Configuration¶
The server reads these environment variables.
| Variable | Default | Meaning |
|---|---|---|
SUFS_DB_PATH |
sufs-tracker.db (image: /data/sufs-tracker.db) |
The SQLite file. Created or upgraded on startup. |
SUFS_STATIC_DIR |
dist/server (image: /app/static) |
Where the server writes the pages it serves at startup. |
SUFS_DOCS_DIR |
site (image: /app/docs) |
A built copy of this documentation, served at /docs/ when the directory exists. |
SUFS_FILES_DIR |
files next to the database (image: /data/files) |
Where attached files are stored, one directory per account. Back it up with the database. |
SUFS_FILES_QUOTA_MB |
1024 |
How many megabytes of attached files one account may hold. |
compose.yaml and compose.dev.yaml additionally read these from .env (see .env.example):
| Variable | Default | Meaning |
|---|---|---|
SUFS_TRACKER_IMAGE |
sufs-tracker:local |
Image to run; set it to the registry image CI pushed. |
SUFS_TRACKER_HOSTNAME |
sufs-tracker.local |
Host name Traefik routes to the container. |
TRAEFIK_ENTRYPOINTS |
web |
Traefik entrypoint(s) for the router, comma separated. |
TRAEFIK_TLS |
false |
Terminate TLS on Traefik for this router. |
TRAEFIK_NETWORK |
traefik |
The external network Traefik is attached to. |
SUFS_TRACKER_PORT |
8000 |
Dev override only: host port published on 127.0.0.1. |
COMPOSE_FILE |
compose.yaml |
Set to compose.yaml:compose.dev.yaml to use the dev override by default. |
The container also gets FORWARDED_ALLOW_IPS=*, so uvicorn trusts the proxy's X-Forwarded-Proto header and marks the session cookie Secure over https.
Limits¶
Sessions last 30 days and are extended while in use. Join codes and invitations last 7 days. API tokens don't expire; users revoke them. Sign-in is throttled to ten failures per address and username in five minutes (kept in memory per process).
Attached files: at most 20 MB each, SUFS_FILES_QUOTA_MB per account, and only these types: PDF; JPEG, PNG, WebP, GIF, HEIC/HEIF images; plain text and CSV; Word (.docx), Excel (.xlsx), OpenDocument text and spreadsheet. Nothing a browser would execute (HTML, SVG, scripts) is accepted, since files are served from the tracker's own address. PDFs and images open in the browser; other types download.
Nothing is configurable on the standalone page; its behaviour is fixed at build time.