mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
619 lines
25 KiB
Bash
619 lines
25 KiB
Bash
# Every variable docker-compose.yml reads. A value an install must set is
|
|
# uncommented. A commented line shows the default, or an example where its comment
|
|
# says so, and nothing after = means the service decides. An empty value keeps the
|
|
# default too. Compose expands top to bottom, so a line using ${...} must sit below
|
|
# every name it reads.
|
|
|
|
FLUXER_DOMAIN=chat.example.com
|
|
FLUXER_PUBLIC_SCHEME=https
|
|
FLUXER_PUBLIC_PORT=443
|
|
|
|
# The address browsers use. FLUXER_HTTP_PORT and FLUXER_HTTPS_PORT below decide
|
|
# which host ports Fluxer binds.
|
|
|
|
# By default Fluxer binds 80 and 443 and gets its own certificate. Point DNS here.
|
|
# Behind your own reverse proxy, uncomment this instead: Fluxer then serves plain
|
|
# HTTP on 127.0.0.1:8080. Keep the scheme and port above describing the public
|
|
# address, not this one.
|
|
#COMPOSE_FILE=docker-compose.yml:docker-compose.proxy.yml
|
|
|
|
# Where that plain-HTTP port binds. Use 0.0.0.0:8080 only when the proxy is on
|
|
# another machine, and firewall it to that machine.
|
|
#FLUXER_EDGE_BIND=127.0.0.1:8080
|
|
|
|
# Which hops may set X-Forwarded-For. The default covers private and loopback
|
|
# addresses. Set your proxy's address if it reaches Fluxer from a public IP.
|
|
#FLUXER_EDGE_TRUSTED_PROXIES=private_ranges
|
|
|
|
# The origin browsers see, no trailing slash. Set it when browsers reach the
|
|
# instance on a host FLUXER_DOMAIN does not name, and it wins over the three
|
|
# values above. Scheme, host and optional port only. It does not move the
|
|
# published ports.
|
|
#FLUXER_PUBLIC_ORIGIN=https://chat.example.com
|
|
|
|
# The address the edge listens on inside its container. Both proxy overlays set
|
|
# this themselves, so a value here is ignored under either. Include the scheme.
|
|
#FLUXER_EDGE_SITE_ADDRESS=https://chat.example.com
|
|
|
|
# The old name for the line above, read only when it is unset.
|
|
#FLUXER_CADDY_SITE_ADDRESS=
|
|
|
|
# Host ports. Container 80 handles the redirect and the certificate challenge,
|
|
# container 443 the TLS site. FLUXER_HTTPS_PORT moves TCP and UDP together, since
|
|
# HTTP/3 needs both. Both accept a bind address. Give them different host ports.
|
|
#FLUXER_HTTP_PORT=80
|
|
#FLUXER_HTTPS_PORT=443
|
|
#FLUXER_HTTP_PORT=127.0.0.1:80
|
|
#FLUXER_HTTPS_PORT=127.0.0.1:443
|
|
|
|
# HTTPS on 8443. Host 80 stays published for the certificate challenge, which
|
|
# only ever arrives on public 80 or 443. Serve your own certificate if nothing
|
|
# forwards those.
|
|
#FLUXER_PUBLIC_PORT=8443
|
|
#FLUXER_HTTPS_PORT=8443
|
|
|
|
# Plain HTTP on 19080. Nothing binds host 80, and the last line parks the idle
|
|
# 443 publish on loopback.
|
|
#FLUXER_PUBLIC_SCHEME=http
|
|
#FLUXER_PUBLIC_PORT=19080
|
|
#FLUXER_HTTP_PORT=19080
|
|
#FLUXER_HTTPS_PORT=127.0.0.1:443
|
|
|
|
# A tunnel needs no HTTPS publish. tunnel.compose.yml ships beside this file and
|
|
# leaves one loopback HTTP publish. Needs Compose 2.24.4 or newer.
|
|
#COMPOSE_FILE=docker-compose.yml:tunnel.compose.yml
|
|
|
|
FLUXER_REGISTRY_OWNER=fluxerapp
|
|
FLUXER_REGISTRY=ghcr.io/${FLUXER_REGISTRY_OWNER}
|
|
FLUXER_IMAGE_TAG=v1
|
|
|
|
POSTGRES_PASSWORD=CHANGE_ME
|
|
MEILI_MASTER_KEY=CHANGE_ME
|
|
# Set these to run Postgres or the object store outside the stack. Backing up a
|
|
# store you moved out is yours to arrange. An upgrade dumps the bundled postgres
|
