140 lines
5.6 KiB
Bash
140 lines
5.6 KiB
Bash
# Bulwark Webmail — Production Configuration
|
||
# Copy this file to .env.local and fill in your values.
|
||
# For development with the built-in mock server, see .env.dev.example instead.
|
||
|
||
# =============================================================================
|
||
# JMAP Server (required)
|
||
# =============================================================================
|
||
|
||
# App name displayed in the UI
|
||
APP_NAME=Bulwark Webmail
|
||
|
||
# URL of your JMAP-compatible mail server (required)
|
||
JMAP_SERVER_URL=https://your-jmap-server.com
|
||
|
||
# =============================================================================
|
||
# Stalwart Mail Server Integration
|
||
# =============================================================================
|
||
|
||
# Enable Stalwart-specific features (password change, sieve filters, etc.)
|
||
# Set to "false" to disable if using a non-Stalwart JMAP server.
|
||
# STALWART_FEATURES=true
|
||
|
||
# If your reverse proxy doesn't forward Stalwart management API paths
|
||
# (/api/account/*, /api/principal/*), set this to the URL where Stalwart's
|
||
# HTTP listener is directly reachable. Defaults to JMAP_SERVER_URL if not set.
|
||
# STALWART_API_URL=https://admin.example.com
|
||
|
||
# =============================================================================
|
||
# OAuth / OpenID Connect (optional)
|
||
# =============================================================================
|
||
|
||
# Set to "true" to use OAuth instead of basic JMAP authentication
|
||
# OAUTH_ENABLED=true
|
||
|
||
# Set to "true" to only allow OAuth login (hides username/password form)
|
||
# Requires OAUTH_ENABLED=true
|
||
# OAUTH_ONLY=true
|
||
|
||
# OAuth client ID registered with your identity provider
|
||
# OAUTH_CLIENT_ID=your-client-id
|
||
|
||
# OAuth client secret (server-side only, never exposed to the browser)
|
||
# OAUTH_CLIENT_SECRET=your-client-secret
|
||
|
||
# OpenID Connect issuer URL for discovery
|
||
# OAUTH_ISSUER_URL=https://your-idp.example.com
|
||
|
||
# =============================================================================
|
||
# Session & Security
|
||
# =============================================================================
|
||
|
||
# Secret key for encrypting "Remember me" sessions and settings sync data.
|
||
# Required for both "Remember me" and settings sync features.
|
||
# Generate with: openssl rand -base64 32
|
||
# SESSION_SECRET=your-secret-key-here
|
||
|
||
# =============================================================================
|
||
# Settings Sync
|
||
# =============================================================================
|
||
|
||
# Enable server-side settings persistence (requires SESSION_SECRET).
|
||
# When enabled, user settings are encrypted and stored on the server,
|
||
# allowing them to sync across browsers and devices.
|
||
# SETTINGS_SYNC_ENABLED=true
|
||
|
||
# Directory for storing encrypted settings files (default: ./data/settings).
|
||
# For Docker, mount a persistent volume at this path.
|
||
# SETTINGS_DATA_DIR=./data/settings
|
||
|
||
# =============================================================================
|
||
# Server Listen Address
|
||
# =============================================================================
|
||
|
||
# Hostname the server binds to (default: 0.0.0.0)
|
||
# Set to "::" for dual-stack
|
||
# HOSTNAME=0.0.0.0
|
||
|
||
# Port the server listens on (default: 3000)
|
||
# PORT=3000
|
||
|
||
# =============================================================================
|
||
# Logging
|
||
# =============================================================================
|
||
|
||
# Log format: "text" (colored, human-readable) or "json" (structured, for log aggregation)
|
||
# LOG_FORMAT=text
|
||
|
||
# Log level: "error", "warn", "info", or "debug"
|
||
# LOG_LEVEL=info
|
||
|
||
# =============================================================================
|
||
# Branding (all optional)
|
||
# =============================================================================
|
||
|
||
# Custom favicon for the browser tab.
|
||
# Supported formats: SVG (recommended), PNG, ICO.
|
||
# Recommended size: 32×32px minimum, 512×512px maximum (or SVG for best scaling).
|
||
# Can be an absolute URL or a path relative to the public/ directory.
|
||
# Defaults to the Bulwark favicon if not set.
|
||
# FAVICON_URL=/branding/my-favicon.svg
|
||
|
||
# Custom logos for the sidebar (shown in the main app after login).
|
||
# Supported formats: SVG (recommended), PNG, WebP.
|
||
# Recommended size: min 24×24px, max 128×128px
|
||
# Can be absolute URLs or paths relative to the public/ directory.
|
||
# If not set, no logo is shown in the sidebar.
|
||
# APP_LOGO_LIGHT_URL=/branding/my-logo-color.svg
|
||
# APP_LOGO_DARK_URL=/branding/my-logo-white.svg
|
||
|
||
# Custom logo images for the login page.
|
||
# Supported formats: SVG (recommended), PNG, WebP.
|
||
# Recommended size: min 32×32px, max 512×512px
|
||
# Can be absolute URLs or paths relative to the public/ directory.
|
||
# Light mode logo (shown on light backgrounds), defaults to Bulwark logo.
|
||
LOGIN_LOGO_LIGHT_URL=/branding/Bulwark_Logo_Color.svg
|
||
#
|
||
# Dark mode logo (shown on dark backgrounds), defaults to Bulwark white logo.
|
||
LOGIN_LOGO_DARK_URL=/branding/Bulwark_Logo_Color.svg
|
||
|
||
# Company or organization name displayed above the version on the login page
|
||
LOGIN_COMPANY_NAME=Bulwark Webmail
|
||
|
||
# URL for the imprint/legal notice link on the login page
|
||
# LOGIN_IMPRINT_URL=https://example.com/imprint
|
||
|
||
# URL for the privacy policy link on the login page
|
||
# LOGIN_PRIVACY_POLICY_URL=https://example.com/privacy
|
||
|
||
# URL for the company website link on the login page
|
||
LOGIN_WEBSITE_URL=https://bulwarkmail.org
|
||
|
||
# =============================================================================
|
||
# Legacy Build-time Variables (still supported as fallback)
|
||
# =============================================================================
|
||
# These are baked into the bundle at build time. The runtime variables above
|
||
# take priority when both are set.
|
||
#
|
||
# NEXT_PUBLIC_APP_NAME=Bulwark Webmail
|
||
# NEXT_PUBLIC_JMAP_SERVER_URL=https://your-jmap-server.com
|