Docker Compose Variables
Docker Compose Example File docker-compose.ymlโ
services:
db:
image: postgres:18-alpine
restart: always
networks:
- boards-network
volumes:
- db-data-18:/var/lib/postgresql
environment:
POSTGRES_DB: 4gaBoards
POSTGRES_PASSWORD: notpassword
POSTGRES_INITDB_ARGS: '-A scram-sha-256'
healthcheck:
test: ['CMD-SHELL', 'pg_isready -U postgres -d 4gaBoards']
interval: 5s
timeout: 5s
retries: 20
redis:
image: redis:8-alpine
restart: always
networks:
- boards-network
volumes:
- redis-data-8:/data
command: ['redis-server', '--appendonly', 'yes', '--requirepass', 'notredispassword']
healthcheck:
test: ['CMD-SHELL', 'redis-cli -a "notredispassword" ping | grep PONG']
interval: 5s
timeout: 5s
retries: 20
4gaBoards:
image: ghcr.io/rargames/4gaboards:latest
restart: always
networks:
- boards-network
volumes:
- user-avatars:/app/public/user-avatars
- project-background-images:/app/public/project-background-images
- attachments:/app/private/attachments
ports:
- 3000:1337
environment:
BASE_URL: http://localhost:3000
SECRET_KEY: notsecretkey
DATABASE_URL: postgresql://postgres:notpassword@db/4gaBoards
NODE_ENV: production
UPLOAD_RATE_LIMIT_STORE: redis
UPLOAD_RATE_LIMIT_REDIS_URL: redis://:notredispassword@redis:6379/0
## Add optional 4ga Boards instance variables here
depends_on:
db:
condition: service_healthy
redis:
condition: service_healthy
volumes:
user-avatars:
project-background-images:
attachments:
db-data-18:
redis-data-8:
networks:
boards-network:
4ga Boards - Required Instance Variablesโ
db service environment variables:
POSTGRES_DB- database namePOSTGRES_PASSWORD- database password
4gaBoards service environment variables:
BASE_URL- domain or ip address used to access 4ga BoardsDATABASE_URL- database url in the following format:postgresql://<username>:<password>@<host>/<database_name>SECRET_KEY- session secret key
4ga Boards - Optional Instance Variablesโ
4gaBoards service environment variables:
Default settings (applied only on first run)โ
Default admin user is always created, but you can override the default values:โ
DEFAULT_ADMIN_USERNAME: "demo"- default admin username, defaults todemoDEFAULT_ADMIN_EMAIL: "demo@demo.demo"- default admin email, defaults todemo@demo.demoDEFAULT_ADMIN_NAME: "Demo Demo"- default admin name, defaults toDemo DemoDEFAULT_ADMIN_PASSWORD: "demo"- default admin password, defaults todemo
Other settings:โ
DEFAULT_PROJECT_CREATION_ALL: true- only admins can create projects if true, defaults totrueDEFAULT_REGISTRATION_ENABLED: true- registration enabled if true, defaults totrueDEFAULT_LOCAL_REGISTRATION_ENABLED: true- local registration emabled if true, defaults totrueDEFAULT_SSO_REGISTRATION_ENABLED: true- sso registration enabled if true, defaults totrueDEFAULT_ALLOWED_REGISTER_DOMAINS: "4gaboards.com;example.com"- a semicolon separated list of allowed domain for registration, defaults to- meaning all domains are allowedDEFAULT_SYNC_SSO_DATA_ON_AUTH: false- sync all user data (except admin status) after each sso login, defaults tofalseDEFAULT_SYNC_SSO_ADMIN_ON_AUTH: false- sync user admin status after each sso login, defaults tofalse
Google OAuth2.0โ
GOOGLE_CLIENT_ID: googleClientId- client id from the project on: https://console.cloud.google.com/GOOGLE_CLIENT_SECRET: googleClientSecret- client secret from the project: generated in app settings
GitHub OAuth2.0โ
GITHUB_CLIENT_ID: githubClientId- client id from the app after creating on: https://github.com/settings/applications/new or https://github.com/settings/apps/newGITHUB_CLIENT_SECRET: githubClientSecret- client secret from the app: generated in app settings
Microsoft OIDCโ
MICROSOFT_CLIENT_ID: microsoftClientId- client id from the app after creating on: https://portal.azure.com/MICROSOFT_CLIENT_SECRET: microsoftClientSecret- client secret from the app: generated in app settings
Generic OIDCโ
OIDC_CLIENT_ID: oidcClientId- client id from the app after creating in custom OIDC providerOIDC_CLIENT_SECRET: oidcClientSecret- client secret from the app: generated in app settingsOIDC_ISSUER_URL: https://oidcIssuer.com- OIDC issuer URL, if OIDC issuer supports discovery protocol (.well-known/openid-configuration) other URLs are configured automatically. However some URLs can be overridden using settigs below:OIDC_AUTH_URL: https://oidcIssuer.com/auth- optional auth URLOIDC_TOKEN_URL: https://oidcIssuer.com/token- optional token URLOIDC_USERINFO_URL: https://oidcIssuer.com/userinfo- optional userinfo URLOIDC_STATE_SECRET: stateSecret- OIDC state secret, generate usingopenssl rand -hex 64OIDC_ENABLED_METHODS: Google,Microsoft,GitHub- a comma-separated list of methods supported by OIDC provider (this is used to show custom buttons for each method - supported methods: Google, Microsoft, GitHub - open GitHub issue if more methods are needed)OIDC_DISABLE_HINT_*: false- disable one of the methods supported by OIDC provider e.g.OIDC_DISABLE_HINT_GITHUB: false, defaults tofalseOIDC_SKIP_ACCOUNT_SELECTION: false- don't sendselect_accountorloginprompt to OIDC provider, defaults tofalseOIDC_SKIP_ACCOUNT_SELECTION_HINT_*: false- don't sendselect_accountorloginprompt to OIDC provider (only for some method) e.g.OIDC_SKIP_ACCOUNT_SELECTION_HINT_GITHUB: false, defaults tofalse
