# Postgres connection used by Prisma DATABASE_URL="postgresql://postgres:postgres@localhost:5432/kcapp?schema=public" # Authentik OIDC issuer (trailing slash optional — both forms are accepted). AUTHENTIK_ISSUER_URL="https://sso.konfi-castle.com/application/o/konfi-castle-app" # Name of the Authentik group whose members are Leitungsteam. Mirrored to # User.isLeitungsteam on every login (the access token must carry a `groups` # claim; add the "groups" scope to the Authentik provider). AUTHENTIK_LEITUNGSTEAM_GROUP="KC-APP-LT" # Secret used to sign guest/Konfi session tokens (local accounts only) GUEST_JWT_SECRET="change-me" # Secret used to sign local Gemeinde Teamer session tokens (password login) TEAM_JWT_SECRET="change-me-too" PORT=3000 # Public base URL of the app, used to build links in outgoing emails. APP_BASE_URL="http://localhost:3000" # Email: defaults to "log" (writes what it would send to the log, no # delivery). Set MAIL_PROVIDER=smtp plus the SMTP_* vars + MAIL_FROM to # actually send Gemeinde-Teamer invite emails. MAIL_PROVIDER="log" MAIL_FROM="KC-App " SMTP_HOST="smtp.example.org" SMTP_PORT=587 SMTP_SECURE="false" SMTP_USER="" SMTP_PASS="" # Push: defaults to "log" (no delivery). Set PUSH_PROVIDER=fcm plus # FCM_PROJECT_ID and GOOGLE_APPLICATION_CREDENTIALS (path to a Firebase # service-account JSON with the "Firebase Cloud Messaging API" enabled) to # send real notifications via FCM HTTP v1. PUSH_PROVIDER="log" FCM_PROJECT_ID="konfi-castle-app" GOOGLE_APPLICATION_CREDENTIALS="/absolute/path/to/serviceAccount.json" # File storage: defaults to Nextcloud via WebDAV; set STORAGE_PROVIDER=s3 to # use an S3-compatible bucket instead (see S3_* vars below). STORAGE_PROVIDER="webdav" WEBDAV_URL="https://nextcloud.example.org/remote.php/dav/files/kc-app" WEBDAV_USERNAME="kc-app" WEBDAV_PASSWORD="change-me" # Only used when STORAGE_PROVIDER=s3 S3_BUCKET="kc-app" S3_REGION="auto" S3_ENDPOINT="" S3_FORCE_PATH_STYLE="false" S3_ACCESS_KEY_ID="" S3_SECRET_ACCESS_KEY="" # Unique id for THIS server instance (local on-site vs. cloud); used to tag # replication log entries and avoid echoing changes back to their origin. SERVER_ID="change-me-uuid" # Local/cloud sync: set on the LOCAL (on-site) server to periodically push/ # pull against the cloud instance's API base URL. Leave SYNC_ENABLED=false # on the cloud server (it only needs to expose /sync/ingest + /sync/export). SYNC_ENABLED="false" SYNC_PEER_URL="https://kc-app-cloud.example.org/api" SYNC_SHARED_SECRET="change-me"