|
# service and skips the dump only when the stack defines none. The values below
|
|
# are examples.
|
|
#FLUXER_POSTGRES_HOST=db.example.com
|
|
#FLUXER_POSTGRES_PORT=5432
|
|
#FLUXER_POSTGRES_DATABASE=fluxer
|
|
#FLUXER_POSTGRES_USERNAME=fluxer
|
|
#FLUXER_POSTGRES_SSL=true
|
|
#FLUXER_S3_ENDPOINT=https://s3.eu-central-1.amazonaws.com
|
|
#FLUXER_S3_PUBLIC_ENDPOINT=https://cdn.example.com
|
|
#FLUXER_S3_REGION=eu-central-1
|
|
#FLUXER_S3_FORCE_PATH_STYLE=false
|
|
|
|
# Bucket names. The bundled store creates these. An outside store needs them to
|
|
# exist already.
|
|
#FLUXER_S3_BUCKET_CDN=fluxer
|
|
#FLUXER_S3_BUCKET_UPLOADS=fluxer-uploads
|
|
#FLUXER_S3_BUCKET_REPORTS=fluxer-reports
|
|
#FLUXER_S3_BUCKET_HARVESTS=fluxer-harvests
|
|
# With the object store outside the stack, add this overlay to COMPOSE_FILE and
|
|
# the bundled seaweedfs no longer starts. Put it after any other overlay, such as
|
|
# docker-compose.yml:docker-compose.proxy.yml:external-object-store.compose.yml.
|
|
# Needs Compose 2.24.4 or newer.
|
|
#COMPOSE_FILE=docker-compose.yml:external-object-store.compose.yml
|
|
|
|
# A full connection URL wins over the host, port and database above. The URL is an
|
|
# example. The CA is the PEM text of the certificate, with \n for line breaks.
|
|
#FLUXER_POSTGRES_URL=postgres://fluxer:[email protected]:5432/fluxer
|
|
#FLUXER_POSTGRES_SSL_CA=
|
|
# The Postgres table that holds the key-value store.
|
|
#FLUXER_POSTGRES_KV_TABLE=fluxer_kv
|
|
# media-proxy reads through these when the store serves reads from another
|
|
# address or bucket.
|
|
#FLUXER_S3_READ_ENDPOINT=
|
|
#FLUXER_S3_READ_BUCKET=
|
|
#FLUXER_S3_READ_BUCKET_STYLE=
|
|
# A temporary S3 session token, read by media-proxy only.
|
|
#FLUXER_S3_SESSION_TOKEN=
|
|
# The bundled store refuses unsigned reads. Set false only for a public-read bucket.
|
|
#FLUXER_S3_READ_SIGNED=true
|
|
|
|
# The other bundled services, pointed elsewhere. Removing a service from the
|
|
# stack belongs in an override file, since an upgrade replaces docker-compose.yml.
|
|
# The URLs below are examples.
|
|
#FLUXER_KV_URL=redis://cache.example.com:6379/0
|
|
#FLUXER_NATS_URL=nats://mq.example.com:4222
|
|
#FLUXER_NATS_JETSTREAM_URL=nats://mq.example.com:4222
|
|
#FLUXER_SVC_NATS_URL=nats://mq.example.com:4222
|
|
#FLUXER_SEARCH_URL=https://search.example.com
|
|
#FLUXER_LIVEKIT_INTERNAL_URL=http://livekit.example.com:7880
|
|
# How the stack talks to those services.
|
|
#FLUXER_KV_MODE=standalone
|
|
#FLUXER_SEARCH_ENGINE=meilisearch
|
|
#FLUXER_SEARCH_USERNAME=
|
|
#FLUXER_SEARCH_PASSWORD=
|
|
#FLUXER_SEARCH_TLS_REJECT_UNAUTHORIZED=true
|
|
|
|
# Voice off. The livekit service still runs until an override removes it.
|
|
#FLUXER_LIVEKIT_ENABLED=false
|
|
|
|
# Optional systems, each off unless configured.
|
|
#FLUXER_STRIPE_ENABLED=false
|
|
#FLUXER_STRIPE_SECRET_KEY=
|
|
#FLUXER_STRIPE_WEBHOOK_SECRET=
|
|
# Stripe prices as one JSON object. The admin dashboard can set them instead.
|
|
#FLUXER_STRIPE_PRICES={}
|
|
#FLUXER_STRIPE_LEGACY_PRICES={}
|
|
#FLUXER_API_DONATION_PROXY_KEY=
|
|
#FLUXER_VISIONARIES_GUILD_ID=
|
|
#FLUXER_VISIONARIES_GUILD_VISIONARY_ROLE_ID=
|
|
|
|
# NCMEC CyberTipline reporting, off by default. All four values are required
|
|
# once it is on. The values below are examples.
|
|
#FLUXER_NCMEC_ENABLED=true
|
|
#FLUXER_NCMEC_BASE_URL=https://report.cybertip.org/ispws
|
|
#FLUXER_NCMEC_USERNAME=
|
|
#FLUXER_NCMEC_PASSWORD=
|
|
#[email protected]
