# Members area — Flask + SQLite behind Caddy. # # Copy this directory to /srv/board/ on the server, fill in .env, then: # mkdir -p /srv/board/data && sudo chown 1000:1000 /srv/board/data # docker compose up -d # # Bound to localhost like Gitea and Woodpecker: the only way in from outside is # through Caddy, which terminates TLS and forwards /comunidad/. services: board: image: vienalatina/board:1 restart: unless-stopped environment: # Session signing key. Generate once with `openssl rand -hex 32`. # Changing it signs everyone out; losing it means nothing worse. - BOARD_SECRET_KEY=${BOARD_SECRET_KEY} # Where the site's content lives. Members never see it: they sign in # here, against a password in our own database. - GITEA_URL=https://git.vienalatina.com - BOARD_BASE_URL=https://vienalatina.com # The Gitea username that becomes the one owner, applied once on an empty # database. Changing it later does nothing: ownership moves from inside # the app, so nobody can take it by editing this file. - BOARD_OWNER=${BOARD_OWNER} # Site-admin token, used only to create Gitea accounts for new members. # This is the most privileged secret on the box after Gitea's own # database: anything that can read this environment can create accounts. # Leave it empty to run without account creation — admins then add people # who already have a Gitea login, and everything else still works. - GITEA_ADMIN_TOKEN=${GITEA_ADMIN_TOKEN:-} - CONTENT_TOKEN=${CONTENT_TOKEN:-} - BOARD_DB=/data/board.db # Outgoing mail, for invitations and password resets. Empty MAIL_HOST is # a supported state: the members area still works, but nobody can be # invited or recover a password, and the screens say so. # # Every one of these has to be listed here. Compose does not hand the # contents of .env to the container by itself — it only substitutes into # this file — so a variable added to .env and not added here is read by # nobody, and the app reports mail as unconfigured with the settings # sitting right there on disk. - MAIL_HOST=${MAIL_HOST:-} - MAIL_PORT=${MAIL_PORT:-587} - MAIL_SECURITY=${MAIL_SECURITY:-starttls} - MAIL_USER=${MAIL_USER:-} - MAIL_PASSWORD=${MAIL_PASSWORD:-} - "MAIL_FROM=${MAIL_FROM:-Viena Latina }" volumes: - ./data:/data ports: - "127.0.0.1:8080:8080"