# # ============================================================================= # GENERAL CONFIGURATION # ============================================================================= # APP_NAME = name of application for use in scripts # COMPOSE_FILE = default for no app_name in the docker-compose file name, app if there is # BACKUP = if true, include this application in backup operations # UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update # HEALTHCHECK = if true, default docker health checks for that container will be enabled # AUTHELIA = if true, use Authelia authentication, if false turned off. # HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote # CFG_MASTODON_APP_NAME=mastodon # MULTI_INSTANCE = if true, this app can run as multiple isolated instances # (own data/DB/subdomain/backups) via `libreportal instance create`. Only set on # apps whose compose identity (container_name, Traefik routers, backup labels) # is instance-safe — see scripts/instance/instance_create.sh. CFG_MASTODON_MULTI_INSTANCE=true CFG_MASTODON_BACKUP=true CFG_MASTODON_BACKUP_STRATEGY=auto CFG_MASTODON_UPDATE_TYPE=auto CFG_MASTODON_COMPOSE_FILE=default CFG_MASTODON_HEALTHCHECK=true CFG_MASTODON_AUTHELIA=false CFG_MASTODON_HEADSCALE=false # # ============================================================================= # SECRETS # ============================================================================= # These feed the compose via #LIBREPORTAL|MASTODON__TAG| tags. They are # auto-generated on first install and — unlike a generator tag in the compose — # preserved across reinstalls, which is what keeps them in step with the # Postgres volume and with every logged-in session. # # DB_NAME / DB_USER / DB_PASSWORD = Postgres database, role and password. Set # once by initdb when the volume is created; changing them afterwards without # also changing them in Postgres locks Mastodon out of its own database. # SECRET_KEY_BASE = signs and encrypts Rails session cookies. Rotating it logs # every user out. # OTP_SECRET = protects stored two-factor enrolments. Rotating it invalidates # them, and anyone with 2FA on needs it reset before they can log in. # VAPID_PRIVATE_KEY / VAPID_PUBLIC_KEY = Web Push identity. These two are the # halves of one P-256 keypair, so they cannot be generated independently the # way the other secrets are — mastodon_install_post_setup replaces the pair # below with a real one on first install, and never touches it again. # RANDOMIZEDVAPID is kept here only so the tag always has something # substitutable: if key generation ever fails, Mastodon starts with push # broken rather than with a literal placeholder as its key. # CFG_MASTODON_DB_NAME_1=RANDOMIZEDUSERNAME1 CFG_MASTODON_DB_USER_1=RANDOMIZEDUSERNAME2 CFG_MASTODON_DB_PASSWORD_1=RANDOMIZEDPASSWORD1 CFG_MASTODON_SECRET_KEY_BASE_1=RANDOMIZEDHEX1 CFG_MASTODON_OTP_SECRET_1=RANDOMIZEDHEX2 CFG_MASTODON_VAPID_PRIVATE_KEY_1=RANDOMIZEDVAPID1 CFG_MASTODON_VAPID_PUBLIC_KEY_1=RANDOMIZEDVAPID2 # # ============================================================================= # METADATA # ============================================================================= # CATEGORY = application category for grouping # TITLE = display name for the application # DESCRIPTION = short description of the application # LONG_DESCRIPTION = detailed description of the application # URL = source repository or documentation URL # ACTIONS = available actions for this application # CFG_MASTODON_CATEGORY="communication" CFG_MASTODON_TITLE="Mastodon" CFG_MASTODON_DESCRIPTION="Social Network" CFG_MASTODON_LONG_DESCRIPTION="Your self-hosted, globally interconnected microblogging community that gives you control over your social media experience" CFG_MASTODON_URL="https://github.com/mastodon/mastodon" CFG_MASTODON_ACTIONS="configure|install|restart|shutdown|uninstall" # # ============================================================================= # NETWORK CONFIGURATION # ============================================================================= # DOMAIN = number of domain from the general config, useful when using multiple domains # WHITELIST = if true only allow whitelisted ips on traefik, if false allow all # CFG_MASTODON_DOMAIN=1 CFG_MASTODON_WHITELIST=false CFG_MASTODON_NETWORK=default # # ============================================================================= # PORT CONFIGURATION # ============================================================================= # PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description # - app: application name # - name: service identifier (webui, dns, ssh, etc.) # - external:internal: port mapping (external can be 'random' for auto-allocation) # - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running) # - protocol: 'tcp' or 'udp' # - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true) # - traefik: if true, Traefik handles this port (reverse proxy) # - webui: if true, this port serves the main web interface # - description: human-readable description of the service # CFG_MASTODON_PORT_1="mastodon-service|webui|random:3010|public|tcp|false|false|true|Web Interface||social" CFG_MASTODON_PORT_2="mastodon-service|streaming|random:4010|public|tcp|false|false|false|Mastodon Streaming API|"