|
|
|
|
# Upload virus scanning, off by default. No ClamAV container ships, so point
|
|
# this at your own. The values below are examples.
|
|
#FLUXER_CLAMAV_ENABLED=true
|
|
#FLUXER_CLAMAV_HOST=clamav
|
|
#FLUXER_CLAMAV_PORT=3310
|
|
#FLUXER_CLAMAV_FAIL_OPEN=false
|
|
|
|
# Outside lookups, off unless turned on. The breached password check asks
|
|
# api.pwnedpasswords.com.
|
|
#FLUXER_BREACHED_PASSWORD_CHECK_ENABLED=false
|
|
#FLUXER_BLOCKLIST_FEEDS_ENABLED=false
|
|
# A local path, or an s3:// URL read with the S3 credentials of this file.
|
|
#FLUXER_GEOIP_DB_PATH=
|
|
|
|
# The client address. The edge sets X-Forwarded-For on every hop, so keep the
|
|
# trust on and the default header. Turning the trust off makes the api refuse
|
|
# every request outside its exempt routes with a 403.
|
|
#FLUXER_CLIENT_IP_HEADER_NAME=x-forwarded-for
|
|
#FLUXER_TRUST_CLIENT_IP_HEADER=true
|
|
|
|
# How much the services write. LOG_LEVEL covers the api and worker and takes trace,
|
|
# debug, info, warn, error or fatal. RUST_LOG covers the Rust services and takes
|
|
# an EnvFilter such as debug. The gateway takes an Erlang level such as notice,
|
|
# and LOGGER_LEVEL beats FLUXER_GATEWAY_LOGGER_LEVEL.
|
|
#LOG_LEVEL=info
|
|
#RUST_LOG=info
|
|
#FLUXER_GATEWAY_LOGGER_LEVEL=info
|
|
#LOGGER_LEVEL=
|
|
|
|
FLUXER_S3_ACCESS_KEY=fluxer
|
|
FLUXER_S3_SECRET_KEY=CHANGE_ME
|
|
|
|
FLUXER_SUDO_MODE_SECRET=CHANGE_ME
|
|
FLUXER_CONNECTION_INITIATION_SECRET=CHANGE_ME
|
|
FLUXER_GATEWAY_RPC_AUTH_TOKEN=CHANGE_ME
|
|
FLUXER_ERLANG_COOKIE=CHANGE_ME
|
|
FLUXER_MEDIA_PROXY_SECRET_KEY=CHANGE_ME
|
|
FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SECRET_BASE64=CHANGE_ME
|
|
FLUXER_ADMIN_SECRET_KEY_BASE=CHANGE_ME
|
|
FLUXER_ADMIN_OAUTH_CLIENT_SECRET=CHANGE_ME
|
|
|
|
# The token every service sends to NATS. The bundled NATS needs none, so this
|
|
# stays empty unless an override points at an external one.
|
|
#FLUXER_NATS_AUTH_TOKEN=
|
|
|
|
FLUXER_VAPID_PUBLIC_KEY=CHANGE_ME
|
|
FLUXER_VAPID_PRIVATE_KEY=CHANGE_ME
|
|
|
|
# Defaults to admin@ followed by FLUXER_DOMAIN. Set it if that mailbox does not
|
|
# exist.
|
|
#[email protected]
|
|
|
|
# The passkey RP ID defaults to FLUXER_DOMAIN, whatever FLUXER_PUBLIC_ORIGIN says.
|
|
# Changing the RP ID invalidates every passkey registered against the old value.
|
|
#FLUXER_PASSKEY_RP_ID=chat.example.com
|
|
#FLUXER_PASSKEY_RP_NAME=Fluxer
|
|
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=https://chat.example.com
|
|
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=http://chat.example.com:19080
