# ---- Fluxer ---- # All three values come from the Fluxer app: User Settings -> Developer -> # Applications -> your app. # Bot token ("Secrets & tokens" -> Bot token). Keep it secret. FLUXER_TOKEN= # Application ID (the "Application ID" field at the top of the page). FLUXER_CLIENT_ID= # Gateway shards this process runs. "auto" (default) stays at 1 until the bot is # in ~2,500+ communities, so it is a no-op for small instances. Pin an integer to # override. One process either way. # FLUXER_SHARD_COUNT=auto # Self-hosted Fluxer instance only — leave unset for hosted Fluxer (fluxer.app). # FLUXER_API_URL is the instance's public API origin, FLUXER_WEB_URL its web app. # FLUXER_API_URL=https://api.chat.example.com # FLUXER_WEB_URL=https://chat.example.com # How timestamps render in bot messages: "native" ( markup, shown in each # reader's timezone) or "text" (plain UTC string). # FLUXER_TIMESTAMPS=native # ---- Web dashboard ---- WEB_PORT=3000 # Dashboard auth: set FLUXER_CLIENT_SECRET ("Secrets & tokens" -> Client secret # in the same app) to require "Log in with Fluxer", gated to community admins. # Also add the callback under "Redirect URIs" in the app: # /auth/fluxer/callback (locally: http://localhost:3000/auth/fluxer/callback) # Leave blank to run the dashboard open (localhost / trusted LAN only). # FLUXER_CLIENT_SECRET= # Signing key for the session cookie. Auto-generated if blank, but then sessions # drop on every restart — pin it in production (any long random string). # SESSION_SECRET= # Public URL of the dashboard, only needed behind a reverse proxy so the OAuth2 # redirect URI is correct. Otherwise derived from the request. # DASHBOARD_URL=https://sylo.example.com # Your Fluxer user id(s), comma/space-separated. With FLUXER_CLIENT_SECRET set, # only these accounts can reach /health (status, error log, database # backup/restore) — every other signed-in user is blocked, not just non-admins. # OWNER_IDS= # Channel id Sylo posts its own errors to (a "dev-log" — distinct from any # per-guild logging/modlog channel). Optional; without it there's no proactive # notification, same as today. Sylo just needs to be in that server and able # to send embeds there. # DEV_LOG_CHANNEL_ID= # ---- Verification captcha (optional) ---- # Cloudflare Turnstile keys enable the Verification module's captcha mode. Free # at https://dash.cloudflare.com -> Turnstile. Without both, captcha mode falls # back to a plain Verify button. Needs DASHBOARD_URL set (members open a link). # TURNSTILE_SITE_KEY= # TURNSTILE_SECRET_KEY= # ---- Free games: extra stores (optional) ---- # IsThereAnyDeal API key broadens the Free games module beyond the Epic Games # Store (Steam, GOG, Fanatical, Humble, …). Free key: isthereanydeal.com/apps. # Without it, Free games is Epic-only. # ITAD_API_KEY= # ---- Twitch alerts (optional) ---- # App client id + secret for the Twitch alerts module ("go live" notifications). # Register a free app at https://dev.twitch.tv/console (OAuth redirect can be any # https URL; the module uses the client-credentials flow). Without both, the # module's poll loop no-ops. # TWITCH_CLIENT_ID= # TWITCH_CLIENT_SECRET= # ---- Kick alerts (optional) ---- # App client id + secret for the Kick alerts module ("go live" notifications). # Create a free app under https://kick.com/settings/developer (the module uses # the client-credentials flow). Without both, the module's poll loop no-ops. # KICK_CLIENT_ID= # KICK_CLIENT_SECRET= # ---- Game stats (module, off by default) ---- # Powers the "Game stats" module: !stats [platform]. # Enable the module per community on the dashboard. These only tune the upstream # API and how long a lookup is cached. GAMETOOLS_API_BASE=https://api.gametools.network STATS_CACHE_TTL_MINUTES=5 # ---- Persistence ---- # SQLite database file. In Docker this should live under the mounted volume. DATABASE_PATH=./data/sylo.db # Optional: use Postgres instead of SQLite (hosted-scale deployments only — # see docs/postgres.md). Leave unset; almost nobody self-hosting needs this. # DATABASE_URL=postgres://user:pass@host:5432/dbname # Automatic database backups (compacted .db snapshots). One is always taken just # before a schema migration; these control the scheduled + retained copies. # BACKUP_DIR= # defaults to /backups # BACKUP_INTERVAL_HOURS=24 # 0 disables the scheduled backup # BACKUP_RETENTION=7 # how many snapshots to keep # Off-site copies (optional): after every snapshot a gzipped copy is pushed to # whichever of these is set — best-effort, logged, never blocks the local backup. # WebDAV target, e.g. a Nextcloud folder — the file is PUT to /.db.gz: # BACKUP_WEBDAV_URL=https://cloud.example.com/remote.php/dav/files/me/sylo-backups # BACKUP_WEBDAV_USER= # BACKUP_WEBDAV_PASS= # use an app password, not your account password # Webhook — uploaded as an attachment (skipped over the ~8 MiB limit): # BACKUP_WEBHOOK_URL=https://... # ---- Logging ---- # LOG_LEVEL=info # debug | info | warn | error # # debug also turns on one line per HTTP request # LOG_FORMAT=text # text | json (LOG_JSON=1 is shorthand for json) # Prometheus metrics are always exposed, unauthenticated, at GET /metrics # (same trust level as GET /health) — scrape it from your LAN or your own proxy. # ---- Misc ---- # NODE_ENV=production # Timezone for transcript timestamps (IANA name). Docker defaults to Europe/Oslo. # TZ=Europe/Oslo