# ───────────────────────────────────────────────────────────────────────────── # setup.env — first-run setup for the theta-env stack. # # This file is used ONLY on the FIRST run of ./setup.sh, to generate # ./config/sso-secrets.js + ./config/proxy-secrets.js with your domain filled # in everywhere consistently. Once ./config/*.js exist they are operator-owned # (edit them directly; setup.env is ignored on later runs). # # cp setup.env.example setup.env # $EDITOR setup.env # set CFG_BASE_DN below to your domain # ./setup.sh # generates ./config/ and builds the stack # # Copying this file to setup.env (gitignored) keeps your domain out of git. # ───────────────────────────────────────────────────────────────────────────── # Your domain, as an LDAP base DN. THIS IS THE ONE PLACE THE DOMAIN IS ENTERED. # Everything else derives from it: the SSO/proxy hostnames default to # sso. / proxy., and the LDAP DNs are cn=admin,, # ou=people,, ou=groups,. Required — setup.sh refuses to run without it. CFG_BASE_DN=dc=example,dc=com # Public hostnames. Optional — default to sso. / proxy. derived # from CFG_BASE_DN above. Uncomment and set only if your hostnames differ # (e.g. a different subdomain, or the domain isn't the bare apex): #CFG_SSO_HOST=sso.example.com #CFG_PROXY_HOST=proxy.example.com # Optional — sensible defaults if left blank: #CFG_ORG=SSO Manager # app display name + outbound email org #CFG_ADMIN_UID=admin # initial SSO admin username #CFG_ADMIN_EMAIL=admin@proxy.example.com # defaults to admin@ #CFG_LDAP_CERT_CN= # LDAP TLS cert CN; empty -> defaults to the domain # Optional SMTP (outbound email from the SSO app). Leave blank to disable: #CFG_SMTP_HOST=smtp.example.com #CFG_SMTP_PORT=587 #CFG_SMTP_USER=noreply@example.com #CFG_SMTP_PASS=your-smtp-password #CFG_SMTP_FROM=SSO Manager # ── DO NOT put secrets here ────────────────────────────────────────────────── # The LDAP admin password, JWT secret, admin password, and LDAP service-account # password are GENERATED (random) into ./config/sso-secrets.js on first run. # Change them later by editing ./config/sso-secrets.js directly. Do NOT set # CFG_LDAP_ADMIN_PASS / CFG_JWT_SECRET / CFG_ADMIN_PASS / CFG_SVC_PASS here.