Skip to content

Configuration

Deployer reads environment variables only (systemd: EnvironmentFile=/etc/deployer/env, mode 600). Settings changed in the interface (Authentik connection, Deployer's own OIDC sign-in, saved recipes) are stored in the database and override the corresponding defaults.

Set the server-specific values

Some defaults are the values of the author's server (domain, IP, DNS zone, Authentik UUIDs). Always set every variable of the Server and apps, DNS and Authentik tables for your own installation.

Service

Variable Default Description
DEPLOYER_LISTEN 127.0.0.1:8150 Address of the HTTP server. Keep it on loopback; nginx publishes it.
DEPLOYER_DATABASE_URL postgres://deployer:deployer@127.0.0.1:5450/deployer?sslmode=disable PostgreSQL connection string.
DEPLOYER_PUBLIC_URL https://deploy.belghali.org Public address: Origin check (CSRF), OIDC redirect, Secure cookies.
DEPLOYER_MASTER_KEY_FILE /etc/deployer/master.key AES-256 key (created on first start, mode 600). Back it up.
DEPLOYER_SETUP_TOKEN_FILE /etc/deployer/setup_token One-time token for the first administrator.
DEPLOYER_REQUIRE_MFA empty 1: acting endpoints require two-factor.
DEPLOYER_DEV empty 1: cookies without Secure (local HTTP development). Never in production.
DEPLOYER_FAKE empty 1: in-memory fakes for the host, DNS and Authentik (development, tests). Never in production.

Server and apps

Variable Default Description
DEPLOYER_DOMAIN belghali.org Apps get <name>.<domain>.
DEPLOYER_SERVER_IP 93.90.200.253 IPv4 the A records point to.
DEPLOYER_STACKS_DIR /srv/stacks One folder per app; deletions archived in _archive/.
DEPLOYER_NGINX_AVAILABLE /etc/nginx/sites-available Where sites are written.
DEPLOYER_NGINX_ENABLED /etc/nginx/sites-enabled Where they are enabled (symlink).
DEPLOYER_NGINX_MAIN /etc/nginx/nginx.conf Copied to test a candidate site in isolation.
DEPLOYER_PORT_MIN / _MAX 8200 / 8999 Loopback ports given to apps (ports in use on the host are skipped).
DEPLOYER_SUBNET_PREFIX 10.250 Apps get <prefix>.<n>.0/24.
DEPLOYER_SUBNET_MIN / _MAX 10 / 250 Range of <n> (subnets in use by Docker are skipped).
DEPLOYER_CERTBOT_EMAIL empty Only for a first certbot run without an account.

DNS (IONOS)

Variable Default Description
DEPLOYER_IONOS_KEY_FILE /root/.secrets/ionos-dns.key File with prefix.secret (sent as X-API-Key), mode 600.
DEPLOYER_IONOS_ZONE author's zone Zone id of your domain.
DEPLOYER_IONOS_NS ns1045.ui-dns.com:53 Authoritative name server queried to confirm propagation before certbot.

Authentik

Variable Default Description
DEPLOYER_AUTHENTIK_URL http://127.0.0.1:9000 Authentik as reached from the server (API and the nginx forward-auth endpoint).
DEPLOYER_AUTHENTIK_PUBLIC_URL https://belghali.org Public Authentik address (issuers, SAML URLs, links).
DEPLOYER_AUTHENTIK_TOKEN_FILE /etc/deployer/authentik.token Fallback API token when none is saved in Settings → Authentik.
DEPLOYER_AUTHENTIK_OUTPOST author's UUID Embedded outpost UUID (choose it in Settings → Authentik instead).
DEPLOYER_AUTHENTIK_AUTH_FLOW author's UUID Authorization flow for new providers (Settings → Authentik).
DEPLOYER_AUTHENTIK_INV_FLOW author's UUID Invalidation (logout) flow (Settings → Authentik).
DEPLOYER_AUTHENTIK_CONTAINER authentik-server-1 Container used by "Connect automatically".

The Settings → Authentik page is the recommended way: Connect automatically runs a fixed script in the Authentik container that creates the service account deployer in the superuser group with the API token deployer-api; or paste an admin API token, test it, then choose the outpost and flows from what Authentik returns. The token is stored sealed with the master key.

Files

Path Content Mode
/etc/deployer/env environment 600
/etc/deployer/master.key AES-256 key 600
/etc/deployer/setup_token first-run token 600
/opt/deployer/bin/deployer (+ .prev) binary (previous version kept for rollback) 755
/opt/deployer/docker-compose.yml database + backup
/opt/deployer/backups/ daily pg_dump, 14 days
<stacks>/<app>/ compose.yaml, secrets/ (400), data/, backups/, README.md
/etc/nginx/sites-available/<fqdn> app sites written by Deployer 600