|
|
|
|
# Notification jobs the push container holds at once, 1 to 1000000.
|
|
#FLUXER_PUSH_SERVICE_QUEUE_CAPACITY=10000
|
|
# Provider requests the push container sends at once, 1 to 65536.
|
|
#FLUXER_PUSH_SERVICE_SEND_CONCURRENCY=256
|
|
# The push container's provider addresses and relay hosts.
|
|
#FLUXER_PUSH_SERVICE_APNS_BASE_URL=
|
|
#FLUXER_PUSH_SERVICE_FCM_BASE_URL=https://fcm.googleapis.com
|
|
#FLUXER_PUSH_SERVICE_MANAGED_RELAY_HOSTS=push.fluxer.com
|
|
#FLUXER_PUSH_SERVICE_OWN_RELAY_HOSTS=
|
|
#FLUXER_PUSH_SERVICE_RELAY_CONSENT_ACCEPTED=false
|
|
|
|
# Direct mobile push through your own APNs and FCM credentials, off by default.
|
|
#FLUXER_PUSH_APNS_ENABLED=false
|
|
#FLUXER_PUSH_APNS_TEAM_ID=
|
|
#FLUXER_PUSH_APNS_KEY_ID=
|
|
#FLUXER_PUSH_APNS_PRIVATE_KEY=
|
|
#FLUXER_PUSH_APNS_PRIVATE_KEY_PATH=
|
|
#FLUXER_PUSH_APNS_APPS=
|
|
#FLUXER_PUSH_APNS_DEFAULT_ENVIRONMENT=production
|
|
#FLUXER_PUSH_FCM_ENABLED=false
|
|
#FLUXER_PUSH_FCM_PROJECT_ID=
|
|
#FLUXER_PUSH_FCM_CLIENT_EMAIL=
|
|
#FLUXER_PUSH_FCM_PRIVATE_KEY=
|
|
#FLUXER_PUSH_FCM_PRIVATE_KEY_PATH=
|
|
#FLUXER_PUSH_FCM_SERVICE_ACCOUNT_JSON_PATH=
|
|
#FLUXER_PUSH_FCM_TOKEN_URI=https://oauth2.googleapis.com/token
|
|
#FLUXER_PUSH_FCM_APPS=
|
|
|
|
|
|
# Optional media policies, both off by default. See the operator docs.
|
|
#
|
|
# CORS limits which web origins may read media. A request with no Origin is
|
|
# always served. Add https://web.fluxer.app if people use the hosted client.
|
|
#
|
|
# Signatures make an attachment read need a signed URL, so a copied link stops
|
|
# working. Needs a secret from openssl rand -base64 32, first entry signs and
|
|
# every entry verifies.
|
|
#
|
|
# Each mode is off, report or enforce, and off is the default. Start at report.
|
|
# media-proxy reads these at start, so apply with docker compose up -d
|
|
# media-proxy. The values below are examples.
|
|
#FLUXER_MEDIA_PROXY_CORS_MODE=enforce
|
|
#FLUXER_MEDIA_PROXY_CORS_ALLOWED_ORIGINS=https://chat.example.com,https://web.fluxer.app
|
|
#FLUXER_MEDIA_PROXY_ATTACHMENT_URL_SECRETS_BASE64=
|
|
#FLUXER_MEDIA_PROXY_ATTACHMENT_SIGNATURE_MODE=enforce
|
|
|
|
# Extra Content-Security-Policy sources, appended to the built-in ones. Set one
|
|
# only when a browser must reach an origin the defaults do not cover. Separate
|
|
# several with spaces or commas. The three values below are illustrations.
|
|
#FLUXER_CSP_EXTRA_DEFAULT_SRC=
|
|
#FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com:7881
|
|
#FLUXER_CSP_EXTRA_IMG_SRC=https://cdn.example.com
|
|
#FLUXER_CSP_EXTRA_MEDIA_SRC=
|
|
#FLUXER_CSP_EXTRA_FONT_SRC=
|
|
#FLUXER_CSP_EXTRA_SCRIPT_SRC=https://analytics.example.com
|
|
#FLUXER_CSP_EXTRA_STYLE_SRC=
|
|
#FLUXER_CSP_EXTRA_FRAME_SRC=
|
|
#FLUXER_CSP_EXTRA_WORKER_SRC=
|
|
#FLUXER_CSP_EXTRA_MANIFEST_SRC=
|
|
|
|
# One report-uri for CSP violation reports. Empty leaves the directive off.
|
|
#FLUXER_CSP_REPORT_URI=
|
|
|
|
# Let the SSO provider resolve to a private address. Off by default, so a
|
|
# misconfigured provider URL cannot reach internal services. Turn it on only for
|
|
# a provider on your own network. The value below is an example.
|
|
#FLUXER_SSO_ALLOW_PRIVATE_ADDRESSES=true
|
|
|
|
# These reach both LiveKit and the api. Change them together.
|
|
LIVEKIT_API_KEY=fluxer
|
|
LIVEKIT_API_SECRET=CHANGE_ME
|
|
|
|
# The URL browsers use for voice signalling. Built from the public origin plus
|
|
# /livekit. Set it only when LiveKit is served from another host.
|
|
#FLUXER_LIVEKIT_URL=
|
|
|
|
# Media ports. LiveKit advertises these, so forward the same numbers.
|
|
#FLUXER_LIVEKIT_TCP_PORT=7881
|
|
#FLUXER_LIVEKIT_UDP_PORT=7882
|
|
|
|
# LiveKit finds its public address over STUN. A host that cannot reach one stops
|
|
# with "could not resolve external IP", so set the address by hand instead, or
|
|
# point STUN elsewhere. The values below are examples.
|
|
#FLUXER_LIVEKIT_USE_EXTERNAL_IP=false
|
|
#FLUXER_LIVEKIT_NODE_IP=203.0.113.10
|
|
#FLUXER_LIVEKIT_STUN_PRIMARY=stun.l.google.com:19302
|
|
#FLUXER_LIVEKIT_STUN_SECONDARY=stun1.l.google.com:19302
|
|
|
|
# The voice region users see, and how much LiveKit logs.
|
|
#FLUXER_LIVEKIT_DEFAULT_REGION={"id":"default","name":"Default","emoji":"🌍","latitude":0,"longitude":0}
|
|
#FLUXER_LIVEKIT_LOG_LEVEL=info
|
|
|
|
FLUXER_KLIPY_API_KEY=
|
|
#FLUXER_YOUTUBE_API_KEY=
|
|
# Hosts the api never unfurls, comma separated.
|
|
#FLUXER_API_UNFURL_IGNORED_HOSTS=
|
|
|
|
FLUXER_EMAIL_ENABLED=false
|
|
FLUXER_EMAIL_PROVIDER=none
|
|
FLUXER_EMAIL_FROM_EMAIL=[email protected]
|
|
FLUXER_EMAIL_FROM_NAME=Fluxer
|
|
#[email protected]
