LibrePortal/containers/rocketchat/rocketchat.config
librelad 74ee73da01 config: default Rocket.Chat and Stoat to automatic updates
The only two templates in the catalogue shipping UPDATE_TYPE=manual,
and both rationales turn out not to apply to what auto actually does.

Automatic updates act on update_available, which is digest-based: they
apply a REBUILD of the tag an app already tracks and never cross a
version line. Crossing lines is the stepped Upgrade, which is a
deliberate action and stays one.

So Rocket.Chat, pinned to 8.7.0 with mongo 8.0, cannot be walked across
a major by the automatic path — the failure its comment guarded against
was unreachable. And Stoat's nine stoatchat services are all pinned to
the same tag, so a pull moves them together or not at all; they cannot
"roll forward independently" into an API/events mismatch.

What manual did cost was real: neither app picked up security rebuilds
of the version it was already on. Rocket.Chat is carrying a critical CVE
at the time of this change.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-19 03:56:42 +01:00

83 lines
4.5 KiB
Plaintext

#
# =============================================================================
# GENERAL CONFIGURATION
# =============================================================================
# APP_NAME = name of application for use in scripts
# COMPOSE_FILE = default for no app_name in docker-compose file name, app if there is
# BACKUP = if true, include this application in backup operations
# UPDATE_TYPE = auto: new image builds are applied automatically (a recovery snapshot is taken first), manual: only when you press Update
# HEALTHCHECK = if true, default docker health checks for that container will be enabled
# AUTHELIA = if true, use Authelia authentication, if false turned off.
# HEADSCALE = options : false, local, remote (see general config). e.g false or local,remote
# MONITORING = if true, export this app's metrics to Prometheus + Grafana (needs both apps installed)
#
CFG_ROCKETCHAT_APP_NAME=rocketchat
CFG_ROCKETCHAT_BACKUP=true
CFG_ROCKETCHAT_BACKUP_STRATEGY=auto
# Auto. Rocket.Chat does run schema migrations on boot and does refuse to start
# too far behind its database — but an automatic update cannot put it there.
# Auto only ever applies a REBUILD of the tag already tracked (8.7.0, mongo 8.0);
# crossing a version line is the stepped Upgrade, which stays a deliberate act.
# So the majors-jump this once guarded against is not reachable from here, while
# staying manual meant the app never picked up security rebuilds of its own
# version — the thing auto exists for.
CFG_ROCKETCHAT_UPDATE_TYPE=auto
CFG_ROCKETCHAT_COMPOSE_FILE=default
CFG_ROCKETCHAT_HEALTHCHECK=true
# Rocket.Chat's own accounts back its mobile and desktop clients; forward-auth
# in front of the web port would block those clients from the REST API.
CFG_ROCKETCHAT_AUTHELIA=false
CFG_ROCKETCHAT_HEADSCALE=false
CFG_ROCKETCHAT_MONITORING=false
# First admin, seeded on the very first boot (Rocket.Chat ignores these once an
# admin exists). Also the credential the Tools tab authenticates with, so
# changing the password here without changing it in the app breaks user
# management — use the reset-password tool, which keeps both in step.
CFG_ROCKETCHAT_ADMIN_USERNAME=admin
CFG_ROCKETCHAT_ADMIN_EMAIL=admin@example.com
CFG_ROCKETCHAT_ADMIN_PASSWORD_1=RANDOMIZEDPASSWORD1
#
# =============================================================================
# METADATA
# =============================================================================
# CATEGORY = application category for grouping
# TITLE = display name for the application
# DESCRIPTION = short description of the application
# LONG_DESCRIPTION = detailed description of the application
# URL = source repository or documentation URL
# ACTIONS = available actions for this application
#
CFG_ROCKETCHAT_CATEGORY="communication"
CFG_ROCKETCHAT_TITLE="Rocket.Chat"
CFG_ROCKETCHAT_DESCRIPTION="Team Chat & Video"
CFG_ROCKETCHAT_LONG_DESCRIPTION="Mature self-hosted chat with channels, threads, voice and video, and native mobile and desktop clients. The free edition caps active users"
CFG_ROCKETCHAT_URL="https://github.com/RocketChat/Rocket.Chat"
CFG_ROCKETCHAT_ACTIONS="configure|install|restart|shutdown|uninstall"
#
# =============================================================================
# NETWORK CONFIGURATION
# =============================================================================
# DOMAIN = number of domain from the general config, useful when using multiple domains
# WHITELIST = if true only allow whitelisted ips (see general config), if false allow all
#
CFG_ROCKETCHAT_DOMAIN=1
CFG_ROCKETCHAT_WHITELIST=false
CFG_ROCKETCHAT_NETWORK=default
#
# =============================================================================
# PORT CONFIGURATION
# =============================================================================
# PORT_ = port configuration: app|name|external:internal|access|protocol|login|traefik|webui|description
# - app: application name
# - name: service identifier (webui, dns, ssh, etc.)
# - external:internal: port mapping (external can be 'random' for auto-allocation)
# - access: 'public' (internet accessible), 'private' (local network only), 'disabled' (not running)
# - protocol: 'tcp' or 'udp'
# - login: if true, this port requires basic-auth via Traefik (only meaningful when traefik=true)
# - traefik: if true, Traefik handles this port (reverse proxy)
# - webui: if true, this port serves the main web interface
# - description: human-readable description of the service
#
CFG_ROCKETCHAT_PORT_1="rocketchat-service|webui|random:3000|public|tcp|false|true|true|Web Interface||rocketchat"