202 lines
8.6 KiB
Bash
202 lines
8.6 KiB
Bash
# Bulwark Webmail — Production Configuration
|
||
# Copy this file to .env.local and fill in your values.
|
||
# For development with the built-in mock server, see .env.dev.example instead.
|
||
|
||
# =============================================================================
|
||
# JMAP Server (required)
|
||
# =============================================================================
|
||
|
||
# App name displayed in the UI, browser tab title, and PWA manifest.
|
||
APP_NAME=Bulwark Webmail
|
||
|
||
# URL of your JMAP-compatible mail server (required unless ALLOW_CUSTOM_JMAP_ENDPOINT is set)
|
||
JMAP_SERVER_URL=https://your-jmap-server.com
|
||
|
||
# Allow users to specify a custom JMAP server URL on the login form.
|
||
# When enabled, a "JMAP Server" field appears on the login page.
|
||
# Users can connect to any JMAP-compatible server.
|
||
# NOTE: External JMAP servers must include this domain in their CORS
|
||
# Access-Control-Allow-Origin header, or browser requests will be blocked.
|
||
# ALLOW_CUSTOM_JMAP_ENDPOINT=true
|
||
|
||
# =============================================================================
|
||
# Stalwart Mail Server Integration
|
||
# =============================================================================
|
||
|
||
# Enable Stalwart-specific features (password change, sieve filters, etc.)
|
||
# Set to "false" to disable if using a non-Stalwart JMAP server.
|
||
# STALWART_FEATURES=true
|
||
|
||
# If your reverse proxy doesn't forward Stalwart management API paths
|
||
# (/api/account/*, /api/principal/*), set this to the URL where Stalwart's
|
||
# HTTP listener is directly reachable. Defaults to JMAP_SERVER_URL if not set.
|
||
# STALWART_API_URL=https://admin.example.com
|
||
|
||
# =============================================================================
|
||
# OAuth / OpenID Connect (optional)
|
||
# =============================================================================
|
||
|
||
# Set to "true" to use OAuth instead of basic JMAP authentication
|
||
# OAUTH_ENABLED=true
|
||
|
||
# Set to "true" to only allow OAuth login (hides username/password form)
|
||
# Requires OAUTH_ENABLED=true
|
||
# OAUTH_ONLY=true
|
||
|
||
# OAuth client ID registered with your identity provider
|
||
# OAUTH_CLIENT_ID=your-client-id
|
||
|
||
# OAuth client secret (server-side only, never exposed to the browser)
|
||
# OAUTH_CLIENT_SECRET=your-client-secret
|
||
# Alternatively, you can specify the path to a file containing the OAuth client secret.
|
||
# OAUTH_CLIENT_SECRET_FILE=/oauth-client-secret
|
||
|
||
# OpenID Connect issuer URL for discovery
|
||
# OAUTH_ISSUER_URL=https://your-idp.example.com
|
||
|
||
# =============================================================================
|
||
# Session & Security
|
||
# =============================================================================
|
||
|
||
# Secret key for encrypting "Remember me" sessions and settings sync data.
|
||
# Required for both "Remember me" and settings sync features.
|
||
# Generate with: openssl rand -base64 32
|
||
# SESSION_SECRET=your-secret-key-here
|
||
# Alternatively, you can specify the path to a file containing the session secret.
|
||
# SESSION_SECRET_FILE=/session-secret
|
||
|
||
# =============================================================================
|
||
# Settings Sync
|
||
# =============================================================================
|
||
|
||
# Enable server-side settings persistence (requires SESSION_SECRET).
|
||
# When enabled, user settings are encrypted and stored on the server,
|
||
# allowing them to sync across browsers and devices.
|
||
# SETTINGS_SYNC_ENABLED=true
|
||
|
||
# Directory for storing encrypted settings files (default: ./data/settings).
|
||
# For Docker, the working directory is /app, so the default resolves to
|
||
# /app/data/settings — mount a persistent volume there:
|
||
# volumes:
|
||
# - bulwark-settings:/app/data/settings
|
||
# SETTINGS_DATA_DIR=./data/settings
|
||
|
||
# =============================================================================
|
||
# Server Listen Address
|
||
# =============================================================================
|
||
|
||
# Hostname the server binds to (default: 0.0.0.0)
|
||
# Set to "::" for dual-stack
|
||
# HOSTNAME=0.0.0.0
|
||
|
||
# Port the server listens on (default: 3000)
|
||
# PORT=3000
|
||
|
||
# =============================================================================
|
||
# Logging
|
||
# =============================================================================
|
||
|
||
# Log format: "text" (colored, human-readable) or "json" (structured, for log aggregation)
|
||
# LOG_FORMAT=text
|
||
|
||
