Files
app-catalog-felhom.eu/templates/papra/docker-compose.yml
T
admin 05cb216968 papra: add required AUTH_SECRET (app refuses to boot without it)
papra was NOT version-bumped by this campaign -- it crash-looped at its existing
26.6.1-rootless pin, so this is a PRE-EXISTING catalog defect: papra has never
been deployable from this template.

  Invalid configuration: In production, the auth secret must not be the default
  one. Please set a secure auth secret using the AUTH_SECRET environment
  variable.

Added as a generated hex:32 secret and marked data_key: true -- it signs
sessions, so regenerating it on restore would invalidate every login.

Campaign 7 catalog sweep.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Nn3VgQk9iwEGgyx6QJ2NvE
2026-07-19 00:42:29 +02:00

46 lines
1.2 KiB
YAML

# Papra - Minimalista dokumentumtár és rendszerező
# Domain: ${SUBDOMAIN}.${DOMAIN}
# Database: None (file-based)
# RAM: ~50M (mem_limit: 256M) | Pi-compatible: Yes
#
# Environment variables:
# DOMAIN - Your domain (e.g., demo-felhom.eu)
services:
papra:
image: ghcr.io/papra-hq/papra:26.6.1-rootless
container_name: papra
restart: unless-stopped
environment:
- TZ=Europe/Budapest
- APP_BASE_URL=https://${SUBDOMAIN}.${DOMAIN}
- AUTH_SECRET=${AUTH_SECRET}
volumes:
- papra_data:/app/data
networks:
- traefik-public
deploy:
resources:
limits:
memory: 256M
healthcheck:
test: ["CMD", "wget", "--spider", "-q", "http://127.0.0.1:1221"]
interval: 30s
timeout: 5s
retries: 3
start_period: 30s
labels:
- "traefik.enable=true"
- "traefik.http.routers.papra.rule=Host(`${SUBDOMAIN}.${DOMAIN}`)"
- "traefik.http.routers.papra.entrypoints=websecure"
- "traefik.http.routers.papra.tls=true"
- "traefik.http.routers.papra.tls.certresolver=letsencrypt"
- "traefik.http.services.papra.loadbalancer.server.port=1221"
volumes:
papra_data:
networks:
traefik-public:
external: true