From ebd532f26fc91315a23b2d73f576dab6e39b2094 Mon Sep 17 00:00:00 2001 From: Timo Goetzken Date: Thu, 24 Sep 2026 15:59:37 +0200 Subject: [PATCH] docs(selfhost): show how to generate VAPID keys on a Docker install The only documented command, pnpm --filter @deft/api exec web-push generate-vapid-keys, needs a source checkout with pnpm. Docker operators have neither on the host; web-push already ships in the app image. Also list the VAPID variables in the self-hosting environment table. --- .env.example | 6 +++++- docs/self-hosting.md | 1 + 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/.env.example b/.env.example index 3d3452bd..2bc5d05e 100644 --- a/.env.example +++ b/.env.example @@ -133,7 +133,11 @@ DEFT_AUDIT_BYPASS_TOKEN= METRICS_SCRAPE_TOKEN= # ── 7. Browser notifications (optional) ─────────────── -# Generate once with: pnpm --filter @deft/api exec web-push generate-vapid-keys +# Generate once from a source checkout with: +# pnpm --filter @deft/api exec web-push generate-vapid-keys +# or, on a Docker install without pnpm, inside the running app container: +# docker compose exec -w /app/apps/api deft node_modules/.bin/web-push generate-vapid-keys +# VAPID_SUBJECT must start with mailto: or https://. # Keep this keypair stable; rotating it invalidates browser subscriptions. VAPID_PUBLIC_KEY= VAPID_PRIVATE_KEY= diff --git a/docs/self-hosting.md b/docs/self-hosting.md index 7f20a11a..b589e2ec 100644 --- a/docs/self-hosting.md +++ b/docs/self-hosting.md @@ -523,6 +523,7 @@ can supply its own AI independently of Deft's provider configuration. | `OLLAMA_URL` | No | Optional local Ollama endpoint; set only when running | none | | `R2_ENDPOINT` / `R2_ACCESS_KEY` / `R2_SECRET_KEY` / `R2_BUCKET` | No | Cloudflare R2 uploads | local uploads volume | | `METRICS_SCRAPE_TOKEN` | No | Bearer token for `/api/metrics` and `/health/queue`; unset disables detailed telemetry | none | +| `VAPID_PUBLIC_KEY` / `VAPID_PRIVATE_KEY` / `VAPID_SUBJECT` | No | Browser push notifications; set all three together, subject starting with `mailto:` or `https://`. Generate the keypair once (see `.env.example` section 7); rotating it invalidates existing browser subscriptions. Unset keeps the Inbox but disables Web Push | none | ### Opt-in Governed App Run keyrings