|
|
FLUXER_EMAIL_APP_BASE_URL=
|
|
FLUXER_EMAIL_SMTP_HOST=
|
|
FLUXER_EMAIL_SMTP_PORT=587
|
|
FLUXER_EMAIL_SMTP_USERNAME=
|
|
FLUXER_EMAIL_SMTP_PASSWORD=
|
|
FLUXER_EMAIL_SMTP_SECURE=true
|
|
#FLUXER_EMAIL_WEBHOOK_SECRET=
|
|
|
|
FLUXER_DISCOVERY_ENABLED=true
|
|
#FLUXER_DISCOVERY_MIN_MEMBER_COUNT=1
|
|
|
|
# Instance identity and account policy.
|
|
#FLUXER_APP_PRODUCT_NAME=Fluxer
|
|
#FLUXER_APP_ICON_URL=
|
|
#FLUXER_APP_SYMBOL_URL=
|
|
#FLUXER_APP_LOGO_URL=
|
|
#FLUXER_APP_WORDMARK_URL=
|
|
#FLUXER_APP_FAVICON_URL=
|
|
#FLUXER_APP_THEME_COLOR=
|
|
#FLUXER_APP_STATUS_PAGE_URL=
|
|
#FLUXER_APP_STATUS_PAGE_INCIDENT_HISTORY_URL=
|
|
#FLUXER_INSTANCE_SETUP_CONFIGURED=false
|
|
#FLUXER_AUTO_JOIN_INVITE_CODE=
|
|
#FLUXER_DELETION_GRACE_PERIOD_HOURS=336
|
|
|
|
# Sign in with Bluesky, off unless turned on.
|
|
#FLUXER_AUTH_BLUESKY_ENABLED=false
|
|
#FLUXER_AUTH_BLUESKY_CLIENT_NAME=Fluxer
|
|
#FLUXER_AUTH_BLUESKY_CLIENT_URI=
|
|
#FLUXER_AUTH_BLUESKY_LOGO_URI=
|
|
#FLUXER_AUTH_BLUESKY_TOS_URI=
|
|
#FLUXER_AUTH_BLUESKY_POLICY_URI=
|
|
#FLUXER_AUTH_BLUESKY_KEYS=
|
|
|
|
# Public addresses. Each follows the public origin unless set here.
|
|
#FLUXER_API_ENDPOINT=
|
|
#FLUXER_API_CLIENT_ENDPOINT=
|
|
#FLUXER_APP_ENDPOINT=
|
|
#FLUXER_GATEWAY_ENDPOINT=
|
|
#FLUXER_MEDIA_ENDPOINT=
|
|
#FLUXER_STATIC_CDN_ENDPOINT=
|
|
#FLUXER_ADMIN_ENDPOINT=
|
|
#FLUXER_MARKETING_ENDPOINT=
|
|
#FLUXER_INVITE_ENDPOINT=
|
|
#FLUXER_GIFT_ENDPOINT=
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_ENDPOINT=
|
|
#PUBLIC_BOOTSTRAP_API_PUBLIC_ENDPOINT=
|
|
# These follow FLUXER_STATIC_CDN_ENDPOINT first, then the public origin.
|
|
#FLUXER_GATEWAY_STATIC_CDN_ENDPOINT=
|
|
#FLUXER_UNFURL_STATIC_CDN_ENDPOINT=
|
|
# These follow FLUXER_MEDIA_ENDPOINT first, then the public origin.
|
|
#FLUXER_MEDIA_PROXY_PUBLIC_ENDPOINT=
|
|
#FLUXER_GATEWAY_MEDIA_PROXY_ENDPOINT=
|
|
|
|
# Extra hosts for static assets, invites, gifts and the web app. Empty by default.
|
|
#FLUXER_STATIC_CDN_DOMAIN=
|
|
#FLUXER_INVITE_DOMAIN=
|
|
#FLUXER_GIFT_DOMAIN=
|
|
#FLUXER_APP_ORIGIN_ALIASES=
|
|
|
|
# The path the admin panel is served under. The edge and the admin service read
|
|
# it. The api follows it through the default FLUXER_ADMIN_ENDPOINT, and not when
|
|
# FLUXER_ADMIN_ENDPOINT is set. Write it with a leading slash and no trailing
|
|
# slash.
|
|
#FLUXER_ADMIN_BASE_PATH=/admin
|
|
|
|
# The compression the edge offers, as Caddy encode arguments.
|
|
#FLUXER_EDGE_ENCODE=zstd gzip
|
|
|
|
# Images of the bundled services, for a mirror or another tag. A new Postgres
|
