feat: add SSO environment variables to docker-compose.yml and create .env.example
All checks were successful
Build & Push Docker Image to Gitea Registry / build-and-push (push) Successful in 19s
All checks were successful
Build & Push Docker Image to Gitea Registry / build-and-push (push) Successful in 19s
This commit is contained in:
21
.env.example
Normal file
21
.env.example
Normal file
@@ -0,0 +1,21 @@
|
|||||||
|
# JWT Secret used for admin/user authentication tokens (change this to a secure random value)
|
||||||
|
JWT_SECRET=your_jwt_secret_here
|
||||||
|
|
||||||
|
# SQLite Database path inside container (normally persistent volume, no need to change)
|
||||||
|
# FULLS_DIR=/app/public/images/fulls
|
||||||
|
# THUMBS_DIR=/app/public/images/thumbs
|
||||||
|
|
||||||
|
# ==========================================
|
||||||
|
# Keycloak SSO (OIDC) Configuration
|
||||||
|
# ==========================================
|
||||||
|
# Base Keycloak URL Realm Authority
|
||||||
|
SSO_AUTHORITY=https://auth.mischlabs.de/realms/mischlabs
|
||||||
|
|
||||||
|
# Client ID configured in Keycloak for Photography
|
||||||
|
SSO_CLIENT_ID=pocketbase
|
||||||
|
|
||||||
|
# Client Secret retrieved from Keycloak (Credentials tab)
|
||||||
|
SSO_CLIENT_SECRET=
|
||||||
|
|
||||||
|
# Public callback URI registered in Keycloak for the Photography app
|
||||||
|
SSO_REDIRECT_URI=https://tom.mischlabs.de/api/auth/sso/callback
|
||||||
@@ -8,6 +8,10 @@ services:
|
|||||||
- JWT_SECRET=${JWT_SECRET:?set JWT_SECRET in your environment}
|
- JWT_SECRET=${JWT_SECRET:?set JWT_SECRET in your environment}
|
||||||
- FULLS_DIR=/app/public/images/fulls
|
- FULLS_DIR=/app/public/images/fulls
|
||||||
- THUMBS_DIR=/app/public/images/thumbs
|
- THUMBS_DIR=/app/public/images/thumbs
|
||||||
|
- SSO_AUTHORITY=${SSO_AUTHORITY:-https://auth.mischlabs.de/realms/mischlabs}
|
||||||
|
- SSO_CLIENT_ID=${SSO_CLIENT_ID:-pocketbase}
|
||||||
|
- SSO_CLIENT_SECRET=${SSO_CLIENT_SECRET:-}
|
||||||
|
- SSO_REDIRECT_URI=${SSO_REDIRECT_URI:-https://tom.mischlabs.de/api/auth/sso/callback}
|
||||||
volumes:
|
volumes:
|
||||||
# Nextcloud-Ordner mit Originalbildern (read-only)
|
# Nextcloud-Ordner mit Originalbildern (read-only)
|
||||||
- /volume1/nextcloud/data/Tom/files/Websitebilder:/app/public/images/fulls:ro
|
- /volume1/nextcloud/data/Tom/files/Websitebilder:/app/public/images/fulls:ro
|
||||||
|
|||||||
Reference in New Issue
Block a user