# ================================================================= # SparkyFitness Environment Configuration (.env) # Interactive Generator: https://codewithcj.github.io/SparkyFitness/install/env-generator # # Sections follow the same order as the generator and the Environment # Variables documentation page. Uncommented values are the ones a normal # deployment sets; commented lines show the default that applies when absent. # ================================================================= # --- 1. PostgreSQL Database Settings --- # Only the two passwords are required. The names below are the defaults that # docker-compose already uses, shown so you can see what you are running with. # # WARNING: the database name, the superuser name and the superuser password are # read ONLY the first time the database initialises. Changing any of them on an # existing instance does nothing to PostgreSQL, and the server then fails to # authenticate. To change them you must ALTER them in PostgreSQL yourself. SPARKY_FITNESS_DB_USER=sparky SPARKY_FITNESS_DB_PASSWORD=changeme_db_password # SPARKY_FITNESS_DB_NAME=sparkyfitness_db # SPARKY_FITNESS_DB_HOST=sparkyfitness-db # SPARKY_FITNESS_DB_PORT=5432 # # The application role is created and kept in sync by the server, so both of # these are optional. Left unset, the server uses "sparky_app" and generates a # new password on every start. Set them explicitly if more than one server # shares this database, or if you pre-created the role yourself. # SPARKY_FITNESS_APP_DB_USER=sparky_app # SPARKY_FITNESS_APP_DB_PASSWORD=changeme_app_db_password # --- 2. Security & Authentication Secrets --- # 64-character hex key (openssl rand -hex 32) SPARKY_FITNESS_API_ENCRYPTION_KEY=changeme_replace_with_a_64_character_hex_string # Required. Signs session cookies and encrypts stored 2FA/TOTP secrets, so it # must stay the same forever: changing it logs every user out, and anyone with # 2FA enabled is locked out permanently. Generate with: openssl rand -base64 32 # Must be base64: the server decodes it as such and silently discards any # character outside that alphabet, shortening the key without telling you. BETTER_AUTH_SECRET=changeme_replace_with_a_strong_better_auth_secret # --- 3. Persistent Host Storage Paths --- # docker-compose falls back to these same values when the variables are # absent, so a running instance already uses them. Changing one points the # server at a new, empty directory. If you bind-mounted paths directly in # docker-compose.yml, these are ignored. # DB_PATH=./postgresql # SERVER_BACKUP_PATH=./backup # SERVER_UPLOADS_PATH=./uploads # --- 4. Server Runtime --- SPARKY_FITNESS_FRONTEND_URL=http://localhost:3004 NODE_ENV=production SPARKY_FITNESS_LOG_LEVEL=ERROR # TZ drives how entries are bucketed into calendar days. Set your own zone. TZ=Etc/UTC # SPARKY_FITNESS_SERVER_PORT=3010 # SPARKY_FITNESS_SERVER_HOST=sparkyfitness-server # SPARKY_FITNESS_EXTRA_TRUSTED_ORIGINS=http://192.168.1.100:3004 # Overrides the base URL Better Auth builds callback links from. Only needed # when it cannot be derived from SPARKY_FITNESS_FRONTEND_URL. # BETTER_AUTH_URL=https://fitness.example.com # --- 5. Admin, Signups & Access Policy --- # SPARKY_FITNESS_ADMIN_EMAIL=admin@example.com SPARKY_FITNESS_DISABLE_SIGNUP=false # FORCE_EMAIL_LOGIN wins over DISABLE_EMAIL_LOGIN. To actually disable password # login, set DISABLE_EMAIL_LOGIN=true and unset FORCE_EMAIL_LOGIN (or set it to # 'false'). Only do so once OIDC or SMTP-backed magic links work, or nobody can # sign in to a fresh instance. # SPARKY_FITNESS_DISABLE_EMAIL_LOGIN=false # SPARKY_FITNESS_FORCE_EMAIL_LOGIN=true # ALLOW_PRIVATE_NETWORK_CORS=false # --- 6. SMTP Email Notifications --- # SPARKY_FITNESS_EMAIL_HOST=smtp.example.com # SPARKY_FITNESS_EMAIL_PORT=587 # SPARKY_FITNESS_EMAIL_SECURE=false # SPARKY_FITNESS_EMAIL_USER=user@example.com # SPARKY_FITNESS_EMAIL_PASS=smtp_password # SPARKY_FITNESS_EMAIL_FROM=noreply@example.com # --- 7. OpenID Connect (OIDC / SSO) --- # SPARKY_FITNESS_OIDC_AUTH_ENABLED=true # SPARKY_FITNESS_OIDC_PROVIDER_NAME=Authentik # SPARKY_FITNESS_OIDC_PROVIDER_SLUG=authentik # SPARKY_FITNESS_OIDC_ISSUER_URL=https://auth.example.com/application/o/sparky/ # SPARKY_FITNESS_OIDC_CLIENT_ID=sparky-client-id # SPARKY_FITNESS_OIDC_CLIENT_SECRET=sparky-client-secret # SPARKY_FITNESS_OIDC_ADMIN_GROUP=Admin # SPARKY_FITNESS_OIDC_SCOPE=openid email profile # --- Advanced OIDC (rarely needed) --- # SPARKY_FITNESS_OIDC_AUTO_REGISTER=true # SPARKY_FITNESS_OIDC_AUTO_REDIRECT=false # SPARKY_FITNESS_OIDC_DOMAIN=example.com # SPARKY_FITNESS_OIDC_LOGO_URL=https://example.com/logo.png # SPARKY_FITNESS_OIDC_TOKEN_AUTH_METHOD=client_secret_post # SPARKY_FITNESS_OIDC_ID_TOKEN_SIGNED_ALG=RS256 # SPARKY_FITNESS_OIDC_USERINFO_SIGNED_ALG=none # SPARKY_FITNESS_OIDC_TIMEOUT=30000 # --- 8. Garmin Microservice --- GARMIN_MICROSERVICE_URL=http://sparkyfitness-garmin:8000 GARMIN_SERVICE_PORT=8000 # Set to true only for the Garmin China region. # GARMIN_SERVICE_IS_CN=false # --- 9. Rate Limiting --- # SPARKY_FITNESS_SIGN_IN_RATELIMIT_MAX=4 # SPARKY_FITNESS_SIGN_IN_RATELIMIT_WINDOW=60 # SPARKY_FITNESS_API_KEY_RATELIMIT_MAX_REQUESTS=100 # SPARKY_FITNESS_API_KEY_RATELIMIT_WINDOW_MS=60000 # --- 10. Frontend Nginx, Ports & Client IP Detection --- # SPARKY_FITNESS_FRONTEND_PORT=3004 # NGINX_RATE_LIMIT=5r/s # DNS resolver for dynamic backend upstream resolution. Defaults to auto-detecting # nameservers from /etc/resolv.conf, falling back to 127.0.0.11 (Docker embedded DNS). # NGINX_RESOLVER=127.0.0.11 # Port nginx listens on inside the container. 80 for the root image, # 8080 for the non-root image. # NGINX_LISTEN_PORT=80 # NGINX_ACCESS_LOG= # NGINX_ERROR_LOG= # NGINX_DUMP_CONFIG=false # Name a CDN header, or count proxy hops. Only relevant behind a proxy. # SPARKY_FITNESS_REAL_IP_HEADER=CF-Connecting-IP # SPARKY_FITNESS_TRUSTED_PROXY_HOPS=1 # --- 11. Outbound Forward Proxy --- # HTTP_PROXY=http://proxy.example.com:8888 # HTTPS_PROXY=http://proxy.example.com:8888 # NO_PROXY=localhost,127.0.0.1,sparkyfitness-garmin # --- 12. Public Demo Mode --- SPARKY_FITNESS_DEMO_MODE=false # SPARKY_FITNESS_DEMO_EMAIL=demo@sparkyfitness.com # SPARKY_FITNESS_DEMO_PASSWORD=changeme_demo_password # --- 13. Admin Policy Toggles --- # All four are also settable in the Admin UI (stored in global_settings). # Setting one to 'true' here forces it on regardless of the stored value; # leaving it commented out defers to the Admin UI. # SECURITY WARNING: the two ALLOW_PRIVATE_NETWORK_* flags let any registered # non-admin user make the server send requests to your internal network (SSRF). # Only enable on a trusted single-tenant deployment. # SPARKY_FITNESS_PUBLIC_API_DOCS=false # DEV_TOOLS_ENABLED=false # ALLOW_PRIVATE_NETWORK_AI=false # ALLOW_PRIVATE_NETWORK_FOOD_PROVIDERS=false # --- 14. Integration Overrides (development only) --- # Points the Liftosaur integration at a different API host. Leave unset in # production: user API keys are sent to whatever host is configured here. # SPARKY_FITNESS_LIFTOSAUR_API_BASE_URL=https://www.liftosaur.com # --- 15. Standalone / Bare-Metal Only --- # Only needed when not running under Docker Compose. # SPARKY_FITNESS_CUSTOM_UPLOADS_DIRECTORY= # SPARKY_FITNESS_CUSTOM_BACKUP_DIRECTORY= # SPARKY_FITNESS_CUSTOM_TEMP_DIRECTORY= # --- 16. Docker Secrets (file-based alternatives) --- # Any VAR can be supplied via VAR_FILE pointing at a mounted secret file. # SPARKY_FITNESS_DB_PASSWORD_FILE=./secrets/db_password # SPARKY_FITNESS_APP_DB_PASSWORD_FILE=./secrets/app_db_password # SPARKY_FITNESS_API_ENCRYPTION_KEY_FILE=./secrets/api_encryption_key # BETTER_AUTH_SECRET_FILE=./secrets/better_auth_secret # SPARKY_FITNESS_EMAIL_PASS_FILE=./secrets/email_pass # SPARKY_FITNESS_OIDC_CLIENT_ID_FILE=./secrets/oidc_client_id # SPARKY_FITNESS_OIDC_CLIENT_SECRET_FILE=./secrets/oidc_client_secret # --- 17. iOS Mobile Development (Optional) --- # EXPO_DEV_APPLE_TEAM_ID= # EXPO_PROD_APPLE_TEAM_ID= # EXPO_DEV_BUNDLE_IDENTIFIER=org.SparkyApps.SparkyFitnessMobile.dev # WIDGET_BUNDLE_IDENTIFIER=org.SparkyApps.SparkyFitnessMobile.dev.ExpoWidgetsTarget # IOS_APP_GROUP_DEV=group.org.SparkyApps.SparkyFitnessMobile.dev # IOS_APP_GROUP_PROD=group.com.SparkyApps.SparkyFitnessMobile.shared