|
# major needs a dump and restore, as the upgrade guide describes.
|
|
#FLUXER_CADDY_IMAGE=caddy:2.11-alpine
|
|
#FLUXER_POSTGRES_IMAGE=postgres:16-alpine
|
|
#FLUXER_VALKEY_IMAGE=valkey/valkey:9.1-alpine
|
|
#FLUXER_NATS_IMAGE=nats:2.14-alpine
|
|
#FLUXER_MEILISEARCH_IMAGE=getmeili/meilisearch:v1.53
|
|
#FLUXER_SEAWEEDFS_IMAGE=chrislusf/seaweedfs:4.47
|
|
#FLUXER_LIVEKIT_IMAGE=livekit/livekit-server:v1.12.0
|
|
|
|
# Restart policy for every long-running service.
|
|
#FLUXER_RESTART_POLICY=unless-stopped
|
|
|
|
# Health checks. Raise the retries or start periods on a slow host.
|
|
#FLUXER_HEALTHCHECK_INTERVAL=10s
|
|
#FLUXER_HEALTHCHECK_TIMEOUT=5s
|
|
#FLUXER_HEALTHCHECK_RETRIES=10
|
|
#FLUXER_APP_HEALTHCHECK_RETRIES=30
|
|
#FLUXER_APP_HEALTHCHECK_START_PERIOD=90s
|
|
#FLUXER_SVC_HEALTHCHECK_START_PERIOD=60s
|
|
#FLUXER_WORKER_HEALTHCHECK_RETRIES=3
|
|
#FLUXER_SEAWEEDFS_HEALTHCHECK_RETRIES=20
|
|
#FLUXER_SEAWEEDFS_HEALTHCHECK_START_PERIOD=60s
|
|
#FLUXER_SEAWEEDFS_INIT_ATTEMPTS=60
|
|
|
|
# Container memory. These are ceilings, not allocations, and the defaults suit a
|
|
# 16 GB host. The reservations bias the kernel away from reclaiming from services
|
|
# whose death takes the instance down. Lower the limits on a smaller host.
|
|
#FLUXER_CADDY_MEMORY_LIMIT=256mb
|
|
#FLUXER_POSTGRES_MEMORY_LIMIT=5gb
|
|
#FLUXER_POSTGRES_MEMORY_RESERVATION=3gb
|
|
#FLUXER_VALKEY_MEMORY_LIMIT=256mb
|
|
#FLUXER_NATS_MEMORY_LIMIT=256mb
|
|
#FLUXER_MEILISEARCH_MEMORY_LIMIT=1536mb
|
|
#FLUXER_SEAWEEDFS_MEMORY_LIMIT=2gb
|
|
#FLUXER_SEAWEEDFS_INIT_MEMORY_LIMIT=128mb
|
|
#FLUXER_LIVEKIT_MEMORY_LIMIT=512mb
|
|
#FLUXER_API_MEMORY_LIMIT=2560mb
|
|
#FLUXER_API_MEMORY_RESERVATION=1gb
|
|
#FLUXER_WORKER_MEMORY_LIMIT=2560mb
|
|
#FLUXER_WORKER_MEMORY_RESERVATION=1gb
|
|
#FLUXER_GATEWAY_MEMORY_LIMIT=1gb
|
|
#FLUXER_GATEWAY_MEMORY_RESERVATION=384mb
|
|
#FLUXER_MEDIA_PROXY_MEMORY_LIMIT=512mb
|
|
#FLUXER_PUSH_MEMORY_LIMIT=256mb
|
|
#FLUXER_STATIC_PROXY_MEMORY_LIMIT=256mb
|
|
#FLUXER_APP_PROXY_MEMORY_LIMIT=256mb
|
|
#FLUXER_SNOWFLAKES_MEMORY_LIMIT=128mb
|
|
#FLUXER_SNOWFLAKES_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_USERS_MEMORY_LIMIT=128mb
|
|
#FLUXER_USERS_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_GIFS_MEMORY_LIMIT=128mb
|
|
#FLUXER_GIFS_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_MESSAGES_MEMORY_LIMIT=128mb
|
|
#FLUXER_MESSAGES_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_UNFURL_MEMORY_LIMIT=128mb
|
|
#FLUXER_UNFURL_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_ADMIN_MEMORY_LIMIT=256mb
