docs: document TESSERA_ENCRYPTION_KEY in env templates

Both example files pointed at the old CALENDAR_ENCRYPTION_KEY name, and
.env.example did not mention the key at all. Since compose now aborts
startup when it is unset, anyone setting up a fresh install from these
templates hit a failure the templates never explained.

Adds the current variable name, the generation command, and a note that
losing the value makes stored credentials unrecoverable.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-11 15:17:41 +02:00
parent 96432a6a7b
commit 379606ee34
2 changed files with 13 additions and 2 deletions
+7
View File
@@ -1,3 +1,10 @@
DB_PASSWORD=your_db_password_here
DATABASE_URL=postgresql://tessera:your_db_password_here@db:5432/tessera
NODE_ENV=development
# Encrypts stored credentials (LDAP bind password, calendar and mailbox logins).
# Required - the stack refuses to start without it.
# Generate one with: openssl rand -hex 32
# If this value is lost, every stored credential becomes unrecoverable.
# Belongs with every database backup, stored separately from it - a backup alone cannot restore credentials.
TESSERA_ENCRYPTION_KEY=