- README rewritten around a copy-paste quick start (CLI and Portainer), verified alert test, day-to-day NocoDB operations, troubleshooting table, FAQ - new docker-compose.allinone.yml: NocoDB (pinned 2026.09.0, SQLite) + monitor on a private network, with healthchecks and the Telegram IPv4 pin documented - docs/: QUICKSTART-PORTAINER, TELEGRAM-SETUP, NOCODB-SETUP, ARCHITECTURE, OPERATIONS, TROUBLESHOOTING (replace DOCUMENTATION.md + COMPOSE-SETUP.md) - secrets: SECRETS.md is gitignored and untracked; tracked template is SECRETS.example.md; real base id / chat id removed from .env.example - LICENSE (MIT), .gitignore/.dockerignore tidied - AGENTS.md: layout, iron rules, verification gates; host-specific deploy details moved to the gitignored OPS-INTERNAL.md
1.1 KiB
1.1 KiB
SECRETS.example.md — credential template
Copy to SECRETS.md (gitignored) or keep the values in your own secret store.
Never commit real credentials — the tracked repo carries only this template.
| Var | Value / source |
|---|---|
NOCODB_URL |
http://nocodb:8080 (all-in-one) or your existing NocoDB URL |
NOCODB_BASE_ID |
NocoDB → open the base → copy the id from the URL |
NOCODB_TOKEN |
NocoDB → Account Settings → Tokens → Create token (nc_pat_…) |
TELEGRAM_BOT_TOKEN |
@BotFather → /newbot → token |
TELEGRAM_CHAT_ID |
@userinfobot, or getUpdates for a group |
NC_AUTH_JWT_SECRET |
openssl rand -hex 32 (all-in-one stack only) |
Where the values are used
| Store | Used by | Committed? |
|---|---|---|
.env (repo root) |
docker compose local runs |
no (gitignored) |
| Portainer stack environment / stack file | Portainer deploys | no (lives on the Portainer host) |
SECRETS.md |
human inventory | no (gitignored) |
If a token ever leaks, regenerate it: NocoDB → Account Settings → Tokens
(revoke + create), Telegram → @BotFather → /revoke.