Files
tessera-ctl/.env.prod.example
T
schalli 379606ee34 docs: document TESSERA_ENCRYPTION_KEY in env templates
Both example files pointed at the old CALENDAR_ENCRYPTION_KEY name, and
.env.example did not mention the key at all. Since compose now aborts
startup when it is unset, anyone setting up a fresh install from these
templates hit a failure the templates never explained.

Adds the current variable name, the generation command, and a note that
losing the value makes stored credentials unrecoverable.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-11 15:18:22 +02:00

32 lines
1.2 KiB
Bash

# Tessera Production Environment
# Copy to .env and fill in all values before running docker compose up
# Database
DB_PASSWORD=change-me-strong-password
DATABASE_URL=postgresql://tessera:change-me-strong-password@db:5432/tessera
# App
APP_URL=https://tessera.deine-domain.de
JWT_SECRET=change-me-64-char-random-string
# Admin account (created on first start)
TESSERA_ADMIN_USER=admin
TESSERA_ADMIN_EMAIL=admin@deine-domain.de
TESSERA_ADMIN_PASSWORD=change-me-strong-password
# Encrypts stored credentials (LDAP bind password, calendar and mailbox logins).
# Required - the stack refuses to start without it.
# Generate one with: openssl rand -hex 32
# If this value is lost, every stored credential becomes unrecoverable.
# Belongs with every database backup, stored separately from it - a backup alone cannot restore credentials.
TESSERA_ENCRYPTION_KEY=
# SMTP (optional — Fallback vor erster Einrichtung in Tessera-UI)
# Nach Einrichtung über Einstellungen > SMTP wird diese Konfiguration ignoriert.
# TESSERA_SMTP_HOST=
# TESSERA_SMTP_PORT=587
# TESSERA_SMTP_SECURE=false
# TESSERA_SMTP_USER=
# TESSERA_SMTP_PASSWORD=
# TESSERA_SMTP_FROM=Tessera <noreply@deine-domain.de>