Configuration
Deployer reads environment variables only (systemd: EnvironmentFile=/etc/deployer/env, mode 600). Settings
changed in the interface (Authentik connection, Deployer's own OIDC sign-in, saved recipes) are stored in the
database and override the corresponding defaults.
Set the server-specific values
Some defaults are the values of the author's server (domain, IP, DNS zone, Authentik UUIDs). Always set every
variable of the Server and apps, DNS and Authentik tables for your own installation.
Service
| Variable |
Default |
Description |
DEPLOYER_LISTEN |
127.0.0.1:8150 |
Address of the HTTP server. Keep it on loopback; nginx publishes it. |
DEPLOYER_DATABASE_URL |
postgres://deployer:deployer@127.0.0.1:5450/deployer?sslmode=disable |
PostgreSQL connection string. |
DEPLOYER_PUBLIC_URL |
https://deploy.belghali.org |
Public address: Origin check (CSRF), OIDC redirect, Secure cookies. |
DEPLOYER_MASTER_KEY_FILE |
/etc/deployer/master.key |
AES-256 key (created on first start, mode 600). Back it up. |
DEPLOYER_SETUP_TOKEN_FILE |
/etc/deployer/setup_token |
One-time token for the first administrator. |
DEPLOYER_REQUIRE_MFA |
empty |
1: acting endpoints require two-factor. |
DEPLOYER_DEV |
empty |
1: cookies without Secure (local HTTP development). Never in production. |
DEPLOYER_FAKE |
empty |
1: in-memory fakes for the host, DNS and Authentik (development, tests). Never in production. |
Server and apps
| Variable |
Default |
Description |
DEPLOYER_DOMAIN |
belghali.org |
Apps get <name>.<domain>. |
DEPLOYER_SERVER_IP |
93.90.200.253 |
IPv4 the A records point to. |
DEPLOYER_STACKS_DIR |
/srv/stacks |
One folder per app; deletions archived in _archive/. |
DEPLOYER_NGINX_AVAILABLE |
/etc/nginx/sites-available |
Where sites are written. |
DEPLOYER_NGINX_ENABLED |
/etc/nginx/sites-enabled |
Where they are enabled (symlink). |
DEPLOYER_NGINX_MAIN |
/etc/nginx/nginx.conf |
Copied to test a candidate site in isolation. |
DEPLOYER_PORT_MIN / _MAX |
8200 / 8999 |
Loopback ports given to apps (ports in use on the host are skipped). |
DEPLOYER_SUBNET_PREFIX |
10.250 |
Apps get <prefix>.<n>.0/24. |
DEPLOYER_SUBNET_MIN / _MAX |
10 / 250 |
Range of <n> (subnets in use by Docker are skipped). |
DEPLOYER_CERTBOT_EMAIL |
empty |
Only for a first certbot run without an account. |
DNS (IONOS)
| Variable |
Default |
Description |
DEPLOYER_IONOS_KEY_FILE |
/root/.secrets/ionos-dns.key |
File with prefix.secret (sent as X-API-Key), mode 600. |
DEPLOYER_IONOS_ZONE |
author's zone |
Zone id of your domain. |
DEPLOYER_IONOS_NS |
ns1045.ui-dns.com:53 |
Authoritative name server queried to confirm propagation before certbot. |
Authentik
| Variable |
Default |
Description |
DEPLOYER_AUTHENTIK_URL |
http://127.0.0.1:9000 |
Authentik as reached from the server (API and the nginx forward-auth endpoint). |
DEPLOYER_AUTHENTIK_PUBLIC_URL |
https://belghali.org |
Public Authentik address (issuers, SAML URLs, links). |
DEPLOYER_AUTHENTIK_TOKEN_FILE |
/etc/deployer/authentik.token |
Fallback API token when none is saved in Settings → Authentik. |
DEPLOYER_AUTHENTIK_OUTPOST |
author's UUID |
Embedded outpost UUID (choose it in Settings → Authentik instead). |
DEPLOYER_AUTHENTIK_AUTH_FLOW |
author's UUID |
Authorization flow for new providers (Settings → Authentik). |
DEPLOYER_AUTHENTIK_INV_FLOW |
author's UUID |
Invalidation (logout) flow (Settings → Authentik). |
DEPLOYER_AUTHENTIK_CONTAINER |
authentik-server-1 |
Container used by "Connect automatically". |
The Settings → Authentik page is the recommended way: Connect automatically runs a fixed script in the
Authentik container that creates the service account deployer in the superuser group with the API token
deployer-api; or paste an admin API token, test it, then choose the outpost and flows from what Authentik
returns. The token is stored sealed with the master key.
Files
| Path |
Content |
Mode |
/etc/deployer/env |
environment |
600 |
/etc/deployer/master.key |
AES-256 key |
600 |
/etc/deployer/setup_token |
first-run token |
600 |
/opt/deployer/bin/deployer (+ .prev) |
binary (previous version kept for rollback) |
755 |
/opt/deployer/docker-compose.yml |
database + backup |
|
/opt/deployer/backups/ |
daily pg_dump, 14 days |
|
<stacks>/<app>/ |
compose.yaml, secrets/ (400), data/, backups/, README.md |
|
/etc/nginx/sites-available/<fqdn> |
app sites written by Deployer |
600 |