- README rewritten around a copy-paste quick start (CLI and Portainer), verified alert test, day-to-day NocoDB operations, troubleshooting table, FAQ - new docker-compose.allinone.yml: NocoDB (pinned 2026.09.0, SQLite) + monitor on a private network, with healthchecks and the Telegram IPv4 pin documented - docs/: QUICKSTART-PORTAINER, TELEGRAM-SETUP, NOCODB-SETUP, ARCHITECTURE, OPERATIONS, TROUBLESHOOTING (replace DOCUMENTATION.md + COMPOSE-SETUP.md) - secrets: SECRETS.md is gitignored and untracked; tracked template is SECRETS.example.md; real base id / chat id removed from .env.example - LICENSE (MIT), .gitignore/.dockerignore tidied - AGENTS.md: layout, iron rules, verification gates; host-specific deploy details moved to the gitignored OPS-INTERNAL.md
25 lines
1.1 KiB
Markdown
25 lines
1.1 KiB
Markdown
# SECRETS.example.md — credential template
|
|
|
|
Copy to `SECRETS.md` (gitignored) or keep the values in your own secret store.
|
|
**Never commit real credentials** — the tracked repo carries only this template.
|
|
|
|
| Var | Value / source |
|
|
|---|---|
|
|
| `NOCODB_URL` | `http://nocodb:8080` (all-in-one) or your existing NocoDB URL |
|
|
| `NOCODB_BASE_ID` | NocoDB → open the base → copy the id from the URL |
|
|
| `NOCODB_TOKEN` | NocoDB → Account Settings → Tokens → Create token (`nc_pat_…`) |
|
|
| `TELEGRAM_BOT_TOKEN` | @BotFather → `/newbot` → token |
|
|
| `TELEGRAM_CHAT_ID` | @userinfobot, or `getUpdates` for a group |
|
|
| `NC_AUTH_JWT_SECRET` | `openssl rand -hex 32` (all-in-one stack only) |
|
|
|
|
## Where the values are used
|
|
|
|
| Store | Used by | Committed? |
|
|
|---|---|---|
|
|
| `.env` (repo root) | `docker compose` local runs | no (gitignored) |
|
|
| Portainer stack environment / stack file | Portainer deploys | no (lives on the Portainer host) |
|
|
| `SECRETS.md` | human inventory | no (gitignored) |
|
|
|
|
If a token ever leaks, regenerate it: NocoDB → Account Settings → Tokens
|
|
(revoke + create), Telegram → @BotFather → `/revoke`.
|