Files
cedricandClaude Opus 5.5 42f6137391 Safer defaults, read-only role, security headers and syslog TCP limits
- ALLOW_PURGE is now false by default; the UI shows a banner when there is
  no authentication.
- Read-only role: AUTH_VIEWER_USER/AUTH_VIEWER_PASS in local mode, or
  OIDC_ADMIN_GROUP in OIDC mode; changes get 403 and the admin settings
  are greyed out.
- Content-Security-Policy (inline scripts allowed by hash) and other
  security headers; cross-site changes are refused.
- Syslog TCP: at most SYSLOG_TCP_MAX_CONNS connections, closed after
  SYSLOG_TCP_IDLE of silence; HTTP idle timeout.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
2026-10-03 16:30:40 +02:00

56 lines
2.5 KiB
Bash

# Copy this file to .env and adjust it.
SYSLOG_PORT=514
HTTP_PORT=8080
TZ=Europe/Paris
# How long logs are kept (e.g. 7d, 30d, 12w, 1y)
RETENTION=30d
# Web UI authentication: local (login page with the account below, or none) or oidc (OpenID Connect provider)
AUTH_MODE=local
# local mode: user and password (empty = no authentication)
AUTH_USER=
AUTH_PASS=
# local mode: optional read-only account (can search and export, cannot change tags, sources or purge)
AUTH_VIEWER_USER=
AUTH_VIEWER_PASS=
# local mode: PNG logo shown on the login page, path inside the container (empty = no logo).
# Mount the file in docker-compose.yml, e.g. ./logo.png:/config/logo.png:ro, then LOGIN_LOGO=/config/logo.png
LOGIN_LOGO=
# Ready-made color tags offered in Settings > Filters (see docs/presets.md).
# Empty: /data/presets.json if present, else the built-in list. To use your own file,
# mount it in docker-compose.yml, e.g. ./presets.json:/config/presets.json:ro
PRESETS_FILE=
# Session lifetime, both modes (e.g. 8h, 24h)
SESSION_TTL=12h
# oidc mode: issuer URL exactly as the provider announces it
# (Keycloak: https://sso.example.org/realms/<realm>, Authentik: https://auth.example.org/application/o/<slug>/)
OIDC_ISSUER=
OIDC_CLIENT_ID=
OIDC_CLIENT_SECRET=
# Callback URL of logstream, to register in the provider (path free, /auth/callback recommended)
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
# Requested scopes (openid is always added)
OIDC_SCOPES=openid profile email
# oidc mode: only members of this group are admins, the others are read-only (empty = everyone is admin).
# The groups come from the ID token claim OIDC_GROUPS_CLAIM (default groups)
OIDC_ADMIN_GROUP=
OIDC_GROUPS_CLAIM=groups
# Reverse DNS: show host names instead of IP addresses (on/off)
RDNS=on
# DNS server used for reverse lookups (e.g. your router: 192.168.1.1). Empty = system resolver
DNS_SERVER=
# Allow "Delete all logs" in Settings (true/false)
ALLOW_PURGE=false
# Maximum number of rows in a CSV export
EXPORT_MAX=100000
# Collect the logs of the Docker containers of this machine (on/off)
DOCKER_LOGS=on
# History read from a container seen for the first time (e.g. 30m, 1h, 24h; 0 = only new lines)
DOCKER_BACKFILL=1h
# Host system logs (enable them in Settings > Sources)
# Group allowed to read the host logs: 4 = adm on Debian/Ubuntu; or the systemd-journal group
# (getent group systemd-journal | cut -d: -f3)
HOST_LOGS_GID=4
# History read when the source is turned on (e.g. 30m, 1h, 24h; 0 = only new entries)
HOST_LOGS_BACKFILL=1h