mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-28 04:38:59 +00:00
32a7d53b2b
* feat: add RBAC viewer accounts, atomic deployments, and fleet-wide backups (Pro) Introduces three Pro-tier features: - RBAC: Multi-user system with admin/viewer roles, user management UI, automatic migration from single-admin credentials, viewer restrictions across the entire UI (read-only editor, hidden action buttons) - Atomic Deployments: Pre-deploy file backup to .sencho-backup/, automatic rollback on health probe failure, manual rollback button, health probes added to stack updates, webhook-triggered deploys use atomic rollback - Fleet-Wide Backups: Point-in-time snapshots of compose files across all nodes (local + remote), stored centrally in SQLite, per-stack restore with optional redeploy, graceful handling of offline nodes * fix(settings): use correct ProGate prop name in UsersSection * fix(settings): remove unused isPro prop from UsersSection * fix(auth): fetch user info after login and setup so isAdmin is set correctly * feat(pricing): revise pricing strategy and enforce variant-based seat limits Raise Personal Pro from $49/yr to $69/yr with 3 viewer seats (up from 1). Add $15/mo billing option for Team Pro. Mark lifetime pricing as a 90-day early-adopter offer. Store Lemon Squeezy variant_name on activation/validation and enforce seat limits server-side per variant. * feat(licensing): add Lemon Squeezy checkout, webhook, and billing portal integration Server-side checkout URL generation (POST /api/checkout) with admin email pre-fill and instance_id custom data. HMAC-SHA256 verified webhook endpoint (POST /api/webhooks/lemonsqueezy) handling order, subscription, and payment lifecycle events for automatic license activation. Customer billing portal link stored from webhook events and exposed via GET /api/billing/portal. In-app checkout buttons in Settings with manual license key fallback. * fix(licensing): exempt Lemon Squeezy webhook from auth middleware The catch-all auth middleware on /api/* was blocking the public webhook endpoint. Added /webhooks/lemonsqueezy to the exemption list alongside /auth/* and /webhooks/:id/trigger. * feat(pricing): update pricing to final live rates Personal Pro: $7.99/month, $69.99/year, $249 lifetime. Team Pro: $49.99/month, $499.99/year, $1,499 lifetime. Added personal_monthly checkout variant across backend, frontend, and website. * refactor(licensing): remove server-side checkout/webhook for self-hosted model Sencho is self-hosted — each user runs their own instance, so there is no central server to receive webhooks or hold the store API key. Replaced in-app checkout buttons with a "View Pricing" redirect to sencho.io and kept manual license key activation as the primary flow. - Delete LemonSqueezyService (checkout, webhook, HMAC verification) - Remove POST /api/checkout, GET /api/billing/portal, POST /api/webhooks/lemonsqueezy - Remove raw body parser and auth exemption for webhook route - Remove all LEMONSQUEEZY_* env vars from .env.example - Replace checkout buttons in SettingsModal with single "View Pricing" button - Simplify LicenseContext checkout to open sencho.io pricing page - Update licensing docs to reflect website-based purchase flow * chore: normalize em-dashes to hyphens across codebase (linter) * chore: remove accidentally tracked directories from index
162 lines
4.7 KiB
Plaintext
162 lines
4.7 KiB
Plaintext
---
|
|
title: Configuration
|
|
description: Environment variables, volume mounts, and the 1:1 path rule.
|
|
---
|
|
|
|
Sencho is configured entirely through environment variables and Docker volume mounts. There is no config file to edit inside the container.
|
|
|
|
## Required environment variables
|
|
|
|
| Variable | Description |
|
|
|----------|-------------|
|
|
| `JWT_SECRET` | Secret key used to sign session tokens. Use a long, random string (32+ characters). Changing this invalidates all active sessions. |
|
|
| `COMPOSE_DIR` | Absolute path to the directory that contains your Compose stacks. Every subdirectory inside becomes a stack in Sencho. |
|
|
|
|
## Optional environment variables
|
|
|
|
| Variable | Default | Description |
|
|
|----------|---------|-------------|
|
|
| `PORT` | `3000` | Port the Sencho HTTP server listens on. |
|
|
| `DATA_DIR` | `/app/data` | Directory where Sencho stores its SQLite database, node registry, and cached metrics. |
|
|
| `NODE_ENV` | `production` | Set automatically in the Docker image. Only change this for local development. |
|
|
|
|
## Required volume mounts
|
|
|
|
### Docker socket
|
|
|
|
Sencho needs access to the Docker daemon to manage containers:
|
|
|
|
```yaml
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
```
|
|
|
|
### Data directory
|
|
|
|
Sencho's database persists all your settings, nodes, alerts, and metrics history. Mount a named volume or host path so it survives container restarts:
|
|
|
|
```yaml
|
|
volumes:
|
|
- ./sencho-data:/app/data
|
|
```
|
|
|
|
<Warning>
|
|
Without a persistent data mount, Sencho will lose all configuration - including registered nodes, alerts, and settings - every time the container restarts.
