# Copy to .env and fill in. Never commit the real .env (see .gitignore). # Proxmox API token — see docs in the "Provision read-only Proxmox API token" issue # for how this was created (dedicated monitor@pve user, PVEAuditor role). PROXMOX_TOKEN_ID=monitor@pve!dashboard PROXMOX_TOKEN_SECRET= # Session cookie signing key — generate with: openssl rand -hex 32 SESSION_SECRET= # Seeded on first boot only; change the password after first login isn't # implemented yet (see backlog), so pick a real one now. ADMIN_USERNAME=admin ADMIN_PASSWORD= # Local login (username/password above) is always available. Set this true to # additionally show a "Sign in with Authentik" button — see docs/oidc-setup.md # for how the Authentik provider was set up. OIDC_ENABLED=false # MUST be the public hostname, not the LAN IP (192.168.1.208:9443) -- Authentik's # discovery doc echoes back whichever host you query it through, and that value # gets baked into authorization_endpoint, which the *browser* is redirected to. # Using the LAN IP here sends anyone off-LAN to an address they can't reach. # See docs/oidc-setup.md for the bug this caused. OIDC_ISSUER_URL=https://auth.jerodrigged.com/application/o/homelab-monitor/ OIDC_CLIENT_ID= OIDC_CLIENT_SECRET= # Public URL is primary since issue #13 shipped; the LAN URL is also registered # in Authentik as a fallback (see docs/oidc-setup.md) if you need to switch back. OIDC_REDIRECT_URI=https://monitor.jerodrigged.com/api/auth/oidc/callback # auth.jerodrigged.com has a real Let's Encrypt cert (unlike the LAN IP's # self-signed one), so this can stay false when OIDC_ISSUER_URL is the public URL. OIDC_ALLOW_INSECURE_TLS=false # Set to true only once a TLS-terminating reverse proxy sits in front (see # issue #13). Leave false for plain-HTTP LAN access, otherwise the session # cookie won't be set at all. COOKIE_SECURE=false PORT=3000 POLL_INTERVAL_SECONDS=30 SNAPSHOT_RETENTION_HOURS=24 # Dedicated key for SshHostCollector (omv, ripper) — see docs/ssh-collector-key-setup.md. # In docker-compose this is mounted from ./ssh/monitor_ed25519 (gitignored, not this path). SSH_PRIVATE_KEY_PATH=./ssh/monitor_ed25519 # Optional. Free API key from fingerbank.org — enriches the "Deep check" button's # results with device fingerprinting (MAC + any SSDP signal found). Without a DHCP # fingerprint (which we don't have access to, not being the DHCP server), this often # only reaches manufacturer-level confidence, same as the free OUI lookup — see # docs/device-discovery.md. Omit entirely to skip this enrichment. FINGERBANK_API_KEY= # Optional. Long-lived access token from Home Assistant (Profile > Security > # Long-Lived Access Tokens). When set (with homeAssistant.url in # config/hosts.yaml), pushes a persistent_notification whenever a MAC address # is seen on the network for the very first time -- see docs/device-discovery.md. # Detection runs either way; this only gates whether you get pushed a notification. HOME_ASSISTANT_TOKEN=