mirror of
https://github.com/fluxerapp/fluxer
synced 2026-10-07 19:22:14 +09:00
320 lines
13 KiB
Bash
320 lines
13 KiB
Bash
# Every variable docker-compose.yml reads, uncommented when it has no default and
|
|
# commented with its default when it has one. Compose expands top to bottom, so a
|
|
# line using ${...} must sit below every name it reads.
|
|
|
|
FLUXER_DOMAIN=chat.example.com
|
|
FLUXER_PUBLIC_SCHEME=https
|
|
FLUXER_PUBLIC_PORT=443
|
|
|
|
# The address browsers use. FLUXER_HTTP_PORT and FLUXER_HTTPS_PORT below decide
|
|
# which host ports Fluxer binds.
|
|
|
|
# By default Fluxer binds 80 and 443 and gets its own certificate. Point DNS here.
|
|
# Behind your own reverse proxy, uncomment this instead: Fluxer then serves plain
|
|
# HTTP on 127.0.0.1:8080. Keep the scheme and port above describing the public
|
|
# address, not this one.
|
|
#COMPOSE_FILE=docker-compose.yml:docker-compose.proxy.yml
|
|
|
|
# Where that plain-HTTP port binds. Use 0.0.0.0:8080 only when the proxy is on
|
|
# another machine, and firewall it to that machine.
|
|
#FLUXER_EDGE_BIND=127.0.0.1:8080
|
|
|
|
# Which hops may set X-Forwarded-For. The default covers private and loopback
|
|
# addresses. Set your proxy's address if it reaches Fluxer from a public IP.
|
|
#FLUXER_EDGE_TRUSTED_PROXIES=private_ranges
|
|
|
|
# The origin browsers see, no trailing slash. Set it when browsers reach the
|
|
# instance on a host FLUXER_DOMAIN does not name, and it wins over the three
|
|
# values above. Scheme, host and optional port only. It does not move the
|
|
# published ports.
|
|
#FLUXER_PUBLIC_ORIGIN=https://chat.example.com
|
|
|
|
# The address the edge listens on inside its container. Both proxy overlays set
|
|
# this themselves, so a value here is ignored under either. Include the scheme.
|
|
#FLUXER_EDGE_SITE_ADDRESS=https://chat.example.com
|
|
|
|
# The old name for the line above, read only when it is unset.
|
|
#FLUXER_CADDY_SITE_ADDRESS=
|
|
|
|
# Host ports. Container 80 handles the redirect and the certificate challenge,
|
|
# container 443 the TLS site. FLUXER_HTTPS_PORT moves TCP and UDP together, since
|
|
# HTTP/3 needs both. Both accept a bind address. Give them different host ports.
|
|
#FLUXER_HTTP_PORT=80
|
|
#FLUXER_HTTPS_PORT=443
|
|
#FLUXER_HTTP_PORT=127.0.0.1:80
|
|
#FLUXER_HTTPS_PORT=127.0.0.1:443
|
|
|
|
# HTTPS on 8443. Host 80 stays published for the certificate challenge, which
|
|
# only ever arrives on public 80 or 443. Serve your own certificate if nothing
|
|
# forwards those.
|
|
#FLUXER_PUBLIC_PORT=8443
|
|
#FLUXER_HTTPS_PORT=8443
|
|
|
|
# Plain HTTP on 19080. Nothing binds host 80, and the last line parks the idle
|
|
# 443 publish on loopback.
|
|
#FLUXER_PUBLIC_SCHEME=http
|
|
#FLUXER_PUBLIC_PORT=19080
|
|
#FLUXER_HTTP_PORT=19080
|
|
#FLUXER_HTTPS_PORT=127.0.0.1:443
|
|
|
|
# A tunnel needs no HTTPS publish. tunnel.compose.yml ships beside this file and
|
|
# leaves one loopback HTTP publish. Needs Compose 2.24.4 or newer.
|
|
#COMPOSE_FILE=docker-compose.yml:tunnel.compose.yml
|
|
|
|
FLUXER_REGISTRY_OWNER=fluxerapp
|
|
FLUXER_REGISTRY=ghcr.io/${FLUXER_REGISTRY_OWNER}
|
|
FLUXER_IMAGE_TAG=v1
|
|
|
|
POSTGRES_PASSWORD=CHANGE_ME
|
|
MEILI_MASTER_KEY=CHANGE_ME
|
|
# Set these to run Postgres or the object store outside the stack. Backing up a
|
|
# store you moved out is yours to arrange, and an upgrade skips it.
|
|
#FLUXER_POSTGRES_HOST=db.example.com
|
|
#FLUXER_POSTGRES_PORT=5432
|
|
#FLUXER_POSTGRES_DATABASE=fluxer
|
|
#FLUXER_POSTGRES_USERNAME=fluxer
|
|
#FLUXER_POSTGRES_SSL=true
|
|
#FLUXER_S3_ENDPOINT=https://s3.eu-central-1.amazonaws.com
|
|
#FLUXER_S3_PUBLIC_ENDPOINT=https://cdn.example.com
|
|
#FLUXER_S3_REGION=eu-central-1
|
|
#FLUXER_S3_FORCE_PATH_STYLE=false
|
|
# Bucket names. The bundled store creates these. An outside store needs them to
|
