LibrePortal/containers/rocketchat/rocketchat.config
librelad 50059ea1b8 rocketchat: add Rocket.Chat with a single-node Mongo replica set
Rocket.Chat tails the Mongo oplog for realtime delivery, and a standalone
mongod has no oplog — so the database has to be a replica set even with one
member.

Uses the official mongo image rather than bitnami/mongodb (which upstream's own
compose uses) because Bitnami moved its catalog behind a paid registry and the
free tags are no longer dependable for a long-lived install. The cost is that
rs.initiate() is not automatic, so the post-start hook runs it once — guarded by
rs.status() so a reinstall over restored data doesn't re-initiate a live set,
and followed by a wait for the member to report itself primary.

Mongo runs without auth: enabling it on a replica set also requires a shared
keyfile for member-to-member auth, which is a lot of moving parts for a database
that is never published outside the docker network.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-18 05:28:46 +01:00

71 lines
4.1 KiB
Plaintext

#
# =============================================================================
# GENERAL CONFIGURATION
# =============================================================================
# APP_NAME = name of application for use in scripts
# COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is
# BACKUP = if true, include this application in backup operations
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
# HEALTHCHECK = if true, default docker health checks for that container will be enabled
# AUTHELIA = if true, use Authelia authentication, if false turned off.
# HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed)
#
CFG_ROCKETCHAT_APP_NAME=rocketchat
CFG_ROCKETCHAT_BACKUP=true
CFG_ROCKETCHAT_BACKUP_STRATEGY=auto
# Manual, not auto. Rocket.Chat runs schema migrations on boot and refuses to
# start if the image is more than one major behind the database — an unattended
# jump across majors can leave the instance down until someone intervenes.
CFG_ROCKETCHAT_UPDATE_TYPE=manual
CFG_ROCKETCHAT_COMPOSE_FILE=default
CFG_ROCKETCHAT_HEALTHCHECK=true
# Rocket.Chat's own accounts back its mobile and desktop clients; forward-auth
# in front of the web port would block those clients from the REST API.
CFG_ROCKETCHAT_AUTHELIA=false
CFG_ROCKETCHAT_HEADSCALE=false
CFG_ROCKETCHAT_MONITORING=false
#
# =============================================================================
# METADATA
# =============================================================================
# CATEGORY = application category for grouping
# TITLE = display name for the application
# DESCRIPTION = short description of the application
# LONG_DESCRIPTION = detailed description of the application
# URL = source repository or documentation URL
# ACTIONS = available actions for this application
#
CFG_ROCKETCHAT_CATEGORY="communication"
CFG_ROCKETCHAT_TITLE="Rocket.Chat"
CFG_ROCKETCHAT_DESCRIPTION="Team Chat & Video"
CFG_ROCKETCHAT_LONG_DESCRIPTION="Rocket.Chat is a mature self-hosted chat platform with channels, threads, voice and video, and native mobile and desktop clients. It integrates directly with a Jitsi Meet server for calls, so it pairs with the Jitsi Meet app already in this catalog. Note the free Community edition caps the number of active users — check the current limit before rolling it out to a large group"
CFG_ROCKETCHAT_URL="https://github.com/RocketChat/Rocket.Chat"
CFG_ROCKETCHAT_ACTIONS="configure|install|restart|shutdown|uninstall"
#
# =============================================================================
# NETWORK CONFIGURATION
# =============================================================================
# DOMAIN = number of domain from the general config, useful when using multiple domains
# WHITELIST = if true only allow whitelisted ips (see general config), if false allow all
#
CFG_ROCKETCHAT_DOMAIN=1
CFG_ROCKETCHAT_WHITELIST=false
CFG_ROCKETCHAT_NETWORK=default
#
# =============================================================================
# PORT CONFIGURATION
# =============================================================================
# PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description
# - app: application name
# - name: service identifier (webui, dns, ssh, etc.)
# - external:internal: port mapping (external can be 'random' for auto-allocation)
# - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running)
# - protocol: 'tcp' or 'udp'
# - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true)
# - traefik: if true, Traefik handles this port (reverse proxy)
# - webui: if true, this port serves the main web interface
# - description: human-readable description of the service
#
CFG_ROCKETCHAT_PORT_1="rocketchat-service|webui|random:3000|public|tcp|false|true|true|Web Interface||rocketchat"