# Copy this file to .env and adjust it before running Docker Compose. # # Usage: # cp .env.example .env # $EDITOR .env # docker compose up -d # # Every value below is optional unless explicitly marked as required. Most # have defaults suitable for local testing, so the ones marked "example # development value" are the ones to change before exposing an instance to # anything but your own machine. # ======================================================================== # Startup phase # ======================================================================== # Which phase the container entrypoint boots into. # auto - decide from the state on disk: operational if setup already # completed, bootstrap if not. This is what you want. # bootstrap - force the setup wizard, even if setup completed before. # operational - force the normal application, skipping the wizard. # Any other value aborts startup. Leave this unset unless you are recovering # an instance whose on-disk state disagrees with what you expect. # TRUSTPOINT_PHASE=auto # ======================================================================== # Database # ======================================================================== # PostgreSQL connection used by the Trustpoint containers. # DATABASE_USER and DATABASE_PASSWORD are example development values. Use a # long, randomly generated password outside local testing: # openssl rand -base64 32 # Name of the database Trustpoint creates and connects to. POSTGRES_DB=trustpoint_db # Database role Trustpoint connects as. The postgres container creates this # role on first start, so changing it here changes both sides. DATABASE_USER=admin # Password for that role. Example development value, change it. DATABASE_PASSWORD=testing321 # Host to reach PostgreSQL on. `postgres` is the service name in # docker-compose.yml, which is what resolves inside the Compose network. Point # it at a hostname or address instead to use a database you run yourself. DATABASE_HOST=postgres # Port PostgreSQL listens on. DATABASE_PORT=5432 # Django database backend. The only reason to set this is to run against # something other than PostgreSQL, which is not a supported deployment. # DATABASE_ENGINE=django.db.backends.postgresql # ======================================================================== # TLS server certificate and Django host checking # ======================================================================== # Comma-separated lists of addresses and names where Trustpoint is reachable. # These are used for: # - Subject Alternative Names (SANs) in the TLS certificate # - Django ALLOWED_HOSTS and CSRF_TRUSTED_ORIGINS # A request arriving under a name that is not listed here is rejected by # Django before it reaches the application, so a deployment reachable under a # real hostname must list it or every request fails. # The values below are example development values covering localhost only. # At least one value must be specified for production deployments. TP_TLS_IPV4_ADDRESSES=127.0.0.1 TP_TLS_IPV6_ADDRESSES=::1 TP_TLS_DNS_NAMES=localhost # HTTP and HTTPS ports for external access. These set both the published # container ports and the ports used to build CSRF_TRUSTED_ORIGINS. # Only non-standard ports appear in CSRF_TRUSTED_ORIGINS (default: 80 for # HTTP, 443 for HTTPS). # TP_HTTP_PORT=80 # TP_HTTPS_PORT=443 # ======================================================================== # Outgoing mail # ======================================================================== # Mail is off by default: with EMAIL_HOST empty, Trustpoint uses Django's # console backend and prints messages to the log instead of sending them. # Setting EMAIL_HOST is what switches on the SMTP backend; the rest of the # values below are read only once it is set. # From address on messages Trustpoint sends. # DEFAULT_FROM_EMAIL=no-reply.trustpoint@localhost # SMTP server hostname. Empty means no mail is sent anywhere. # EMAIL_HOST= # SMTP port. # EMAIL_PORT=587 # Transport security. Left unset, these follow the port: 587 implies STARTTLS # and 465 implies implicit TLS. Set one explicitly only if your server does # something else on that port. # EMAIL_USE_TLS= # EMAIL_USE_SSL= # SMTP credentials. Authentication is attempted only when both are non-empty, # so a relay that accepts unauthenticated mail needs neither. # EMAIL_HOST_USER= # EMAIL_HOST_PASSWORD= # Seconds to wait on the SMTP connection before giving up. # EMAIL_TIMEOUT=10 # ======================================================================== # Security configuration # ======================================================================== # Security preset. Supported values are LAB, BROWNFIELD, INDUSTRIAL, # HARDENED, and CRITICAL. Unset restriction variables inherit this preset. TP_SECURITY_MODE=LAB # Optional restrictions may only make the selected preset more restrictive. # Invalid or weakening values abort startup. # TP_SECURITY_RSA_MINIMUM_KEY_SIZE=2048 # TP_SECURITY_MAX_CERT_VALIDITY_DAYS=365 # TP_SECURITY_MAX_CRL_VALIDITY_DAYS=90 # Default lifetime for CMP, EST, and REST onboarding credentials, in seconds (null for no expiry). # TP_SECURITY_ALLOW_CA_ISSUANCE=false # TP_SECURITY_ALLOW_AUTO_GEN_PKI=false # TP_SECURITY_ALLOW_SELF_SIGNED_CA=false # TP_SECURITY_ALLOW_IMPORTED_PRIVATE_KEYS=false # TP_SECURITY_AUTO_GEN_PKI=false # Optional symbolic protocol allow-lists. Empty values disable all protocols. # TP_SECURITY_PERMITTED_NO_ONBOARDING_PKI_PROTOCOLS=CMP_SHARED_SECRET,EST_USERNAME_PASSWORD # TP_SECURITY_PERMITTED_ONBOARDING_PROTOCOLS=MANUAL,CMP_IDEVID,CMP_SHARED_SECRET,EST_IDEVID,EST_USERNAME_PASSWORD,AOKI,BRSKI,OPC_GDS_PUSH,REST_USERNAME_PASSWORD # ======================================================================== # Auto-Setup Configuration (Skip Setup Wizard) # ======================================================================== # If TP_AUTO_SETUP=true, Trustpoint will automatically configure itself # from environment variables, bypassing the interactive setup wizard. # Intended for automated testing and repeatable demo environments. A normal # install should leave it off and use the wizard, which does not require the # admin password to be written to a file on disk. # Enable automatic setup from environment variables (true/false) # TP_AUTO_SETUP=false # Superuser credentials (REQUIRED if TP_AUTO_SETUP=true) # Startup fails if auto-setup is on and either is missing. Both are example # development values. # TP_ADMIN_USERNAME=admin # TP_ADMIN_PASSWORD=testing321 # Email address on the superuser account. Optional, blank if unset. # TP_ADMIN_EMAIL= # Inject demo data for testing (true/false) # Creates example devices and certificates. Development and demo only, never # on an instance holding real data. # TP_INJECT_DEMO_DATA=false # Note: When auto-setup is enabled, the TLS certificate will be automatically # generated using the TP_TLS_* variables specified above.