|
# exist already.
|
|
#FLUXER_S3_BUCKET_CDN=fluxer
|
|
#FLUXER_S3_BUCKET_UPLOADS=fluxer-uploads
|
|
#FLUXER_S3_BUCKET_REPORTS=fluxer-reports
|
|
#FLUXER_S3_BUCKET_HARVESTS=fluxer-harvests
|
|
|
|
# The other bundled services, pointed elsewhere. Removing a service from the
|
|
# stack belongs in an override file, since an upgrade replaces docker-compose.yml.
|
|
#FLUXER_KV_URL=redis://cache.example.com:6379/0
|
|
#FLUXER_NATS_URL=nats://mq.example.com:4222
|
|
#FLUXER_NATS_JETSTREAM_URL=nats://mq.example.com:4222
|
|
#FLUXER_SVC_NATS_URL=nats://mq.example.com:4222
|
|
#FLUXER_SEARCH_URL=https://search.example.com
|
|
#FLUXER_LIVEKIT_INTERNAL_URL=http://livekit.example.com:7880
|
|
|
|
# Voice off. The livekit service still runs until an override removes it.
|
|
#FLUXER_LIVEKIT_ENABLED=false
|
|
|
|
# Optional systems, each off unless configured.
|
|
#FLUXER_SMS_ENABLED=false
|
|
#FLUXER_STRIPE_ENABLED=false
|
|
#FLUXER_NCMEC_ENABLED=false
|
|
#FLUXER_CLAMAV_ENABLED=false
|
|
|
|
# Outside lookups, off unless turned on. The Tor exit list comes from
|
|
# onionoo.torproject.org and the breached password check asks
|
|
# api.pwnedpasswords.com.
|
|
#FLUXER_TOR_EXIT_LIST_ENABLED=true
|
|
#FLUXER_BREACHED_PASSWORD_CHECK_ENABLED=true
|
|
|
|
# The client address. Name the header your proxy actually writes, and turn the
|
|
# trust off when nothing sits in front.
|
|
#FLUXER_CLIENT_IP_HEADER_NAME=cf-connecting-ip
|
|
#FLUXER_TRUST_CLIENT_IP_HEADER=true
|
|
|
|
# How much the services write. trace, debug, info, warn, error or fatal.
|
|
#LOG_LEVEL=debug
|
|
|
|
FLUXER_S3_ACCESS_KEY=fluxer
|
|
FLUXER_S3_SECRET_KEY=CHANGE_ME
|
|
|
|
FLUXER_SUDO_MODE_SECRET=CHANGE_ME
|
|
FLUXER_CONNECTION_INITIATION_SECRET=CHANGE_ME
|
|
FLUXER_GATEWAY_RPC_AUTH_TOKEN=CHANGE_ME
|
|
FLUXER_ERLANG_COOKIE=CHANGE_ME
|
|
FLUXER_MEDIA_PROXY_SECRET_KEY=CHANGE_ME
|
|
FLUXER_MEDIA_PROXY_UPLOAD_RELAY_SECRET_BASE64=CHANGE_ME
|
|
FLUXER_ADMIN_SECRET_KEY_BASE=CHANGE_ME
|
|
FLUXER_ADMIN_OAUTH_CLIENT_SECRET=CHANGE_ME
|
|
|
|
# The token every service sends to NATS. The bundled NATS needs none, so this
|
|
# stays empty unless an override points at an external one.
|
|
#FLUXER_NATS_AUTH_TOKEN=
|
|
|
|
FLUXER_VAPID_PUBLIC_KEY=CHANGE_ME
|
|
FLUXER_VAPID_PRIVATE_KEY=CHANGE_ME
|
|
|
|
# Defaults to admin@ followed by FLUXER_DOMAIN. Set it if that mailbox does not
|
|
# exist.
|
|
#[email protected]
|
|
|
|
# Passkeys follow FLUXER_DOMAIN. Set these only if browsers use another host.
|
|
# Changing the RP ID invalidates every passkey registered against the old value.
|
|
#FLUXER_PASSKEY_RP_ID=chat.example.com
|
|
#FLUXER_PASSKEY_RP_NAME=Fluxer
|
|
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=https://chat.example.com
|
|
#FLUXER_PASSKEY_ADDITIONAL_ALLOWED_ORIGINS=http://chat.example.com:19080
|
|
|
|
# Notification jobs the push container holds at once, 1 to 1000000.
|
|
#FLUXER_PUSH_SERVICE_QUEUE_CAPACITY=10000
|
|
# Provider requests the push container sends at once, 1 to 65536.
|
|
#FLUXER_PUSH_SERVICE_SEND_CONCURRENCY=256
|
|
|
|
|
|
# Optional media policies, both off by default. See the operator docs.
|
|
#
|
|
# CORS limits which web origins may read media. A request with no Origin is
|
|
# always served. Add https://web.fluxer.app if people use the hosted client.
|
|
#
|
|
# Signatures make an attachment read need a signed URL, so a copied link stops
|
|
# working. Needs a secret from openssl rand -base64 32, first entry signs and
|
|
# every entry verifies.
|
|
#
|
|
# Each mode is off, report or enforce. Start at report. media-proxy reads these
|
|
# at start, so apply with docker compose up -d media-proxy.
|
|
#FLUXER_MEDIA_PROXY_CORS_MODE=enforce
|
|
#FLUXER_MEDIA_PROXY_CORS_ALLOWED_ORIGINS=https://chat.example.com,https://web.fluxer.app