# Log level: "error", "warn", "info", or "debug"
|
||
# LOG_LEVEL=info
|
||
|
||
# =============================================================================
|
||
# Branding (all optional)
|
||
# =============================================================================
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# App identity
|
||
# ---------------------------------------------------------------------------
|
||
|
||
# Short name for the app, used in contexts where space is limited
|
||
# (e.g. home screen label on mobile). Defaults to APP_NAME if not set.
|
||
# APP_SHORT_NAME=Bulwark
|
||
|
||
# Description shown in the PWA manifest (displayed by the OS during install).
|
||
# Defaults to a generic Bulwark description if not set.
|
||
# APP_DESCRIPTION=Your personal webmail
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# Icons & favicon
|
||
# ---------------------------------------------------------------------------
|
||
|
||
# Custom favicon shown in the browser tab.
|
||
# Supported formats: SVG (recommended), PNG, ICO.
|
||
# Can be an absolute URL (https://...) or a path relative to the public/ directory.
|
||
# Defaults to the Bulwark favicon if not set.
|
||
# FAVICON_URL=/branding/my-favicon.svg
|
||
|
||
# Source image used to auto-generate PWA icons (192×192 and 512×512 PNG).
|
||
# Supported formats: SVG (recommended for best quality) or PNG (≥512×512px recommended).
|
||
# Can be an absolute URL (https://...) or a path relative to the public/ directory.
|
||
# Falls back to FAVICON_URL if not set, and to the default Bulwark icons if neither is set.
|
||
# PWA_ICON_URL=/branding/my-icon.svg
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# PWA appearance
|
||
# ---------------------------------------------------------------------------
|
||
|
||
# Color applied to the browser UI chrome when the app is installed as a PWA
|
||
# (address bar, status bar on Android). Default: #ffffff
|
||
# PWA_THEME_COLOR=#3b82f6
|
||
|
||
# Background color shown on the PWA splash screen while the app is loading.
|
||
# Should match your app's main background color. Default: #ffffff
|
||
# PWA_BACKGROUND_COLOR=#ffffff
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# Logos
|
||
# ---------------------------------------------------------------------------
|
||
|
||
# Logos shown in the sidebar (main app, after login).
|
||
# Supported formats: SVG (recommended), PNG, WebP.
|
||
# Recommended size: min 24×24px, max 128×128px.
|
||
# Can be absolute URLs or paths relative to the public/ directory.
|
||
# If not set, no logo is shown in the sidebar.
|
||
# APP_LOGO_LIGHT_URL=/branding/my-logo-color.svg
|
||
# APP_LOGO_DARK_URL=/branding/my-logo-white.svg
|
||
|
||
# Logos shown on the login page.
|
||
# Supported formats: SVG (recommended), PNG, WebP.
|
||
# Recommended size: min 32×32px, max 512×512px.
|
||
# Can be absolute URLs or paths relative to the public/ directory.
|
||
# Light mode logo (shown on light backgrounds). Defaults to the Bulwark logo.
|
||
LOGIN_LOGO_LIGHT_URL=/branding/Bulwark_Logo_Color.svg
|
||
# Dark mode logo (shown on dark backgrounds). Defaults to the Bulwark white logo.
|
||
LOGIN_LOGO_DARK_URL=/branding/Bulwark_Logo_Color.svg
|
||
|
||
# ---------------------------------------------------------------------------
|
||
# Login page
|
||
# ---------------------------------------------------------------------------
|
||
|
||
# Company name shown above the version number on the login page.
|
||
LOGIN_COMPANY_NAME=Bulwark Webmail
|
||
|
||
# URL for the imprint / legal notice link on the login page.
|
||
# LOGIN_IMPRINT_URL=https://example.com/imprint
|
||
|
||
# URL for the privacy policy link on the login page.
|
||
# LOGIN_PRIVACY_POLICY_URL=https://example.com/privacy
|
||
|
||
# URL for the company website link on the login page.
|
||
LOGIN_WEBSITE_URL=https://bulwarkmail.org
|
||
|
||
# =============================================================================
|
||
# Extension Directory / Marketplace
|
||
# =============================================================================
|
||
|
||
# URL of the BulwarkMail extension directory for the admin marketplace.
|
||
# Set this to enable browsing and installing plugins/themes from the directory.
|
||
# EXTENSION_DIRECTORY_URL=https://extensions.bulwarkmail.org
|
||
|
||
# =============================================================================
|
||
# Legacy Build-time Variables (still supported as fallback)
|
||
# =============================================================================
|
||
# These are baked into the bundle at build time. The runtime variables above
|
||
# take priority when both are set.
|
||
#
|
||
# NEXT_PUBLIC_APP_NAME=Bulwark Webmail
|
||
# NEXT_PUBLIC_JMAP_SERVER_URL=https://your-jmap-server.com
|