docs: document TESSERA_ENCRYPTION_KEY in env templates

Both example files pointed at the old CALENDAR_ENCRYPTION_KEY name, and
.env.example did not mention the key at all. Since compose now aborts
startup when it is unset, anyone setting up a fresh install from these
templates hit a failure the templates never explained.

Adds the current variable name, the generation command, and a note that
losing the value makes stored credentials unrecoverable.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-08-11 15:17:41 +02:00
parent 96432a6a7b
commit 379606ee34
2 changed files with 13 additions and 2 deletions
+6 -2
View File
@@ -14,8 +14,12 @@ TESSERA_ADMIN_USER=admin
TESSERA_ADMIN_EMAIL=admin@deine-domain.de
TESSERA_ADMIN_PASSWORD=change-me-strong-password
# Calendar encryption key — generate with: openssl rand -hex 32
CALENDAR_ENCRYPTION_KEY=
# Encrypts stored credentials (LDAP bind password, calendar and mailbox logins).
# Required - the stack refuses to start without it.
# Generate one with: openssl rand -hex 32
# If this value is lost, every stored credential becomes unrecoverable.
# Belongs with every database backup, stored separately from it - a backup alone cannot restore credentials.
TESSERA_ENCRYPTION_KEY=
# SMTP (optional — Fallback vor erster Einrichtung in Tessera-UI)
# Nach Einrichtung über Einstellungen > SMTP wird diese Konfiguration ignoriert.