Zum Hauptinhalt springen

Environment Generator

Der Generator ist direkt in diese Dokumentationsseite eingebettet. Er erstellt eine vollständige deploy.yaml für Docker Compose, Portainer, NAS-Stacks oder Hosting-Plattformen wie Mittwald – ohne die Doku zu verlassen. Beim Öffnen prüft er die neueste StatO-Version über das öffentliche GitHub-Release; wenn GitHub nicht erreichbar ist, verwendet er einen sichtbaren geprüften Fallback.

Docker-Compose-Stack erzeugen

Die Datei wird ausschließlich in deinem Browser erstellt. Datenbankpasswort und JWT-Secret werden nicht übertragen.

deploy.yaml

# StatO Docker-Compose-Deployment
# Enthält Secrets: sicher aufbewahren und niemals in Git committen.

name: stato

x-hardened: &hardened
  restart: unless-stopped
  read_only: true
  security_opt: [no-new-privileges:true]
  cap_drop: [ALL]

services:
  postgres:
    image: postgres:16-alpine
    restart: unless-stopped
    security_opt: [no-new-privileges:true]
    environment:
      POSTGRES_DB: stato_prod
      POSTGRES_USER: stato_user
      POSTGRES_PASSWORD: "StatoDb_c95aacecb269167e6a9fcc3ff85ae361e2bf2770daf519d9_A9!"
      TZ: Europe/Berlin
    volumes:
      - postgres-data:/var/lib/postgresql/data
    healthcheck:
      test: [CMD-SHELL, "pg_isready -U stato_user -d stato_prod"]
      interval: 10s
      timeout: 5s
      retries: 10

  backend:
    <<: *hardened
    image: "ghcr.io/hubertoink/stato-backend:1.7.1"
    tmpfs: [/tmp]
    environment:
      NODE_ENV: production
      APP_ENV: production
      STRICT_SECURITY_MODE: "true"
      TZ: Europe/Berlin
      API_PREFIX: api
      APP_ORIGIN: "http://localhost:8088"
      CORS_ORIGINS: "http://localhost:8088"
      TRUST_PROXY: "true"
      AUTH_REFRESH_COOKIE_SECURE: "false"
      AUTH_REFRESH_COOKIE_SAMESITE: lax
      DB_HOST: postgres
      DB_USERNAME: stato_user
      DB_PASSWORD: "StatoDb_c95aacecb269167e6a9fcc3ff85ae361e2bf2770daf519d9_A9!"
      DB_DATABASE: stato_prod
      DB_SYNCHRONIZE: "false"
      DB_MIGRATIONS_RUN: "true"
      DB_BOOTSTRAP_ON_EMPTY: "true"
      JWT_SECRET: "712c1882a0c53364a1fa081d7749ecfee3151f05ad101562481d9c6cb98198db35afa941d7d1d7a340de0d2a992b8006"
      PASSWORD_RESET_MODE: "admin_temp_password"
      USER_PROVISIONING_MODE: "local"
      AUTH_2FA_ENABLED: "false"
      AUTH_2FA_CODE_TTL: "600"
      SUPERADMIN_EMAIL: "admin@stato.local"
      INITIAL_SETUP_ENABLED: "true"
      PUBLIC_APP_NAME: "StatO"
      PUBLIC_ORG_NAME: "Meine Organisation"
      PUBLIC_LOGIN_SUBTITLE: "OKJA Statistik und Dokumentation"
      RATE_LIMIT_TTL: "60"
      RATE_LIMIT_MAX: "100"
      AUTH_RATE_LIMIT_TTL: "60"
      AUTH_RATE_LIMIT_MAX: "10"
    depends_on:
      postgres:
        condition: service_healthy
    volumes:
      - backend-uploads:/app/uploads

  frontend:
    <<: *hardened
    image: "ghcr.io/hubertoink/stato-frontend:onprem-1.7.1"
    tmpfs: [/tmp, /var/cache/nginx, /var/run]
    depends_on: [backend]
    ports:
      - "8088:8080"

  backup:
    <<: *hardened
    image: "ghcr.io/hubertoink/stato-backup:1.7.1"
    tmpfs: [/tmp]
    environment:
      PGHOST: postgres
      PGUSER: stato_user
      PGPASSWORD: "StatoDb_c95aacecb269167e6a9fcc3ff85ae361e2bf2770daf519d9_A9!"
      PGDATABASE: stato_prod
      BACKUP_OUTPUT_DIR: /backups
      BACKUP_UPLOADS_DIR: /mnt/uploads
      BACKUP_RETENTION_DAYS: "14"
    depends_on:
      postgres:
        condition: service_healthy
    volumes:
      - backend-uploads:/mnt/uploads:ro
      - backup-data:/backups

volumes:
  postgres-data:
  backend-uploads:
  backup-data:

Danach deployen​

Speichere die erzeugte Datei als deploy.yaml und importiere sie in deine Plattform oder starte sie auf dem Server:

docker compose -f deploy.yaml up -d

Die Datei enthält Datenbankpasswort und JWT-Secret. Bewahre sie geschützt auf und committe sie niemals in ein Repository.

HTTPS und Reverse Proxy​

Der generierte Stack ist für HTTP hinter einem vorhandenen Reverse Proxy konzipiert. Bei Mittwald, Portainer oder ähnlichen Plattformen hinterlegst du dort Domain und TLS und trägst hier die vollständige spätere Adresse ein, z. B. https://stato.example.org.

Für internes HTTPS mit Caddy nutzt du weiterhin die Ausgabe stato.env aus dem Release-Bundle. Die einzelnen Konfigurationsmöglichkeiten stehen in der Environment-Variablen-Referenz.