-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy path.env.example
More file actions
38 lines (32 loc) · 1.63 KB
/
Copy path.env.example
File metadata and controls
38 lines (32 loc) · 1.63 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
DATABASE_URL=sqlite:tus.db
STORAGE_DIR=uploads
BASE_URL=http://localhost:3000
BIND_ADDR=0.0.0.0:3000
MAX_UPLOAD_BYTES=107374182400
ABANDONED_AFTER_HOURS=24
CLEANUP_INTERVAL_SECS=3600
RUST_LOG=info
# Required on first startup — the password for the initial admin account.
# Once created, this value is no longer read; change the password via the dashboard.
ADMIN_PASSWORD=changeme
# Session cookie Secure flag. Auto-enables when BASE_URL starts with https://.
# Override with COOKIE_SECURE=false for local testing over HTTP. Otherwise omit.
# COOKIE_SECURE=true
# Comma-separated CIDRs of trusted reverse proxies whose X-Forwarded-For header is
# honoured for real-IP attribution (rate limiting, audit log, login throttle).
# When unset, forwarded headers are ignored and the TCP peer address is used directly.
# Set this to your proxy/Docker network range when running behind nginx/Caddy/Traefik.
# TRUSTED_PROXIES=10.0.0.0/8,172.16.0.0/12,192.168.0.0/16
# Login brute-force protection (in-memory, resets on restart).
# LOGIN_MAX_ATTEMPTS=10
# LOGIN_LOCKOUT_SECS=900
# Global API key for the legacy /files TUS endpoint and /metrics Prometheus scrape endpoint.
# Dashboard login and session APIs use session cookies instead. Leave unset to disable (local/dev only).
# API_KEY=your-secret-key-here
# OIDC / SSO (OpenID Connect authorization code flow with PKCE).
# Set OIDC_ISSUER_URL to enable the "Sign in with SSO" button on the login page.
# OIDC_ISSUER_URL=https://accounts.google.com
# OIDC_CLIENT_ID=your-client-id
# OIDC_CLIENT_SECRET=your-client-secret
# OIDC_REDIRECT_URI=https://tuskar.example.com/api/auth/oidc/callback
# OIDC_DEFAULT_ROLE=viewer