# Copy to .env and fill in. Never commit the real .env (see .gitignore). # Proxmox API token — see docs in the "Provision read-only Proxmox API token" issue # for how this was created (dedicated monitor@pve user, PVEAuditor role). PROXMOX_TOKEN_ID=monitor@pve!dashboard PROXMOX_TOKEN_SECRET= # Session cookie signing key — generate with: openssl rand -hex 32 SESSION_SECRET= # Seeded on first boot only; change the password after first login isn't # implemented yet (see backlog), so pick a real one now. ADMIN_USERNAME=admin ADMIN_PASSWORD= # Local login (username/password above) is always available. Set this true to # additionally show a "Sign in with Authentik" button — see docs/oidc-setup.md # for how the Authentik provider was set up. OIDC_ENABLED=false OIDC_ISSUER_URL=https://192.168.1.208:9443/application/o/homelab-monitor/ OIDC_CLIENT_ID= OIDC_CLIENT_SECRET= # Public URL is primary since issue #13 shipped; the LAN URL is also registered # in Authentik as a fallback (see docs/oidc-setup.md) if you need to switch back. OIDC_REDIRECT_URI=https://monitor.jerodrigged.com/api/auth/oidc/callback # Authentik's cert is self-signed on the LAN, same situation as Proxmox's API. OIDC_ALLOW_INSECURE_TLS=true # Set to true only once a TLS-terminating reverse proxy sits in front (see # issue #13). Leave false for plain-HTTP LAN access, otherwise the session # cookie won't be set at all. COOKIE_SECURE=false PORT=3000 POLL_INTERVAL_SECONDS=30 SNAPSHOT_RETENTION_HOURS=24 # Dedicated key for SshHostCollector (omv, ripper) — see docs/ssh-collector-key-setup.md. # In docker-compose this is mounted from ./ssh/monitor_ed25519 (gitignored, not this path). SSH_PRIVATE_KEY_PATH=./ssh/monitor_ed25519