# Required: a long random secret for signing JWTs. # Generate with: openssl rand -base64 48 SECRET_KEY=change-me-to-a-long-random-string # Host directory where stack folders (compose.yaml + .env) are stored. # This MUST be the same path on the host and is bind-mounted into the backend. STACKS_HOST_DIR=./data/stacks # Allowed CORS origin(s) for the API (comma separated). The bundled frontend # proxies /api, so this only matters if you call the API from another origin. CORS_ORIGINS=http://localhost:5009 # Optional: comma-separated generic JSON webhook URLs that receive every event. # Richer per-destination webhooks (ntfy/Discord/Slack/Gotify, per-event) are # managed from Settings → Notifications in the UI. NOTIFY_WEBHOOKS= # Throwaway image used to read/write named-volume contents during backups. BACKUP_HELPER_IMAGE=alpine:latest # File browser (sidebar) + volume host-path picker. # ALLOWED_BROWSE_ROOTS: comma-separated paths the browser may reach (sandbox). # HOST_ROOT_PREFIX: where the host filesystem is mounted inside the backend # container. Leave empty to browse the container's own filesystem. To browse # the real host, uncomment the "/:/host_root" volume in docker-compose.yml and # set HOST_ROOT_PREFIX=/host_root here (mount without :ro to allow edits). ALLOWED_BROWSE_ROOTS=/,/mnt,/media,/srv,/opt HOST_ROOT_PREFIX=