|
|
|
|
# Meilisearch indexing memory and threads. Each indexing thread needs its own
|
|
# buffers on top of the indexing memory, so raise the threads only together with
|
|
# the container limit above.
|
|
#FLUXER_MEILISEARCH_MAX_INDEXING_MEMORY=256mb
|
|
#FLUXER_MEILISEARCH_MAX_INDEXING_THREADS=2
|
|
#FLUXER_MEILISEARCH_ENV=production
|
|
#FLUXER_MEILISEARCH_NO_ANALYTICS=true
|
|
|
|
# SeaweedFS heap ceiling. Go cannot see the container limit, so without this an
|
|
# upload burst gets the container OOM-killed. Keep it near three quarters of
|
|
# FLUXER_SEAWEEDFS_MEMORY_LIMIT and raise both together.
|
|
#FLUXER_SEAWEEDFS_GOMEMLIMIT=1536MiB
|
|
#FLUXER_SEAWEEDFS_TELEMETRY=false
|
|
|
|
# Volumes SeaweedFS creates at once when a bucket needs space. Each reserves 1 GB
|
|
# of free disk from the start, and SeaweedFS's own default of 7 fills a small
|
|
# disk before every bucket has one, so uploads fail with no free volumes left.
|
|
#FLUXER_SEAWEEDFS_VOLUME_GROWTH=1
|
|
|
|
# Node sizes its heap from the container limit by default. Leave these unset
|
|
# unless you need to pin it. A heap ceiling above the container limit gets the
|
|
# container OOM-killed instead of reporting a heap error. The values below are
|
|
# examples.
|
|
#FLUXER_API_NODE_HEAP_MB=1792
|
|
#FLUXER_WORKER_NODE_HEAP_MB=1792
|
|
|
|
# Extra Node flags for api and worker, appended to NODE_OPTIONS. Empty by
|
|
# default. The value below is an example.
|
|
#FLUXER_API_NODE_OPTIONS=--heapsnapshot-near-heap-limit=1
|
|
#FLUXER_WORKER_NODE_OPTIONS=--heapsnapshot-near-heap-limit=1
|
|
|
|
# Extra CA certificates api and worker trust, as a PEM bundle path inside the
|
|
# container. The default is the image's system bundle.
|
|
#FLUXER_NODE_EXTRA_CA_CERTS=/etc/ssl/certs/ca-certificates.crt
|
|
|
|
# Bundled Postgres tuning. Keep it consistent with the memory limit above. This
|
|
# is the server setting, not the per-service pool sizes.
|
|
#FLUXER_POSTGRES_SERVER_MAX_CONNECTIONS=150
|
|
#FLUXER_POSTGRES_SHARED_BUFFERS=512MB
|
|
#FLUXER_POSTGRES_EFFECTIVE_CACHE_SIZE=2GB
|
|
#FLUXER_POSTGRES_WORK_MEM=8MB
|
|
#FLUXER_POSTGRES_MAINTENANCE_WORK_MEM=256MB
|
|
#FLUXER_POSTGRES_AUTOVACUUM_WORK_MEM=128MB
|
|
#FLUXER_POSTGRES_SHM_SIZE=1gb
|
|
#FLUXER_POSTGRES_RANDOM_PAGE_COST=1.1
|
|
#FLUXER_POSTGRES_EFFECTIVE_IO_CONCURRENCY=200
|
|
#FLUXER_POSTGRES_DEFAULT_STATISTICS_TARGET=200
|
|
#FLUXER_POSTGRES_JIT=off
|
|
#FLUXER_POSTGRES_MIN_WAL_SIZE=512MB
|
|
#FLUXER_POSTGRES_MAX_WAL_SIZE=2GB
|
|
#FLUXER_POSTGRES_CHECKPOINT_COMPLETION_TARGET=0.9
|
|
#FLUXER_POSTGRES_WAL_BUFFERS=16MB
|
|
#FLUXER_POSTGRES_WAL_COMPRESSION=zstd
|
|
#FLUXER_POSTGRES_BGWRITER_DELAY=50ms
|
|
#FLUXER_POSTGRES_BGWRITER_LRU_MAXPAGES=1000
|
|
#FLUXER_POSTGRES_AUTOVACUUM_VACUUM_SCALE_FACTOR=0.05
|
|
#FLUXER_POSTGRES_AUTOVACUUM_ANALYZE_SCALE_FACTOR=0.02
|
|
#FLUXER_POSTGRES_AUTOVACUUM_VACUUM_COST_LIMIT=2000
|
|
#FLUXER_POSTGRES_TRACK_IO_TIMING=on
|
|
#FLUXER_POSTGRES_SHARED_PRELOAD_LIBRARIES=pg_stat_statements
|
|
|
|
# Postgres pool size of each service that opens a pool.
|
|
#FLUXER_API_POSTGRES_MAX_CONNECTIONS=25
|
|
#FLUXER_WORKER_POSTGRES_MAX_CONNECTIONS=25
|
|
#FLUXER_USERS_SHARD_POSTGRES_MAX_CONNECTIONS=20
|
|
#FLUXER_MESSAGES_SHARD_POSTGRES_MAX_CONNECTIONS=20
|
|
|
|
# The bundled Valkey holds durable state as well as cache, so it runs with an
|
|
# append-only file and with noeviction, which fails an over-limit write instead
|
|
# of dropping queued work. Change the policy only if that state lives elsewhere.
|
|
#FLUXER_VALKEY_MAXMEMORY=192mb
|
|
#FLUXER_VALKEY_MAXMEMORY_POLICY=noeviction
|
|
#FLUXER_VALKEY_APPENDFSYNC=everysec
|
|
|
|
# The gateway derives its scheduler count from the CPU quota, clamped here. One
|
|
# scheduler lets a single blocking operation stall every websocket on the node.
|
|
#FLUXER_ERLANG_SCHEDULERS_MIN=2
|
|
#FLUXER_ERLANG_SCHEDULERS_MAX=16
|
|
# A fixed scheduler count skips the clamp. Dirty CPU schedulers default to two
|
|
# thirds of it.
|
|
#FLUXER_ERLANG_SCHEDULERS=
|
|
#FLUXER_ERLANG_DIRTY_CPU_SCHEDULERS=
|
|
|
|
# Gateway push and RPC tuning.
|
|
#FLUXER_GATEWAY_PUSH_ENABLED=true
|
|
#FLUXER_GATEWAY_PUSH_ENROLLED_CLEAR_NOTIFICATIONS_ENABLED=true
|
|
#FLUXER_GATEWAY_PUSH_OUTBOX_REQUEST_TIMEOUT_MS=100000
|
|
#FLUXER_GATEWAY_PRESENCE_PUSH_BUFFER_MAX_ENTRIES=128
|
|
#FLUXER_GATEWAY_PRESENCE_PUSH_BUFFER_MAX_BYTES=1048576
|
|
#FLUXER_GATEWAY_HTTP_RPC_MAX_CONCURRENCY=512
|
|
#FLUXER_GATEWAY_NATS_RPC_MAX_HANDLERS=512
|