|
|
#FLUXER_MEDIA_PROXY_ATTACHMENT_URL_SECRETS_BASE64=
|
|
#FLUXER_MEDIA_PROXY_ATTACHMENT_SIGNATURE_MODE=enforce
|
|
|
|
# Extra Content-Security-Policy sources, appended to the built-in ones. Set one
|
|
# only when a browser must reach an origin the defaults do not cover. Separate
|
|
# several with spaces or commas. The three values below are illustrations.
|
|
#FLUXER_CSP_EXTRA_DEFAULT_SRC=
|
|
#FLUXER_CSP_EXTRA_CONNECT_SRC=wss://livekit.example.com:7881
|
|
#FLUXER_CSP_EXTRA_IMG_SRC=https://cdn.example.com
|
|
#FLUXER_CSP_EXTRA_MEDIA_SRC=
|
|
#FLUXER_CSP_EXTRA_FONT_SRC=
|
|
#FLUXER_CSP_EXTRA_SCRIPT_SRC=https://analytics.example.com
|
|
#FLUXER_CSP_EXTRA_STYLE_SRC=
|
|
#FLUXER_CSP_EXTRA_FRAME_SRC=
|
|
#FLUXER_CSP_EXTRA_WORKER_SRC=
|
|
#FLUXER_CSP_EXTRA_MANIFEST_SRC=
|
|
|
|
# One report-uri for CSP violation reports. Empty leaves the directive off.
|
|
#FLUXER_CSP_REPORT_URI=
|
|
|
|
# Let the SSO provider resolve to a private address. Off by default, so a
|
|
# misconfigured provider URL cannot reach internal services. Turn it on only for
|
|
# a provider on your own network.
|
|
#FLUXER_SSO_ALLOW_PRIVATE_ADDRESSES=true
|
|
|
|
# These reach both LiveKit and the api. Change them together.
|
|
LIVEKIT_API_KEY=fluxer
|
|
LIVEKIT_API_SECRET=CHANGE_ME
|
|
|
|
# The URL browsers use for voice signalling. Built from the public origin plus
|
|
# /livekit. Set it only when LiveKit is served from another host.
|
|
#FLUXER_LIVEKIT_URL=
|
|
|
|
# Media ports. LiveKit advertises these, so forward the same numbers.
|
|
#FLUXER_LIVEKIT_TCP_PORT=7881
|
|
#FLUXER_LIVEKIT_UDP_PORT=7882
|
|
|
|
# LiveKit finds its public address over STUN. A host that cannot reach one stops
|
|
# with "could not resolve external IP", so set the address by hand instead, or
|
|
# point STUN elsewhere.
|
|
#FLUXER_LIVEKIT_USE_EXTERNAL_IP=false
|
|
#FLUXER_LIVEKIT_NODE_IP=203.0.113.10
|
|
#FLUXER_LIVEKIT_STUN_PRIMARY=stun.l.google.com:19302
|
|
#FLUXER_LIVEKIT_STUN_SECONDARY=stun1.l.google.com:19302
|
|
|
|
FLUXER_KLIPY_API_KEY=
|
|
|
|
