docker-compose.arm64.build.yml builds the image for linux/arm64 from source and tags it for the registry (docker compose ... build, then push); it can also build and run directly on an arm64 machine. Building on x86 works through QEMU, with the one-time binfmt setup noted in the file. docker-compose.arm64.yml runs that published image on the arm64 machine with no build there. Both use the same image name and an :arm64 tag, kept apart from the default image so the existing docker-compose.yml is untouched. IMAGE_REPO and ARM64_TAG (in .env or the shell) switch the registry or pin a release tag. Also adds a .dockerignore, which the repo lacked. The Dockerfile runs COPY . . after npm ci, so a local build from a developer checkout would overwrite the container's node_modules with the host's (Windows/x86 binaries) and break the build -- most visibly when cross-building for arm64. It also keeps .env, data/ and .git out of the build context. libsql's arm64 musl binary is present in package-lock.json, and the Dockerfile's node:22-alpine base is multi-arch. Not built or run: Docker isn't available in this environment, so neither the emulated arm64 build nor the compose files themselves have been executed. The YAML was only checked for whitespace and against the runtime section of docker-compose.yml. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
32 lines
1.4 KiB
Bash
32 lines
1.4 KiB
Bash
# Public URL the app is reachable at (used for OIDC redirect_uri and cookie behavior).
|
|
APP_BASE_URL=https://homelab.example.lan
|
|
|
|
# Random long string used to sign session cookies. Generate with:
|
|
# node -e "console.log(require('crypto').randomBytes(32).toString('hex'))"
|
|
SESSION_SECRET=change-me-to-a-random-64-char-hex-string
|
|
|
|
# 32-byte (64 hex char) key used to encrypt stored integration API tokens at
|
|
# rest (AES-256-GCM). Generate the same way as SESSION_SECRET. Losing/changing
|
|
# this key makes previously-stored integration credentials unreadable.
|
|
CREDENTIALS_ENCRYPTION_KEY=change-me-to-a-random-64-char-hex-string
|
|
|
|
# Port docker-compose publishes on the host (container always listens on 3000).
|
|
HOST_PORT=3000
|
|
|
|
# Optional, for the arm64 compose files (docker-compose.arm64*.yml): registry image and tag.
|
|
#IMAGE_REPO=gitea.labsconnect.se/bobban/homelabmanager-homelab-manager
|
|
#ARM64_TAG=arm64
|
|
|
|
# --- Authentik OIDC application/provider ---
|
|
# Create an OAuth2/OIDC "Provider" in Authentik with:
|
|
# Redirect URI: <APP_BASE_URL>/auth/callback
|
|
# Scopes: openid, email, profile
|
|
# then create an "Application" using that provider, and assign the users/groups
|
|
# who should be able to sign in. Copy the provider's values below.
|
|
AUTHENTIK_ISSUER_URL=https://authentik.example.lan/application/o/homelab-manager/
|
|
AUTHENTIK_CLIENT_ID=
|
|
AUTHENTIK_CLIENT_SECRET=
|
|
|
|
# Notification channels (Gotify, ntfy, SMTP, webhook) are configured in-app
|
|
# under Settings, not here.
|