# Postgres connection used by Prisma DATABASE_URL="postgresql://postgres:postgres@localhost:5432/kcapp?schema=public" # Authentik OIDC issuer, e.g. https://auth.example.org/application/o/kc-app/ AUTHENTIK_ISSUER_URL="https://authentik.example.org/application/o/kc-app" # Secret used to sign guest/Konfi session tokens (local accounts only) GUEST_JWT_SECRET="change-me" # Secret used to sign local Gemeinde Teamer session tokens (password login) TEAM_JWT_SECRET="change-me-too" PORT=3000 # File storage: defaults to Nextcloud via WebDAV; set STORAGE_PROVIDER=s3 to # use an S3-compatible bucket instead (see S3_* vars below). STORAGE_PROVIDER="webdav" WEBDAV_URL="https://nextcloud.example.org/remote.php/dav/files/kc-app" WEBDAV_USERNAME="kc-app" WEBDAV_PASSWORD="change-me" # Only used when STORAGE_PROVIDER=s3 S3_BUCKET="kc-app" S3_REGION="auto" S3_ENDPOINT="" S3_FORCE_PATH_STYLE="false" S3_ACCESS_KEY_ID="" S3_SECRET_ACCESS_KEY="" # Unique id for THIS server instance (local on-site vs. cloud); used to tag # replication log entries and avoid echoing changes back to their origin. SERVER_ID="change-me-uuid" # Local/cloud sync: set on the LOCAL (on-site) server to periodically push/ # pull against the cloud instance's API base URL. Leave SYNC_ENABLED=false # on the cloud server (it only needs to expose /sync/ingest + /sync/export). SYNC_ENABLED="false" SYNC_PEER_URL="https://kc-app-cloud.example.org/api" SYNC_SHARED_SECRET="change-me"