eodia analytics is configured through environment variables. In development, copy
.env.example to .env at the root of the repository: the API, the worker, the web app and
Docker Compose all read it. A variable already present in the environment (Docker, CI) always
wins; .env.local, if it exists, wins over .env.
| Variable | Default (development) | Role |
|---|
NODE_ENV | development | production makes SECRET_KEY mandatory and turns off the demo and the built-in worker |
DATABASE_URL | postgres://eodia:eodia@localhost:55436/analytics | the database; the user owns the three schemas |
READER_PASSWORD | eodia-analytics in development | the password of the eodia_analytics read role; if absent in production, the role exists but cannot sign in |
SECRET_KEY | a development key | 64 hexadecimal characters: encrypts the site secrets. Mandatory in production |
SESSION_DAYS | 14 | the length of a sign-in session, in days |
| Variable | Default | Role |
|---|
PUBLIC_URL | http://localhost:3600 | the address of the administration (invitation links, OIDC); https:// makes the session cookie Secure |
COLLECT_URL | http://localhost:4600 in development, PUBLIC_URL in production | the public address of /a.js and /collect: the one used in the installation snippets. See the collection domain |
API_PORT | 4600 | the port the API listens on |
API_HOST | 0.0.0.0 | the address the API listens on |
API_URL | http://localhost:4600 | the address of the API, to which the interface relays /api/* |
| Variable | Default | Role |
|---|
TRUST_PROXY | 0 in development, 1 in production | read the visitor’s address from X-Forwarded-For; only behind a trusted proxy |
GEOIP_DB | — | the .mmdb country file (DB-IP Lite, CC BY 4.0); without it, only the proxy header (CF-IPCountry, X-Country-Code) gives the country |
COLLECT_RATE | 120 | events per minute and per visitor, at most |
COLLECT_FLUSH_MS | 1000 | the maximum delay before a batch is written, in milliseconds |
| Variable | Default | Role |
|---|
INSIGHTS_URL | — | the insights address: the Statistics button, and the only origin listened to by preview mode |
INSIGHTS_EMBED_KID | — | the identifier of the embedding secret created in insights |
INSIGHTS_EMBED_SECRET | — | its value |
INSIGHTS_EMBED_TTL | 240 | the validity of a signed link, in minutes |
See the Statistics button.
| Variable | Default | Role |
|---|
OIDC_ISSUER | — | the OpenID Connect issuer; enables SSO |
OIDC_CLIENT_ID | — | the client identifier |
OIDC_CLIENT_SECRET | — | the client secret, if it is confidential |
OIDC_LABEL | Se connecter avec SSO | the button label |
OIDC_SCOPES | openid email profile | the requested scopes |
OIDC_GROUPS_CLAIM | — | the groups claim to mirror onto the groups with the same name |
PASSWORD_LOGIN | 1 | 0 to keep only SSO |
See single sign-on.
| Variable | Default | Role |
|---|
SMTP_URL | — | the outgoing mail server: smtp://user:password@smtp.example.com:587; without it, invitation links are copied by hand |
SMTP_FROM | eodia analytics <noreply@localhost> | the sender |
| Variable | Default | Role |
|---|
DEMO | 1 in development, 0 in production | creates the admin@eodia.local account and the demo sites (Maison Arvor, the Arvor blog) |
INPROCESS_WORKER | 1 in development, 0 in production | runs the worker inside the API process |
docker-compose.prod.yml also reads:
| Variable | Role |
|---|
DOMAIN | the public domain, served over HTTPS by Caddy |
ACME_EMAIL | the contact address for certificates (default admin@DOMAIN) |
DB_PASSWORD | the database password |
IMAGE | the image to use (default eodia-analytics:latest) |