|
| 1 | +# Passwall Server Environment Variables |
| 2 | +# Copy this file to .env and fill in your actual values |
| 3 | +# NEVER commit .env to git! |
| 4 | + |
| 5 | +# =================================== |
| 6 | +# SERVER CONFIGURATION |
| 7 | +# =================================== |
| 8 | +SERVER_PORT=3625 |
| 9 | +SERVER_ENV=production |
| 10 | +SERVER_DOMAIN=https://your-domain.com |
| 11 | +SERVER_TIMEOUT=30 |
| 12 | + |
| 13 | +# CRITICAL: Generate a strong random secret for JWT tokens |
| 14 | +# Example: openssl rand -base64 64 |
| 15 | +SERVER_SECRET=your-super-secret-jwt-key-here-use-openssl-rand-base64-64 |
| 16 | + |
| 17 | +# CRITICAL: Generate a strong passphrase for encryption |
| 18 | +# Example: openssl rand -base64 32 |
| 19 | +SERVER_PASSPHRASE=your-encryption-passphrase-here |
| 20 | + |
| 21 | +# Token expiration durations (examples: 15m, 1h, 24h, 7d) |
| 22 | +SERVER_ACCESS_TOKEN_EXPIRE_DURATION=15m |
| 23 | +SERVER_REFRESH_TOKEN_EXPIRE_DURATION=24h |
| 24 | + |
| 25 | +# Generated password length for password manager |
| 26 | +SERVER_GENERATED_PASSWORD_LENGTH=16 |
| 27 | + |
| 28 | +# =================================== |
| 29 | +# DATABASE CONFIGURATION |
| 30 | +# =================================== |
| 31 | +DATABASE_NAME=passwall |
| 32 | +DATABASE_USERNAME=postgres |
| 33 | +DATABASE_PASSWORD=your-database-password |
| 34 | +DATABASE_HOST=localhost |
| 35 | +DATABASE_PORT=5432 |
| 36 | +DATABASE_DBMS=postgres |
| 37 | +DATABASE_SSL_MODE=disable |
| 38 | +DATABASE_LOG_MODE=false |
| 39 | + |
| 40 | +# =================================== |
| 41 | +# EMAIL CONFIGURATION |
| 42 | +# =================================== |
| 43 | +# SMTP Settings |
| 44 | +EMAIL_HOST=smtp.example.com |
| 45 | +EMAIL_PORT=587 |
| 46 | +EMAIL_USERNAME=your-email@example.com |
| 47 | +EMAIL_PASSWORD=your-email-password |
| 48 | +EMAIL_FROM_EMAIL=no-reply@passwall.io |
| 49 | +EMAIL_FROM_NAME=Passwall |
| 50 | +EMAIL_API_KEY=your-email-api-key-if-needed |
| 51 | + |
| 52 | +# =================================== |
| 53 | +# BACKUP CONFIGURATION |
| 54 | +# =================================== |
| 55 | +BACKUP_FOLDER=./store/backup |
| 56 | +BACKUP_ROTATION=7 |
| 57 | +BACKUP_PERIOD=1440 |
| 58 | + |
| 59 | +# =================================== |
| 60 | +# SECURITY NOTES |
| 61 | +# =================================== |
| 62 | +# 1. Generate strong random secrets: |
| 63 | +# - JWT Secret: openssl rand -base64 64 |
| 64 | +# - Passphrase: openssl rand -base64 32 |
| 65 | +# |
| 66 | +# 2. Use environment variables in production |
| 67 | +# |
| 68 | +# 3. Enable SSL/TLS in production: |
| 69 | +# - DATABASE_SSL_MODE=require |
| 70 | +# - Use HTTPS domain |
| 71 | +# |
| 72 | +# 4. Change all default passwords |
| 73 | +# |
| 74 | +# 5. Revoke and regenerate email API keys if compromised |
0 commit comments