Configure your deployment
The supplied .env file configures Docker Compose and the application services. Edit it in the deployment directory before you run start.sh.
start.sh loads .env as Bash input. Quote values that contain spaces or shell characters.
Images and registry access
| Variable | Template value or purpose |
|---|---|
IMAGE_TAG | 13, a moving application tag. Use a specific release tag for repeatable deployments. |
MYSQL_IMAGE_TAG | 8.4 |
REDIS_IMAGE_TAG | 8.6.1 |
DOCKER_REGISTRY_USERNAME | Username from the setup email |
DOCKER_REGISTRY_SECRET | Registry credential from the setup email |
The API, server rendering, preview, and Nginx images come from registry.digidib.dev.
The MySQL and Redis images use their public Docker image repositories.
Secrets
Replace SESSION_SECRET, MYSQL_PASSWORD, and MYSQL_ROOT_PASSWORD before the first start.
Generate a separate value for each secret:
openssl rand -hex 32
SESSION_SECRET must contain at least 32 characters. It signs sessions and also participates in MCP client registration.
Keep it stable across routine updates.
Set LICENSE_KEY to the supplied license key. Store .env with access limited to deployment administrators:
chmod 600 .env
Changing a MySQL password in .env does not change the password inside an existing database.
For password rotation, change the MySQL account and its application configuration together.
Domain and HTTPS
DOMAIN_NAME=regex101.example.com
OAUTH_ORIGIN=https://regex101.example.com
DOMAIN_NAME is the hostname without a scheme or path. OAUTH_ORIGIN is the public origin used for sign-in callbacks.
Point DNS at your reverse proxy or load balancer. Forward its requests to the customer Nginx service on HTTP port 80. Configure the certificate and HTTPS listener at that proxy.
The supplied Compose file publishes ports 80 and 443. Nginx listens on port 80. Publishing port 443 does not create a TLS listener. MySQL and Redis have no published host ports in the supplied Compose file.
Proxy trust
TRUST_PROXY controls which upstream addresses the application trusts for forwarded request information.
An empty value uses the uniquelocal address range. Explicit values accept comma-separated IP addresses, CIDR ranges, or named address ranges.
true trusts all proxies. false disables proxy trust. Numeric hop counts are not supported.
Use addresses that match your proxy network.
Database and storage
| Variable | Default | Purpose |
|---|---|---|
MYSQL_HOSTNAME | mysql | Compose service hostname |
MYSQL_PORT | 3306 | MySQL connection port |
MYSQL_DATABASE | regex101 | Application database |
MYSQL_USER | regex101 | Application database account |
MYSQL_DATA_DIR | ./mysql/data | Host directory mounted at /var/lib/mysql |
MYSQL_CONF_FILE | ./mysql/mysql.cnf | MySQL server configuration file |
MYSQL_CONNECTION_LIMIT | 30 | Application connection-pool limit |
MYSQL_CONNECT_TIMEOUT | 5000 | Connection timeout in milliseconds |
Relative paths resolve from the deployment directory. Preserve the data directory when you update containers. The API applies database migrations at startup before it serves requests.
Redis uses two separate services:
| Service | Hostname variable | Port variable | Named volume |
|---|---|---|---|
| Sessions | REDIS_SESSIONS_HOSTNAME=redis-sessions | REDIS_SESSIONS_PORT=6379 | redis-sessions-data |
| Cache | REDIS_CACHE_HOSTNAME=redis-cache | REDIS_CACHE_PORT=6379 | redis-cache-data |
Both Redis services use append-only persistence. Each supplied Redis configuration sets a 1,000 MB memory limit and the allkeys-lru eviction policy.
These Redis limits are not a memory requirement for the complete deployment.
See Backups for the persistent data and configuration that recovery needs.
Optional application configuration
| Variable | Behavior |
|---|---|
OAUTH_* | Configure Google, GitHub, or custom OpenID Connect sign-in. |
SESSION_TTL_MS | Session duration in milliseconds. The default is 30 days. |
API_BODY_LIMIT_MB | Request-body limit for the API, from 1 through 16 MB. The default is 10 MB. |
MINIMAL_INTERFACE=true | Hide header menus, release announcements, and the Enterprise version block. |
DISABLED_FEATURES | Disable selected application feature IDs. This cannot add license entitlements. |
LICENSE_FILE | Host path to supplied offline license material. See offline installation. |
Apply a configuration change
For an existing deployment, follow the update procedure.
start.sh pulls the configured images and recreates containers, so a moving image tag can also update the application.
To recreate services with the images already present on the host, run:
docker compose up -d --force-recreate
If LICENSE_FILE is configured, include its Compose override:
docker compose -f docker-compose.yml -f docker-compose.license-file.yml \
up -d --force-recreate
Verify service health with docker compose ps after the change.