|
#FLUXER_GATEWAY_HTTP_FAILURE_THRESHOLD=6
|
|
#FLUXER_GATEWAY_HTTP_RECOVERY_TIMEOUT_MS=15000
|
|
|
|
# In-flight request ceiling for every svc router and shard. Unset, each keeps its
|
|
# own default: 192 for messages, 320 for snowflakes and 64 for the rest. One value
|
|
# replaces all of them, so size it for the busiest. Too low a value rejects
|
|
# requests rather than slowing them, and the api turns that into a 503. The value
|
|
# below is an example.
|
|
#FLUXER_SVC_MAX_CONCURRENT_REQUESTS=320
|
|
|
|
# svc caches, and how the api calls the svc services over NATS.
|
|
#FLUXER_SVC_CACHE_MAX_ENTRIES=100000
|
|
#FLUXER_SVC_CACHE_TTL_MS=30000
|
|
#FLUXER_GIFS_SHARD_CACHE_MAX_BYTES=536870912
|
|
#FLUXER_GIF_SERVICE_NATS_CLIENT_NAME=fluxer-api-gifs
|
|
#FLUXER_GIF_SERVICE_TIMEOUT_MS=12000
|
|
#FLUXER_GIF_SERVICE_REGISTER_SHARE_TIMEOUT_MS=3000
|
|
#FLUXER_USERS_SERVICE_NATS_CLIENT_NAME=fluxer-api-users
|
|
#FLUXER_USERS_SERVICE_TIMEOUT_MS=6000
|
|
#FLUXER_USERS_SERVICE_INFLIGHT_MAX_ENTRIES=10000
|
|
#FLUXER_SNOWFLAKE_SERVICE_NATS_CLIENT_NAME=fluxer-api-snowflakes
|
|
#FLUXER_SNOWFLAKE_SERVICE_BATCH_SIZE=128
|
|
#FLUXER_SNOWFLAKE_SERVICE_LOW_WATERMARK=
|
|
#FLUXER_SNOWFLAKE_SERVICE_MAX_BUFFER_AGE_MS=5000
|
|
#FLUXER_SNOWFLAKE_SERVICE_REQUEST_TIMEOUT_MS=6000
|
|
|
|
# Worker concurrency per lane, as a JSON object keyed by lane.
|
|
#FLUXER_API_WORKER_LANE_CONCURRENCY_OVERRIDES=
|
|
|
|
# Named prepared statements need a session that outlives the transaction, so set
|
|
# this to false behind a transaction-pooling connection pooler. The bundled
|
|
# compose talks to Postgres directly, where the default is correct.
|
|
#FLUXER_POSTGRES_PREPARED_STATEMENTS=true
|
|
|
|
# How long a client may take to send a request. The header timeout covers the
|
|
# request line and headers, the request timeout the whole exchange, and the first
|
|
# is clamped down to the second. Milliseconds, 1000 to 3600000.
|
|
#FLUXER_API_HEADERS_TIMEOUT_MS=30000
|
|
#FLUXER_API_REQUEST_TIMEOUT_MS=120000
|
|
|
|
# api request limits and IP bans. A refresh interval of 0 stops the periodic
|
|
# ban reload.
|
|
#FLUXER_API_MAX_INFLIGHT_REQUESTS=512
|
|
#FLUXER_API_IP_BAN_EXEMPT_IPS=
|
|
#FLUXER_IP_BAN_REFRESH_INTERVAL_MS=300000
|
|
|
|
# Uploads and data exports. Presigned exports link to FLUXER_S3_PUBLIC_ENDPOINT,
|
|
# so turn them on only once browsers can reach it.
|
|
#FLUXER_API_PRESIGNED_ATTACHMENT_UPLOADS_ENABLED=true
|
|
#FLUXER_API_PRESIGNED_HARVEST_DOWNLOADS_ENABLED=false
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_MAX_BODY_BYTES=524288000
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_TOKEN_TTL_SECS=900
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_KEEP_DIRECT_COUNTRIES=
|
|
#FLUXER_API_STORAGE_CHANGE_FEED_ENABLED=false
|
|
#FLUXER_API_STORAGE_CHANGE_FEED_STREAM=STORAGE_CHANGES
|
|
#FLUXER_API_STORAGE_CHANGE_FEED_SKIP_BUCKETS=
|
|
#FLUXER_CACHE_PURGE_ADAPTER=none
|
|
#FLUXER_CACHE_PURGE_HTTP_ENDPOINT=
|
|
#FLUXER_CACHE_PURGE_HTTP_TOKEN=
|
|
#FLUXER_CACHE_PURGE_HTTP_TIMEOUT_MS=10000
|
|
|
|
# media-proxy limits and timeouts.
|
|
#FLUXER_MEDIA_PROXY_READ_ONLY=false
|
|
#FLUXER_MEDIA_PROXY_NSFW_THRESHOLD=0.85
|
|
#FLUXER_NSFW_SERVICE_ENDPOINT=
|
|
#FLUXER_MEDIA_PROXY_MAX_NATIVE_TRANSFORMS=
|
|
#FLUXER_MEDIA_PROXY_WORKER_QUEUE_CAPACITY=
|
|
#FLUXER_MEDIA_PROXY_MAX_ENCODE_DURATION_MS=30000
|
|
#FLUXER_MEDIA_PROXY_MAX_ENCODE_FRAMES=20000
|
|
#FLUXER_MEDIA_PROXY_TRANSFORM_TIMEOUT_MS=15000
|
|
#FLUXER_MEDIA_PROXY_TRANSFORM_CACHE_BYTES=268435456
|
|
#FLUXER_MEDIA_PROXY_TRANSFORM_CACHE_MAX_ENTRY_BYTES=67108864
|
|
#FLUXER_MEDIA_PROXY_TRANSFORM_CACHE_TTL_MS=120000
|
|
#FLUXER_MEDIA_PROXY_SOCKET_IO_TIMEOUT_MS=30000
|
|
#FLUXER_MEDIA_PROXY_SHUTDOWN_GRACE_MS=30000
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_S3_TIMEOUT_MS=900000
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_BUFFERED_RETRY_BYTES=33554432
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_BUFFERED_RETRY_TOTAL_BYTES=536870912
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SPOOL_DIR=
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SPOOL_CHUNK_BYTES=1048576
|
|
#FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SPOOL_MAX_TOTAL_BYTES=8589934592
|
|
|
|
# app-proxy discovery refresh, index upstream and manifest scope.
|
|
#DISCOVERY_REFRESH_INTERVAL_MS=60000
|
|
#FLUXER_APP_PROXY_INDEX_UPSTREAM_URL=
|
|
#FLUXER_APP_PROXY_SAME_ORIGIN_HOSTS=
|
|
#FLUXER_APP_PROXY_MANIFEST_SCOPE_EXTENSIONS=
|