From 379606ee34379631a488938580c851a777140652 Mon Sep 17 00:00:00 2001 From: Schalli Date: Tue, 11 Aug 2026 15:17:41 +0200 Subject: [PATCH] docs: document TESSERA_ENCRYPTION_KEY in env templates Both example files pointed at the old CALENDAR_ENCRYPTION_KEY name, and .env.example did not mention the key at all. Since compose now aborts startup when it is unset, anyone setting up a fresh install from these templates hit a failure the templates never explained. Adds the current variable name, the generation command, and a note that losing the value makes stored credentials unrecoverable. Co-Authored-By: Claude Opus 5 (1M context) --- .env.example | 7 +++++++ .env.prod.example | 8 ++++++-- 2 files changed, 13 insertions(+), 2 deletions(-) diff --git a/.env.example b/.env.example index 20added..07ae0f2 100644 --- a/.env.example +++ b/.env.example @@ -1,3 +1,10 @@ DB_PASSWORD=your_db_password_here DATABASE_URL=postgresql://tessera:your_db_password_here@db:5432/tessera NODE_ENV=development + +# Encrypts stored credentials (LDAP bind password, calendar and mailbox logins). +# Required - the stack refuses to start without it. +# Generate one with: openssl rand -hex 32 +# If this value is lost, every stored credential becomes unrecoverable. +# Belongs with every database backup, stored separately from it - a backup alone cannot restore credentials. +TESSERA_ENCRYPTION_KEY= diff --git a/.env.prod.example b/.env.prod.example index 77b60d5..864c7f7 100644 --- a/.env.prod.example +++ b/.env.prod.example @@ -14,8 +14,12 @@ TESSERA_ADMIN_USER=admin TESSERA_ADMIN_EMAIL=admin@deine-domain.de TESSERA_ADMIN_PASSWORD=change-me-strong-password -# Calendar encryption key — generate with: openssl rand -hex 32 -CALENDAR_ENCRYPTION_KEY= +# Encrypts stored credentials (LDAP bind password, calendar and mailbox logins). +# Required - the stack refuses to start without it. +# Generate one with: openssl rand -hex 32 +# If this value is lost, every stored credential becomes unrecoverable. +# Belongs with every database backup, stored separately from it - a backup alone cannot restore credentials. +TESSERA_ENCRYPTION_KEY= # SMTP (optional — Fallback vor erster Einrichtung in Tessera-UI) # Nach Einrichtung über Einstellungen > SMTP wird diese Konfiguration ignoriert.