feat: add SSO environment variables to docker-compose.yml and create .env.example
All checks were successful
Build & Push Docker Image to Gitea Registry / build-and-push (push) Successful in 19s

This commit is contained in:
Kroonk
2026-05-21 10:55:48 +02:00
parent 75e4fbaa19
commit 3ea02bab3c
2 changed files with 25 additions and 0 deletions

21
.env.example Normal file
View File

@@ -0,0 +1,21 @@
# JWT Secret used for admin/user authentication tokens (change this to a secure random value)
JWT_SECRET=your_jwt_secret_here
# SQLite Database path inside container (normally persistent volume, no need to change)
# FULLS_DIR=/app/public/images/fulls
# THUMBS_DIR=/app/public/images/thumbs
# ==========================================
# Keycloak SSO (OIDC) Configuration
# ==========================================
# Base Keycloak URL Realm Authority
SSO_AUTHORITY=https://auth.mischlabs.de/realms/mischlabs
# Client ID configured in Keycloak for Photography
SSO_CLIENT_ID=pocketbase
# Client Secret retrieved from Keycloak (Credentials tab)
SSO_CLIENT_SECRET=
# Public callback URI registered in Keycloak for the Photography app
SSO_REDIRECT_URI=https://tom.mischlabs.de/api/auth/sso/callback

View File

@@ -8,6 +8,10 @@ services:
- JWT_SECRET=${JWT_SECRET:?set JWT_SECRET in your environment}
- FULLS_DIR=/app/public/images/fulls
- THUMBS_DIR=/app/public/images/thumbs
- SSO_AUTHORITY=${SSO_AUTHORITY:-https://auth.mischlabs.de/realms/mischlabs}
- SSO_CLIENT_ID=${SSO_CLIENT_ID:-pocketbase}
- SSO_CLIENT_SECRET=${SSO_CLIENT_SECRET:-}
- SSO_REDIRECT_URI=${SSO_REDIRECT_URI:-https://tom.mischlabs.de/api/auth/sso/callback}
volumes:
# Nextcloud-Ordner mit Originalbildern (read-only)
- /volume1/nextcloud/data/Tom/files/Websitebilder:/app/public/images/fulls:ro