DATABASE_URL=file:../db/custom.db # unix-account login (cockpit-style, v0.4.0+): # pam — host PAM only (the cockpit default posture; run the # service as root so any unix account can sign in) # pam+local — PAM first, SdUser local accounts as fallback (works # unprivileged — unix_chkpwd only serves the invoking uid) # local — SdUser console accounts only SYSDECK_AUTH_MODE=pam+local # SYSDECK_PAM_SERVICE=sysdeck # ship /etc/pam.d/sysdeck to tailor the stack # SYSDECK_PYTHON=python3 # cockpit module detection (v0.4.1): extra scan roots beyond # /usr/share/cockpit and /usr/local/share/cockpit (colon-separated) #SYSDECK_COCKPIT_SCAN=/path/to/staged/cockpit # KLANKER_URL=http://127.0.0.1:8080 # KLANKER_ADMIN_TOKEN= # SYSDECK_SESSION_SECURE=1 # add the Secure cookie flag when fronted by TLS # mutation authorization (v0.4.3): admin gates mutating bridge commands # behind an admin session (wheel/sudo/adm or uid 0); any restores the # single-operator posture #SYSDECK_MUTATIONS=admin # X-Forwarded-For defines rate-limit identity only behind a trusted proxy #SYSDECK_TRUST_PROXY=1