From c0d08b0880dcce7337d9bdf046c93b318a84c2dc Mon Sep 17 00:00:00 2001 From: Anders Betts Date: Sun, 20 Sep 2026 15:58:10 +0200 Subject: deploy: pass BOKFD_SECRET_KEY through compose; document waves 1-2 --- docs/DEPLOY.md | 6 ++++++ 1 file changed, 6 insertions(+) (limited to 'docs/DEPLOY.md') diff --git a/docs/DEPLOY.md b/docs/DEPLOY.md index ed105f8..7385a8f 100644 --- a/docs/DEPLOY.md +++ b/docs/DEPLOY.md @@ -184,8 +184,14 @@ LEGO_DOMAIN=bokf.makandra.eu LEGO_EMAIL=anders@makandra.eu INWX_USERNAME=... INWX_PASSWORD=... +BOKFD_SECRET_KEY=... # openssl rand -hex 32 ``` +`BOKFD_SECRET_KEY` encrypts secrets that live in the database (the SMTP +password) with AES-256-GCM; without it, setting or sending with a mail +password fails. Keep it out of the repository and out of backups of the +database — losing it only means re-entering the SMTP password. + Forward port 8788 on the router to the host. The `certs` sidecar obtains and renews the certificate into `var/db/certs/certificates/`; `bokfd` reloads it in place. On the very first `up`, `bokfd` may restart a few times until the -- cgit v1.3