Files
ampelos-dashboard/.env.example
T
Ryan 3ccae54259 Authentik moved to charon.sticknife.com
The identity provider's hostname changed. Only AUTHENTIK_ISSUER points at it,
so the live change is one line in .env.local; this commit carries the docs and
the example, which still named the old host.

The issuer string has to match the provider's own discovery document exactly,
trailing slash and all -- a host that answers is not the same as an issuer that
validates -- so the example now says how to check it. AUTH_URL is unrelated and
stays: it is this app's address, not Authentik's.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 12:40:58 +02:00

43 lines
1.9 KiB
Bash

# ampelos-dashboard
#
# Copy to .env.local and fill in. Next.js loads .env.local automatically from
# the working directory, which is what ampelos.service sets. Never commit it.
# --- database -------------------------------------------------------------
# This repository owns the schema. ampelos-agent reads the same database with
# raw SQL and holds no copy of it, so a rename here needs `npm run check:schema`
# run over there.
DATABASE_URL=postgres://user:password@mimir/ampelos
# --- sign-in --------------------------------------------------------------
# AUTH_URL is this app's own address. The ISSUER is Authentik's, and the two
# are unrelated -- moving the identity provider does not change AUTH_URL.
AUTH_URL=https://ampelos.sticknife.com
# Must match the "issuer" field in the provider's own discovery document
# exactly, trailing slash included, or the sign-in fails validation even though
# the host answers. Check with:
# curl -s https://<host>/application/o/<slug>/.well-known/openid-configuration
AUTHENTIK_ISSUER=https://charon.sticknife.com/application/o/ampelos/
AUTHENTIK_CLIENT_ID=
AUTHENTIK_CLIENT_SECRET=
# --- ampelos-agent --------------------------------------------------------
# Where the indexer listens, for the manual search and grab panel. The
# automatic acquisition loop does not go through here.
AMPELOS_INDEXER_URL=http://127.0.0.1:8081
AMPELOS_AGENT_TIMEOUT_SECONDS=30
# Shared with ampelos-agent, in both directions: the satellites POST to
# /api/agents/* with it, and this app sends it to the indexer. Same value in
# both repositories' environments, in neither's history.
AMPELOS_AGENT_TOKEN=
# --- external services ----------------------------------------------------
MOVIEDB_API=
PLEX_URL=
PLEX_PORT=32400
PLEX_AUTH_TOKEN=
PLEX_MACHINE_IDENTIFIER=
# Read-only here: the dashboard shows queue state, the agent does the grabbing.
QBT_URL=http://localhost:8080