# Bulwark Webmail — Production Configuration # Copy this file to .env.local and fill in your values. # For development with the built-in mock server, see .env.dev.example instead. # ============================================================================= # JMAP Server (required) # ============================================================================= # App name displayed in the UI APP_NAME=Bulwark Webmail # URL of your JMAP-compatible mail server (required) JMAP_SERVER_URL=https://your-jmap-server.com # ============================================================================= # Stalwart Mail Server Integration # ============================================================================= # Enable Stalwart-specific features (password change, sieve filters, etc.) # Set to "false" to disable if using a non-Stalwart JMAP server. # STALWART_FEATURES=true # If your reverse proxy doesn't forward Stalwart management API paths # (/api/account/*, /api/principal/*), set this to the URL where Stalwart's # HTTP listener is directly reachable. Defaults to JMAP_SERVER_URL if not set. # STALWART_API_URL=https://admin.example.com # ============================================================================= # OAuth / OpenID Connect (optional) # ============================================================================= # Set to "true" to use OAuth instead of basic JMAP authentication # OAUTH_ENABLED=true # Set to "true" to only allow OAuth login (hides username/password form) # Requires OAUTH_ENABLED=true # OAUTH_ONLY=true # OAuth client ID registered with your identity provider # OAUTH_CLIENT_ID=your-client-id # OAuth client secret (server-side only, never exposed to the browser) # OAUTH_CLIENT_SECRET=your-client-secret # OpenID Connect issuer URL for discovery # OAUTH_ISSUER_URL=https://your-idp.example.com # ============================================================================= # Session & Security # ============================================================================= # Secret key for encrypting "Remember me" sessions and settings sync data. # Required for both "Remember me" and settings sync features. # Generate with: openssl rand -base64 32 # SESSION_SECRET=your-secret-key-here # ============================================================================= # Settings Sync # ============================================================================= # Enable server-side settings persistence (requires SESSION_SECRET). # When enabled, user settings are encrypted and stored on the server, # allowing them to sync across browsers and devices. # SETTINGS_SYNC_ENABLED=true # Directory for storing encrypted settings files (default: ./data/settings). # For Docker, mount a persistent volume at this path. # SETTINGS_DATA_DIR=./data/settings # ============================================================================= # Logging # ============================================================================= # Log format: "text" (colored, human-readable) or "json" (structured, for log aggregation) # LOG_FORMAT=text # Log level: "error", "warn", "info", or "debug" # LOG_LEVEL=info # ============================================================================= # Login Page Customization (all optional) # ============================================================================= # Custom logo images for the login page (PNG, SVG, etc.) # Can be absolute URLs or paths relative to the public/ directory. # Light mode logo (shown on light backgrounds), defaults to Bulwark logo. LOGIN_LOGO_LIGHT_URL=/branding/Bulwark_Logo_Color.svg # # Dark mode logo (shown on dark backgrounds), defaults to Bulwark white logo. LOGIN_LOGO_DARK_URL=/branding/Bulwark_Logo_Color.svg # Company or organization name displayed above the version on the login page LOGIN_COMPANY_NAME=Bulwark Webmail # URL for the imprint/legal notice link on the login page # LOGIN_IMPRINT_URL=https://example.com/imprint # URL for the privacy policy link on the login page # LOGIN_PRIVACY_POLICY_URL=https://example.com/privacy # URL for the company website link on the login page LOGIN_WEBSITE_URL=https://bulwarkmail.org # ============================================================================= # Legacy Build-time Variables (still supported as fallback) # ============================================================================= # These are baked into the bundle at build time. The runtime variables above # take priority when both are set. # # NEXT_PUBLIC_APP_NAME=Bulwark Webmail # NEXT_PUBLIC_JMAP_SERVER_URL=https://your-jmap-server.com