diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 5 |
1 files changed, 4 insertions, 1 deletions
@@ -90,6 +90,8 @@ Go changes need a restart. | `JWT_SECRET` | — | **Required** outside dev; long random string (`openssl rand -hex 32`) | | `SUPERADMIN_USERNAME` / `SUPERADMIN_PASSWORD` | `admin` / — | Created on first start if no superadmin exists | | `MAX_UPLOAD_MB` | `10` | Per-file upload limit; the superadmin can override it per blog in `/admin/` | +| `HTTPS` | `false` | The proxy terminates TLS: generated links are `https://`, the session cookie is `Secure`, HSTS is sent. **Set it in production.** | +| `TRUST_PROXY` | `false` | Take the client address from the last `X-Forwarded-For` entry (the one your proxy wrote) for rate limiting and the log. Set it when the app is only reachable through your proxy. | | `DEV` | `false` | Hot-reload templates, allow missing secrets | Migrations run automatically at startup, for the control database and for every blog database. @@ -103,7 +105,8 @@ docker compose up --build -d The app listens on `127.0.0.1:8080` (see `APP_PORT`); put a reverse proxy in front that terminates TLS and forwards **both** the root domain and the wildcard -with the original `Host` header. DNS needs two records: `A example.com` and +with the original `Host` header. Keep `HTTPS=true` and `TRUST_PROXY=true` in +`.env` for that setup (the sample has them). DNS needs two records: `A example.com` and `A *.example.com` (or CNAMEs) pointing at the proxy. nginx example: |