FLUXER_EMAIL_ENABLED=false
|
|
FLUXER_EMAIL_PROVIDER=none
|
|
FLUXER_EMAIL_FROM_EMAIL=[email protected]
|
|
FLUXER_EMAIL_FROM_NAME=Fluxer
|
|
FLUXER_EMAIL_APP_BASE_URL=
|
|
FLUXER_EMAIL_SMTP_HOST=
|
|
FLUXER_EMAIL_SMTP_PORT=587
|
|
FLUXER_EMAIL_SMTP_USERNAME=
|
|
FLUXER_EMAIL_SMTP_PASSWORD=
|
|
FLUXER_EMAIL_SMTP_SECURE=true
|
|
|
|
FLUXER_CAPTCHA_ENABLED=false
|
|
FLUXER_CAPTCHA_PROVIDER=none
|
|
FLUXER_CAPTCHA_HCAPTCHA_SITE_KEY=
|
|
FLUXER_CAPTCHA_HCAPTCHA_SECRET_KEY=
|
|
FLUXER_CAPTCHA_TURNSTILE_SITE_KEY=
|
|
FLUXER_CAPTCHA_TURNSTILE_SECRET_KEY=
|
|
FLUXER_DISCOVERY_ENABLED=true
|
|
|
|
# Container memory. These are ceilings, not allocations, and the defaults suit a
|
|
# 16 GB host. The reservations bias the kernel away from reclaiming from services
|
|
# whose death takes the instance down. Lower the limits on a smaller host.
|
|
#FLUXER_CADDY_MEMORY_LIMIT=256mb
|
|
#FLUXER_POSTGRES_MEMORY_LIMIT=5gb
|
|
#FLUXER_POSTGRES_MEMORY_RESERVATION=3gb
|
|
#FLUXER_VALKEY_MEMORY_LIMIT=256mb
|
|
#FLUXER_NATS_MEMORY_LIMIT=256mb
|
|
#FLUXER_MEILISEARCH_MEMORY_LIMIT=768mb
|
|
#FLUXER_SEAWEEDFS_MEMORY_LIMIT=2gb
|
|
#FLUXER_SEAWEEDFS_INIT_MEMORY_LIMIT=128mb
|
|
#FLUXER_LIVEKIT_MEMORY_LIMIT=512mb
|
|
#FLUXER_API_MEMORY_LIMIT=2560mb
|
|
#FLUXER_API_MEMORY_RESERVATION=1gb
|
|
#FLUXER_WORKER_MEMORY_LIMIT=2560mb
|
|
#FLUXER_WORKER_MEMORY_RESERVATION=1gb
|
|
#FLUXER_GATEWAY_MEMORY_LIMIT=1gb
|
|
#FLUXER_GATEWAY_MEMORY_RESERVATION=384mb
|
|
#FLUXER_MEDIA_PROXY_MEMORY_LIMIT=512mb
|
|
#FLUXER_PUSH_MEMORY_LIMIT=256mb
|
|
#FLUXER_STATIC_PROXY_MEMORY_LIMIT=256mb
|
|
#FLUXER_APP_PROXY_MEMORY_LIMIT=256mb
|
|
#FLUXER_SNOWFLAKES_MEMORY_LIMIT=128mb
|
|
#FLUXER_SNOWFLAKES_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_USERS_MEMORY_LIMIT=128mb
|
|
#FLUXER_USERS_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_GIFS_MEMORY_LIMIT=128mb
|
|
#FLUXER_GIFS_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_MESSAGES_MEMORY_LIMIT=128mb
|
|
#FLUXER_MESSAGES_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_UNFURL_MEMORY_LIMIT=128mb
