Settings

The settings of a server, and the Key File that seals its secrets.

A server names its settings in config.toml in the state directory, or in PAGIS_* variables for a deployment that mounts no file. A variable wins for the run and is never written back into the file.

config.tomlVariableDefaultWhat it is
portPAGIS_PORT4400The product port.
bindPAGIS_BIND127.0.0.1The Bind Address of the product port. Name the private interface the proxy is on, or 0.0.0.0 for every interface.
public_originPAGIS_PUBLIC_ORIGINDerived from bind and portThe Public Origin: the scheme, host and port a browser reaches the installation at. The CORS answer names it.
trusted_proxyPAGIS_TRUSTED_PROXYNoneThe Trusted Proxy: the one address whose X-Forwarded-For and X-Forwarded-Proto the daemon believes.
[administration] portPAGIS_ADMINISTRATION_PORT4401The Administration Port.
[administration] bindPAGIS_ADMINISTRATION_BIND127.0.0.1Its Bind Address, loopback whatever the product port binds.
[database] urlPAGIS_DATABASE_URLNoneThe postgres:// URL of the database that holds the records. A server does not start without it.
[secrets] key_fileNone/run/secrets/pagis-secrets-keyThe Key File (Linux).
[screen] advertise_ipPAGIS_SCREEN_ADVERTISE_IP127.0.0.1The address browsers reach the Media Relay at.
[screen] media_port_first, media_port_lastPAGIS_SCREEN_MEDIA_PORT_FIRST, PAGIS_SCREEN_MEDIA_PORT_LAST50000, 50099The Media Relay's UDP range.
bind = "10.0.1.7"
public_origin = "https://pagis.example.net"
trusted_proxy = "10.0.1.6"

[administration]
port = 4401
bind = "127.0.0.1"

[database]
url = "postgres://pagis:<password>@127.0.0.1:5432/pagis"

Bind the private interface the proxy is on, not 0.0.0.0, where the network allows it. The daemon then answers the proxy alone, and a firewall rule is a second line of defence rather than the only one.

An Administrator changes the port, the Docker endpoint and the log level in the Settings view of the Administration Interface, and the daemon writes config.toml itself. The timezone is each Person's own: their browser or Client App reports it at their first sign-in, and they change it in Settings → Timezone of the Product App. The clock of the server is never a Person's timezone.

A change to the port, the log level or the multi-user mode takes effect on a restart. The daemon then exits with code 75, and a supervisor starts it again: the Client App, or the restart policy of the compose deployment. Each of them sets PAGIS_SUPERVISED=1, and the Settings view then waits for the new process. A daemon that a person started by hand has no supervisor, so the Settings view says to run pagis again. A supervisor of your own, such as a systemd unit with Restart=on-failure, sets PAGIS_SUPERVISED=1 too. --port and PAGIS_PORT override the port of config.toml for one run, and the Settings view shows both ports while they differ.

The log level applies to the daemon's own lines. The libraries it uses log warnings and errors alone. PAGIS_LOG replaces the whole filter with a tracing directive such as debug or info,tantivy=debug.

The Key File

On Linux the daemon reads the Installation Key, which seals secrets.enc, from the Key File. The file holds 64 hexadecimal characters and nothing else. The daemon refuses a file that a group or another user can read, and it does not start without the file.

head -c 32 /dev/urandom | od -An -tx1 | tr -d ' \n' > pagis-secrets-key
chmod 600 pagis-secrets-key

The key never sits in config.toml and never goes into a backup: an archive that holds both is a lock beside its key. Keep it where the deployment keeps its other secrets. A restored server without it opens no stored secret.

Edit on GitHub

On this page