|
|
</Warning>
|
|
|
|
### Compose directory - the 1:1 path rule
|
|
|
|
<Warning>
|
|
This is the most common source of deployment problems. Read carefully.
|
|
</Warning>
|
|
|
|
When Sencho runs `docker compose up`, it does so on your **host machine**. Docker resolves relative volume paths in your Compose files relative to the **host** path of the stack directory - not the path inside the Sencho container.
|
|
|
|
**The rule:** Mount your Compose directory at the **exact same path** inside the container as it exists on your host.
|
|
|
|
```yaml
|
|
# ✅ Correct - host path matches container path
|
|
volumes:
|
|
- /home/boris/docker:/home/boris/docker
|
|
environment:
|
|
- COMPOSE_DIR=/home/boris/docker
|
|
```
|
|
|
|
```yaml
|
|
# ❌ Wrong - paths differ, relative volumes will break
|
|
volumes:
|
|
- /home/boris/docker:/app/compose
|
|
environment:
|
|
- COMPOSE_DIR=/app/compose
|
|
```
|
|
|
|
If you use a simple path like `/opt/compose` on your host, mount it at `/opt/compose` in the container:
|
|
|
|
```yaml
|
|
volumes:
|
|
- /opt/compose:/opt/compose
|
|
environment:
|
|
- COMPOSE_DIR=/opt/compose
|
|
```
|
|
|
|
## Full docker-compose.yml example
|
|
|
|
```yaml
|
|
services:
|
|
sencho:
|
|
image: saelix/sencho:latest
|
|
restart: unless-stopped
|
|
ports:
|
|
- "3000:3000"
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
- ./sencho-data:/app/data
|
|
- /opt/compose:/opt/compose # 1:1 path rule
|
|
environment:
|
|
- JWT_SECRET=your-long-random-secret-here
|
|
- COMPOSE_DIR=/opt/compose
|
|
- DATA_DIR=/app/data
|
|
```
|
|
|
|
## Optional: global environment file
|
|
|
|
If your Compose stacks share common variables (e.g. `PUID`, `PGID`, `TZ`), you can pass an `env_file` to the Sencho container so those variables are available in the host environment when `docker compose` runs:
|
|
|
|
```yaml
|
|
services:
|
|
sencho:
|
|
image: saelix/sencho:latest
|
|
env_file:
|
|
- /opt/compose/globals.env # shared vars for all stacks
|
|
environment:
|
|
- JWT_SECRET=your-secret
|
|
- COMPOSE_DIR=/opt/compose
|
|
volumes:
|
|
- /var/run/docker.sock:/var/run/docker.sock
|
|
- /opt/compose:/opt/compose
|
|
- ./sencho-data:/app/data
|
|
```
|
|
|
|
## Reverse proxy setup
|
|
|
|
Sencho works behind any reverse proxy. The only requirement is that WebSocket connections are forwarded correctly (used for live logs, container terminals, and the host console).
|
|
|
|
### Nginx
|
|
|
|
```nginx
|
|
server {
|
|
listen 80;
|
|
server_name sencho.yourdomain.com;
|
|
|
|
location / {
|
|
proxy_pass http://localhost:3000;
|
|
proxy_http_version 1.1;
|
|
|
|
# WebSocket support
|
|
proxy_set_header Upgrade $http_upgrade;
|
|
proxy_set_header Connection "upgrade";
|
|
|
|
proxy_set_header Host $host;
|
|
proxy_set_header X-Real-IP $remote_addr;
|
|
proxy_read_timeout 3600s;
|
|
}
|
|
}
|
|
```
|
|
|
|
### Traefik (Docker labels)
|
|
|
|
```yaml
|
|
labels:
|
|
- "traefik.enable=true"
|
|
- "traefik.http.routers.sencho.rule=Host(`sencho.yourdomain.com`)"
|
|
- "traefik.http.services.sencho.loadbalancer.server.port=3000"
|
|
```
|
|
|
|
<Note>
|
|
Traefik handles WebSocket upgrades automatically for HTTP/1.1 backends. No extra configuration needed.
|
|
</Note>
|
|
|
|
## First boot
|
|
|
|
After starting Sencho, open it in your browser. If no admin account exists yet, you'll be taken to a setup screen to create one. This only appears once - subsequent visits go directly to the login page.
|