Notifications (Email Notifications, Email Verifications, Email-to-Card)โ
NOTIFICATIONS_HOST_URL: http://localhost:3223- notifications host URL, defaults tonull, all notification variables have to be configured in order for notifications to workNOTIFICATIONS_CLIENT_ID: notificationsClientId- noitifications client idNOTIFICATIONS_CLIENT_SECRET: notificationsClientSecret- notifications client secretMAIL_SERVICE_INBOUND_EMAIL: localhost@inbound.4gaboards.com- inbound email address (used mainly as a hint for correct email addresses for Email-to-Card)INSTANCE_NAME: localhost- instance name (used mainly for notifications email subject)
HyperDxโ
HYPERDX_ENABLED: false- enable HyperDx integration, defaults tofalseHYPERDX_API_KEY: hyperdxApiKey- HyperDx api keyHYPERDX_INSTANCE_NAME: 4gaboards.com- HyperDx instance name, defaults toINSTANCE_NAMEor4gaboards.comif instance name is not availableHYPERDX_TRACE_PROPAGATION_TARGETS: string- HyperDx trace propagation targets (string), defaults tonullOTEL_URL: https://otel.prod.4gacore.com- HyperDx Otel URL, defaults tonullOTEL_URL_FORMAT: http/protobuf- HyperDx Otel URL format, defaults tohttp/protobuf
Uploads, Attachments and Image Processingโ
UPLOAD_RATE_LIMIT_ENABLED: true- upload rate limit disabled if false, defaults totrueUPLOAD_RATE_LIMIT_MAX_ATTEMPTS: 30- upload rate limit max attempts in window, defaults to30UPLOAD_RATE_LIMIT_WINDOW_MS: 60000- upload rate limit window in milliseconds, defaults to60000- 1 minuteUPLOAD_RATE_LIMIT_STORE: memory- upload rate limit store (memoryorredis), defaults tomemoryUPLOAD_RATE_LIMIT_REDIS_URL: redis://:notredispassword@localhost:6379/0- upload rate limit redis url, required ifUPLOAD_RATE_LIMIT_STORE: redisUPLOAD_RATE_LIMIT_REDIS_CONNECT_TIMEOUT_MS: 500- upload rate limit redis connect timeout in milliseconds, defaults to500UPLOAD_RATE_LIMIT_KEY_PREFIX: rl:upload- upload rate limit redis key prefix, defaults torl:uploadATTACHMENT_MAX_BYTES: 26214400- max attachment file size in bytes, defaults to26214400- 25 MBAVATAR_MAX_BYTES: 26214400- max avatar image size in bytes, defaults to26214400- 25 MBPROJECT_BACKGROUND_IMAGE_MAX_BYTES: 26214400- max project background image size in bytes, defaults to26214400- 25 MBBOARD_IMPORT_MAX_BYTES: 104857600- max board import file size in bytes, defaults to104857600- 100 MBBOARD_IMPORT_MAX_COMPRESSED_BYTES: 104857600- max compressed board import size in bytes, defaults to104857600- 100 MBBOARD_IMPORT_MAX_UNCOMPRESSED_BYTES: 524288000- max uncompressed board import size in bytes, defaults to524288000- 500 MBBOARD_IMPORT_MAX_ENTRIES: 5000- max extracted entries in board import archive, defaults to5000BOARD_IMPORT_MAX_EXTRACTION_MS: 30000- max extraction time for board import in milliseconds, defaults to30000- 30 secondsSHARP_MAX_INPUT_PIXELS: 40000000- Sharp max input pixels, defaults to40000000SHARP_CONCURRENCY: 2- Sharp concurrency, defaults to2SHARP_CACHE_MEMORY_MB: 50- Sharp cache memory in MB, defaults to50SHARP_CACHE_ITEMS: 100- Sharp cache item count, defaults to100SHARP_CACHE_FILES: 20- Sharp cache file count, defaults to20
Other settingsโ
CLIENT_URL: http://localhost:3000- main client URL - usually not needed, if running production defaults toBASE_URL, if development defaults tohttp://localhost:3000(skip this unless you really need it)DEMO_MODE: false- demo mode enabled if true, defaults tofalseLOG_LEVEL: warn- log levels from highest to lowest - error, warn, info, http, verbose, debug, silly, defaults towarnTRUST_PROXY: 0- trust proxy used only if 4ga Boards are behind a proxy/load balancer, defaults to0TOKEN_EXPIRES_IN: 365- token expiration in days, defaults to365AUTH_RATE_LIMIT_ENABLED: true- login rate limit disabled if false, defaults totrueAUTH_RATE_LIMIT_MAX_ATTEMPTS: 5- login rate limit max attempts in window, defaults to5AUTH_RATE_LIMIT_WINDOW_MS: 60000- login rate limit window, defaults to60000- 10 minutesSYSTEM_NOTIFICATIONS_DISABLED: true- stop receiving system notifications, we honor it and do not send notifications except important security update releases to admins. We recommend usingSuppressed System Notification Tagsin user preferences instead as it allows more control e.g. leaving one admin with update notifications
Additional Links:
4ga Boards docker-compose.yml File
4ga Boards Professional Hosting