Skip to content

Configuration reference ​

The installer writes the production environment file. For local development, copy .env.example and change values before exposing the stack outside your machine.

Control plane ​

VariablePurposeDefault
HTTP_PORTStandard Caddy HTTP ingress port (80 in VPS installs; 8888 locally)8888
RECOVERY_HTTP_PORTSecondary HTTP port for temporary IP and recovery access in the VPS topology3030
HTTPS_PORTPublic Caddy HTTPS port8443
PUBLIC_URLComplete external control-panel URLhttp://localhost:8888
CONTROL_HOSTSSpace-separated control-panel host allowlistlocalhost
POSTGRES_PASSWORDBundled control-plane database passworddevelopment placeholder
JWT_SECRETSession signing key, at least 32 charactersdevelopment placeholder
ENCRYPTION_KEYStored-secret encryption key, at least 32 charactersdevelopment placeholder
COOKIE_SECURESend the session cookie only over HTTPSfalse
DOKYR_BUILDKIT_HOSTBuildKit daemon used by Auto buildstcp://buildkit:1234
DOKYR_BUILDKIT_CACHE_REFOptional registry cache reference; supports {service}empty
DOKYR_RAILPACK_FRONTENDBuildKit frontend used for Railpack plansghcr.io/railwayapp/railpack-frontend:latest

The VPS installer exposes Caddy on standard HTTP port 80 for domain traffic and ACME challenges, while retaining port 3030 for temporary IP and recovery access. It detects SERVER_IP, derives the temporary PUBLIC_URL from RECOVERY_HTTP_PORT, and generates POSTGRES_PASSWORD, JWT_SECRET, and ENCRYPTION_KEY. These variables remain available for advanced automation and recovery; they are not interactive installation questions. A permanent control-panel domain is stored from Infrastructure → Domains after the owner account is created.

Platform updates ​

VariablePurposeDefault
DOKYR_IMAGEImage used by the Compose serviceghcr.io/azayr/dokyr:latest
DOKYR_REGISTRY_IMAGERegistry repository checked for updatesghcr.io/azayr/dokyr
DOKYR_UPDATE_CHANNELMutable channel resolved to an immutable digestlatest

Registry ​

VariablePurposeDefault
REGISTRY_HOSTSFirst-start compatibility hostnameregistry.invalid
REGISTRY_STORAGEfilesystem or s3filesystem
REGISTRY_HTTP_RELATIVEURLSKeep upload redirects relative behind proxiestrue
REGISTRY_S3_REGIONS3 regionempty
REGISTRY_S3_BUCKETS3 bucketempty
REGISTRY_S3_ENDPOINTCustom S3-compatible endpointempty
REGISTRY_S3_FORCEPATHSTYLEUse path-style bucket addressingfalse

Integrations and mail ​

GitHub applications are created interactively through the App Manifest flow and do not require static client credentials. GitLab OAuth uses GITLAB_CLIENT_ID, GITLAB_CLIENT_SECRET, and optionally GITLAB_BASE_URL. Gitea OAuth uses GITEA_CLIENT_ID, GITEA_CLIENT_SECRET, and GITEA_BASE_URL; the base URL may be an HTTPS production origin or an explicit http:// local-network origin for development.

Dokyr's own notification SMTP settings can be bootstrapped once with the SMTP_* variables. After the complete configuration is imported, PostgreSQL becomes the source of truth and later Compose restarts do not overwrite values saved in the interface.

The bundled Stalwart service uses STALWART_* and MAIL_STALWART_* variables. The installer generates its passwords. Configure the public mail hostname from Infrastructure → Mail rather than editing the compatibility variables by hand.

See the repository's .env.example for the complete list and comments.

Open source infrastructure, operated on your terms.