://qstash.upstash.io/v1/publish/
# ANALYTICS
# ============================================================================
# Tinybird (optional - for monitor analytics and charts)
# Leave empty to disable analytics features
# Get from: https://www.tinybird.co
# Self-hosted with the local container: tb --local info (use the `token` value;
# NOT curl :7181/tokens, which returns a different workspace)
TINY_BIRD_API_KEY=
# Same token as TINY_BIRD_API_KEY, read by the private-location ingest server (Go).
# Both must be set: the ingest server never reads TINY_BIRD_API_KEY, so leaving
# this empty makes Tinybird reject every check with a 403.
TINYBIRD_TOKEN=
# Tinybird URL (optional - defaults to cloud API)
# For local Tinybird container, set to: http://tinybird-local:7181
TINYBIRD_URL=
# Set to "true" to resolve every Tinybird pipe and ingest to empty instead of
# calling the instance above (optional - defaults to off).
TINYBIRD_NOOP=
# EMAIL
# ============================================================================
# [REQUIRED] Resend API key for sending magic link emails
# Get from: https://resend.com
RESEND_API_KEY=re_your_resend_api_key_here
# AUTHENTICATION
# ============================================================================
# [REQUIRED] NextAuth secret - generate with: openssl rand -base64 32
AUTH_SECRET=your-random-secret-here-min-32-chars
# [REQUIRED] Self-hosted mode - enables magic link authentication
# Set to "true" to allow email login without OAuth
# Note: NEXT_PUBLIC_SELF_HOST is the client-side build-time version of this flag,
# baked into the Docker image at build time (see apps/dashboard/Dockerfile).
# It controls UI behavior like the Telegram connection flow (QR vs manual input),
# and cannot be changed via this runtime config file.
SELF_HOST="true"
# GitHub OAuth (optional)
# Get from: https://github.com/settings/developers
AUTH_GITHUB_ID=
AUTH_GITHUB_SECRET=
# Google OAuth (optional)
# Get from: https://console.cloud.google.com
AUTH_GOOGLE_ID=
AUTH_GOOGLE_SECRET=
# Generic OIDC SSO (optional) - works with any OIDC provider (Okta, Auth0, Entra ID, Keycloak, ...)
# Setting ISSUER enables the SSO login button; NAME customizes the button label (default: "SSO")
AUTH_OIDC_ISSUER=
AUTH_OIDC_ID=
AUTH_OIDC_SECRET=
AUTH_OIDC_NAME=
# GOOGLE CLOUD
# ============================================================================
# Google Cloud Platform (optional - for scheduled tasks)
GCP_PROJECT_ID=
GCP_LOCATION=
GCP_CLIENT_EMAIL=
GCP_PRIVATE_KEY=
# Cron secret for scheduled jobs.
# Also used by the private-location app to authenticate status forwards to the workflows
# app (WORKFLOWS_URL, set per-service in docker-compose; defaults to the prod Fly URL).
CRON_SECRET=your-random-cron-secret
# API KEYS
# ============================================================================
# Unkey (optional - for API key management)
# Get from: https://unkey.dev
UNKEY_API_ID=
UNKEY_TOKEN=
# Super admin token for privileged operations
SUPER_ADMIN_TOKEN=
# Server region identifier
FLY_REGION=self-hosted
# STRIPE
# ============================================================================
# Stripe (optional - for payments)
# Get from: https://stripe.com/docs/keys
STRIPE_SECRET_KEY=
STRIPE_WEBHOOK_SECRET_KEY=
NEXT_PUBLIC_STRIPE_PUBLISHABLE_KEY=
# VERCEL
# ============================================================================
# Vercel (optional - for custom domains)
# Get from: https://vercel.com
PROJECT_ID_VERCEL=
TEAM_ID_VERCEL=
VERCEL_AUTH_BEARER_TOKEN=
# Vercel Blob storage (optional)
BLOB_READ_WRITE_TOKEN=
# OBSERVABILITY
# ============================================================================
# Sentry (optional - error tracking)
# Get from: https://sentry.io
NEXT_PUBLIC_SENTRY_DSN=
SENTRY_AUTH_TOKEN=
# OpenPanel (optional - analytics)
# Get from: https://openpanel.dev
NEXT_PUBLIC_OPENPANEL_CLIENT_ID=
OPENPANEL_CLIENT_SECRET=
# PagerDuty (optional - alerting)
PAGERDUTY_APP_ID=
# Slack webhook (optional)
SLACK_SUPPORT_WEBHOOK_URL=
# Telegram Bot (optional)
TELEGRAM_BOT_TOKEN=
# SERVICE CONFIGURATION
# ============================================================================
NODE_ENV=production
# [REQUIRED] Public URL for the application
NEXT_PUBLIC_URL=http://localhost:3002
# Screenshot service (optional)
SCREENSHOT_SERVICE_URL=
# OAuth for the MCP server. The API server is the authorization server and the
# dashboard serves the consent screen, so both need their public origins here.
# With NODE_ENV=production the defaults point at openstatus Cloud, which would
# send your users to app.openstatus.dev to approve a connection.
OAUTH_ISSUER=http://localhost:3001
DASHBOARD_URL=http://localhost:3002
# NOTE: OPENSTATUS_INGEST_URL does not belong here. No service in this compose
# stack reads it -- it configures the *probe* (ghcr.io/openstatushq/private-location),
# which runs on whatever host you monitor from. Set it there, alongside
# OPENSTATUS_KEY, pointing at this stack's private-location service on port 8081.
# Docs knowledge base for the AI assistant / MCP server (optional)
# The search_docs/get_doc_page and search_content/get_content_page tools query
# this site's /api/search and /api/markdown endpoints. Defaults to the public openstatus.dev docs.
# OPENSTATUS_WEB_BASE_URL=https://www.openstatus.dev
# AI chat provider (optional). Configure ONE option to enable the assistant.
# Option 1 — OpenAI-compatible endpoint (NVIDIA NIM, vLLM, Ollama, OpenRouter…).
# Recommended for self-hosting; takes priority when AI_BASE_URL is set. The model
# MUST support tool calling. AI_API_KEY is optional for keyless local gateways.
# AI_BASE_URL=https://integrate.api.nvidia.com/v1
# AI_API_KEY=nvapi-xxxxx
# AI_MODEL=meta/llama-3.1-70b-instruct
# Option 2 — Vercel AI Gateway (model chosen by workspace plan).
# AI_GATEWAY_API_KEY=
# DEVELOPMENT & TESTING
# ============================================================================
# Turbo build mode
TURBO_ENV_MODE=loose
# Playground API keys (optional)
PLAYGROUND_UNKEY_API_KEY=
# Workspace settings (optional)
WORKSPACES_HIDE_URL=