|
|
#FLUXER_UNFURL_SHARD_MEMORY_LIMIT=256mb
|
|
#FLUXER_ADMIN_MEMORY_LIMIT=256mb
|
|
|
|
# Meilisearch indexing memory. Keep it well under the container limit above.
|
|
#FLUXER_MEILISEARCH_MAX_INDEXING_MEMORY=384mb
|
|
|
|
# SeaweedFS heap ceiling. Go cannot see the container limit, so without this an
|
|
# upload burst gets the container OOM-killed. Keep it near three quarters of
|
|
# FLUXER_SEAWEEDFS_MEMORY_LIMIT and raise both together.
|
|
#FLUXER_SEAWEEDFS_GOMEMLIMIT=1536MiB
|
|
|
|
# Node sizes its heap from the container limit by default. Leave these unset
|
|
# unless you need to pin it. A heap ceiling above the container limit gets the
|
|
# container OOM-killed instead of reporting a heap error.
|
|
#FLUXER_API_NODE_HEAP_MB=1792
|
|
#FLUXER_WORKER_NODE_HEAP_MB=1792
|
|
|
|
# Bundled Postgres tuning. Keep it consistent with the memory limit above. This
|
|
# is the server setting, not the per-service pool sizes.
|
|
#FLUXER_POSTGRES_SERVER_MAX_CONNECTIONS=150
|
|
#FLUXER_POSTGRES_SHARED_BUFFERS=512MB
|
|
#FLUXER_POSTGRES_EFFECTIVE_CACHE_SIZE=2GB
|
|
#FLUXER_POSTGRES_WORK_MEM=8MB
|
|
#FLUXER_POSTGRES_MAINTENANCE_WORK_MEM=256MB
|
|
#FLUXER_POSTGRES_AUTOVACUUM_WORK_MEM=128MB
|
|
#FLUXER_POSTGRES_SHM_SIZE=1gb
|
|
|
|
# The bundled Valkey holds durable state as well as cache, so it runs with an
|
|
# append-only file and with noeviction, which fails an over-limit write instead
|
|
# of dropping queued work. Change the policy only if that state lives elsewhere.
|
|
#FLUXER_VALKEY_MAXMEMORY=192mb
|
|
#FLUXER_VALKEY_MAXMEMORY_POLICY=noeviction
|
|
|
|
# The gateway derives its scheduler count from the CPU quota, clamped here. One
|
|
# scheduler lets a single blocking operation stall every websocket on the node.
|
|
#FLUXER_ERLANG_SCHEDULERS_MIN=2
|
|
#FLUXER_ERLANG_SCHEDULERS_MAX=16
|
|
|
|
# In-flight request ceiling for the users and messages routers and their shards.
|
|
# One value replaces the built-in default on all of them, so size it for the
|
|
# busiest. Too low a value rejects requests rather than slowing them, and the api
|
|
# turns that into a 503.
|
|
#FLUXER_SVC_MAX_CONCURRENT_REQUESTS=192
|
|
|
|
# Named prepared statements need a session that outlives the transaction, so set
|
|
# this to false behind a transaction-pooling connection pooler. The bundled
|
|
# compose talks to Postgres directly, where the default is correct.
|
|
#FLUXER_POSTGRES_PREPARED_STATEMENTS=true
|
|
|
|
# How long a client may take to send a request. The header timeout covers the
|
|
# request line and headers, the request timeout the whole exchange, and the first
|
|
# is clamped down to the second. Milliseconds, 1000 to 3600000.
|
|
#FLUXER_API_HEADERS_TIMEOUT_MS=30000
|
|
#FLUXER_API_REQUEST_TIMEOUT_MS=120000
|