# Required: a long random secret for signing JWTs. # Generate with: openssl rand -base64 48 SECRET_KEY=change-me-to-a-long-random-string # Host directory where stack folders (compose.yaml + .env) are stored. # It MUST be the same path as STACKS_DIR inside the container (/opt/stacks): # compose runs in the backend container and resolves a stack's relative bind # mounts (./config) against the *container* path, so the daemon creates those # data directories at that path on the host. With a different host path here, # every stack's data lands outside StackPilot's view — the file browser and the # editor won't see it (backups capture it either way, via a helper container). STACKS_HOST_DIR=/opt/stacks # Allowed CORS origin(s) for the API (comma separated). The bundled frontend # proxies /api, so this only matters if you call the API from another origin. CORS_ORIGINS=http://localhost:5009 # Optional: comma-separated generic JSON webhook URLs that receive every event. # Richer per-destination webhooks (ntfy/Discord/Slack/Gotify, per-event) are # managed from Settings → Notifications in the UI. NOTIFY_WEBHOOKS= # Throwaway image used to read/write named-volume contents during backups. BACKUP_HELPER_IMAGE=alpine:latest # File browser (sidebar) + volume host-path picker. Admin-only. # ALLOWED_BROWSE_ROOTS: comma-separated paths the browser may reach (sandbox). # A single "/" in this list disables the sandbox -- it makes every path # allowed. StackPilot's own DATA_DIR is refused regardless of this setting. # HOST_ROOT_PREFIX: where the host filesystem is mounted inside the backend # container. Leave empty to browse the container's own filesystem. To browse # the real host, uncomment the "/:/host_root" volume in docker-compose.yml and # set HOST_ROOT_PREFIX=/host_root here (mount without :ro to allow edits). ALLOWED_BROWSE_ROOTS=/mnt,/media,/srv,/opt,/home HOST_ROOT_PREFIX=