# # ============================================================================= # GENERAL CONFIGURATION # ============================================================================= # APP_NAME = name of application for use in scripts # COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is # BACKUP = if true, include this application in backup operations # UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update # HEALTHCHECK = if true, default docker health checks for that container will be enabled # AUTHELIA = if true, use Authelia authentication, if false turned off. # HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote # MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed) # CFG_MATTERMOST_APP_NAME=mattermost # MULTI_INSTANCE = if true, this app can run as multiple isolated instances # (own data/DB/subdomain/backups) via `libreportal instance create`. Only set on # apps whose compose identity (container_name, Traefik routers, backup labels) # is instance-safe — see scripts/instance/instance_create.sh. CFG_MATTERMOST_MULTI_INSTANCE=true CFG_MATTERMOST_BACKUP=true CFG_MATTERMOST_BACKUP_STRATEGY=auto CFG_MATTERMOST_UPDATE_TYPE=auto CFG_MATTERMOST_COMPOSE_FILE=default CFG_MATTERMOST_HEALTHCHECK=true # Left false deliberately. Mattermost ships its own account system and its # native desktop/mobile clients authenticate against it directly — putting # Authelia's forward-auth in front of the web port would lock those clients out # of the API without giving single sign-on in return (OIDC/SAML is a paid tier # in the Team Edition shipped here). Turn it on only if you intend to use the # web client exclusively. CFG_MATTERMOST_AUTHELIA=false CFG_MATTERMOST_HEADSCALE=false CFG_MATTERMOST_MONITORING=false # Postgres password for the `mattermost` role, fed to the compose via # #LIBREPORTAL|MATTERMOST_DB_PASSWORD_1_TAG| (both the server's datasource URL and # the database's own env). Generated on first install and preserved across # reinstalls — initdb sets it once when the volume is created. CFG_MATTERMOST_DB_PASSWORD_1=RANDOMIZEDPASSWORD1 # # ============================================================================= # METADATA # ============================================================================= # CATEGORY = application category for grouping # TITLE = display name for the application # DESCRIPTION = short description of the application # LONG_DESCRIPTION = detailed description of the application # URL = source repository or documentation URL # ACTIONS = available actions for this application # CFG_MATTERMOST_CATEGORY="communication" CFG_MATTERMOST_TITLE="Mattermost" CFG_MATTERMOST_DESCRIPTION="Team Chat" CFG_MATTERMOST_LONG_DESCRIPTION="Self-hosted team chat with channels, threads, file sharing and search, plus polished desktop and mobile clients. Free and unlimited on users" CFG_MATTERMOST_URL="https://github.com/mattermost/mattermost" CFG_MATTERMOST_ACTIONS="configure|install|restart|shutdown|uninstall" # # ============================================================================= # NETWORK CONFIGURATION # ============================================================================= # DOMAIN = number of domain from the general config, useful when using multiple domains # WHITELIST = if true only allow whitelisted ips (see general config), if false allow all # CFG_MATTERMOST_DOMAIN=1 CFG_MATTERMOST_WHITELIST=false CFG_MATTERMOST_NETWORK=default # # ============================================================================= # PORT CONFIGURATION # ============================================================================= # PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description # - app: application name # - name: service identifier (webui, dns, ssh, etc.) # - external:internal: port mapping (external can be 'random' for auto-allocation) # - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running) # - protocol: 'tcp' or 'udp' # - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true) # - traefik: if true, Traefik handles this port (reverse proxy) # - webui: if true, this port serves the main web interface # - description: human-readable description of the service # CFG_MATTERMOST_PORT_1="mattermost-service|webui|random:8065|public|tcp|false|true|true|Web Interface||mattermost" # Email of the account the WebUI card advertises; set by whoever runs the setup # wizard or the create-account tool, and kept in step by the reset-password tool. CFG_MATTERMOST_ADMIN_EMAIL= # Written by the reset-password tool when it acts on ADMIN_EMAIL's account, so # the card can show a working credential. Empty and unslotted on purpose: # Mattermost seeds no account at install (the first one comes from its own signup # wizard), so a generated password would name an account that does not exist, and # the slot number marks a value the installer generates. Without this key # declared, authPersistCfg has nothing to write to and the reset is never # recorded. CFG_MATTERMOST_ADMIN_PASSWORD=