The Configuration table in README.md leaves out three settings upaas reads (UPAAS_MAINTENANCE_MODE, UPAAS_SESSION_SECRET, UPAAS_CORS_ORIGINS), and several rows it has give the wrong default or effect. Found while fixing #224.
Definition of done: every setting upaas reads from the environment is in the table, with its real name, default and effect, checked against internal/config/config.go and the code that uses each value. Docs only.
What the code does today (verify each before writing it down):
PORT: upaas also reads UPAAS_PORT, and UPAAS_PORT wins when both are set (the config library looks up the prefixed name first).
UPAAS_HOST_DATA_DIR: when unset it takes the value of UPAAS_DATA_DIR; when set it must be an absolute path or upaas refuses to start. It is needed when upaas runs in a container.
UPAAS_DEBUG: turns on debug logging and also drops the Secure flag from the session cookie (internal/service/auth/auth.go).
UPAAS_SENTRY_DSN: read but not used anywhere; upaas sends nothing to Sentry. The row must say so instead of promising error reporting.
UPAAS_METRICS_USERNAME / UPAAS_METRICS_PASSWORD: /metrics is served only when the username is set, behind basic auth with these credentials.
UPAAS_MAINTENANCE_MODE (default false): only shown as maintenanceMode in the /health response; it blocks nothing.
UPAAS_SESSION_SECRET: signs session cookies and CSRF tokens. When unset, a random secret is generated once and kept in $UPAAS_DATA_DIR/session.key.
UPAAS_CORS_ORIGINS: comma-separated origins allowed to make cross-origin requests with cookies. Unset means no CORS headers are sent.
The Docker client (internal/docker/client.go) also reads the standard DOCKER_API_VERSION, DOCKER_CERT_PATH and DOCKER_TLS_VERIFY; UPAAS_DOCKER_HOST (which has a default) always overrides DOCKER_HOST. One sentence under the table covers this.
Also: one dated entry at the top of Completed Steps in TODO.md, in the style of the others, ending with this issue's number.
Out of scope: code changes; the YAML config file upaas can also read; the Compose port problem, which is filed separately.
Model: opus-5-5
The Configuration table in `README.md` leaves out three settings upaas reads (`UPAAS_MAINTENANCE_MODE`, `UPAAS_SESSION_SECRET`, `UPAAS_CORS_ORIGINS`), and several rows it has give the wrong default or effect. Found while fixing https://git.eeqj.de/sneak/upaas/issues/224.
Definition of done: every setting upaas reads from the environment is in the table, with its real name, default and effect, checked against `internal/config/config.go` and the code that uses each value. Docs only.
What the code does today (verify each before writing it down):
- `PORT`: upaas also reads `UPAAS_PORT`, and `UPAAS_PORT` wins when both are set (the config library looks up the prefixed name first).
- `UPAAS_HOST_DATA_DIR`: when unset it takes the value of `UPAAS_DATA_DIR`; when set it must be an absolute path or upaas refuses to start. It is needed when upaas runs in a container.
- `UPAAS_DEBUG`: turns on debug logging and also drops the `Secure` flag from the session cookie (`internal/service/auth/auth.go`).
- `UPAAS_SENTRY_DSN`: read but not used anywhere; upaas sends nothing to Sentry. The row must say so instead of promising error reporting.
- `UPAAS_METRICS_USERNAME` / `UPAAS_METRICS_PASSWORD`: `/metrics` is served only when the username is set, behind basic auth with these credentials.
- `UPAAS_MAINTENANCE_MODE` (default false): only shown as `maintenanceMode` in the `/health` response; it blocks nothing.
- `UPAAS_SESSION_SECRET`: signs session cookies and CSRF tokens. When unset, a random secret is generated once and kept in `$UPAAS_DATA_DIR/session.key`.
- `UPAAS_CORS_ORIGINS`: comma-separated origins allowed to make cross-origin requests with cookies. Unset means no CORS headers are sent.
- The Docker client (`internal/docker/client.go`) also reads the standard `DOCKER_API_VERSION`, `DOCKER_CERT_PATH` and `DOCKER_TLS_VERIFY`; `UPAAS_DOCKER_HOST` (which has a default) always overrides `DOCKER_HOST`. One sentence under the table covers this.
Also: one dated entry at the top of Completed Steps in `TODO.md`, in the style of the others, ending with this issue's number.
Out of scope: code changes; the YAML config file upaas can also read; the Compose port problem, which is filed separately.
Model: opus-5-5
clawbot
self-assigned this 2026-09-29 02:51:17 +02:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The Configuration table in
README.mdleaves out three settings upaas reads (UPAAS_MAINTENANCE_MODE,UPAAS_SESSION_SECRET,UPAAS_CORS_ORIGINS), and several rows it has give the wrong default or effect. Found while fixing #224.Definition of done: every setting upaas reads from the environment is in the table, with its real name, default and effect, checked against
internal/config/config.goand the code that uses each value. Docs only.What the code does today (verify each before writing it down):
PORT: upaas also readsUPAAS_PORT, andUPAAS_PORTwins when both are set (the config library looks up the prefixed name first).UPAAS_HOST_DATA_DIR: when unset it takes the value ofUPAAS_DATA_DIR; when set it must be an absolute path or upaas refuses to start. It is needed when upaas runs in a container.UPAAS_DEBUG: turns on debug logging and also drops theSecureflag from the session cookie (internal/service/auth/auth.go).UPAAS_SENTRY_DSN: read but not used anywhere; upaas sends nothing to Sentry. The row must say so instead of promising error reporting.UPAAS_METRICS_USERNAME/UPAAS_METRICS_PASSWORD:/metricsis served only when the username is set, behind basic auth with these credentials.UPAAS_MAINTENANCE_MODE(default false): only shown asmaintenanceModein the/healthresponse; it blocks nothing.UPAAS_SESSION_SECRET: signs session cookies and CSRF tokens. When unset, a random secret is generated once and kept in$UPAAS_DATA_DIR/session.key.UPAAS_CORS_ORIGINS: comma-separated origins allowed to make cross-origin requests with cookies. Unset means no CORS headers are sent.internal/docker/client.go) also reads the standardDOCKER_API_VERSION,DOCKER_CERT_PATHandDOCKER_TLS_VERIFY;UPAAS_DOCKER_HOST(which has a default) always overridesDOCKER_HOST. One sentence under the table covers this.Also: one dated entry at the top of Completed Steps in
TODO.md, in the style of the others, ending with this issue's number.Out of scope: code changes; the YAML config file upaas can also read; the Compose port problem, which is filed separately.
Model: opus-5-5