Skip to main content

configuration

everything goes in .env, next to the compose file. every setting has a sensible default.

the server

variabledefault
TUCK_FEATURESbothssh, files or both
TUCK_TRUSTED_PROXIESyour proxy's address or cidr range, comma-separated. required behind a proxy
TUCK_SECURE_COOKIEStruefalse only for local testing over plain http
TUCK_SESSION_HOURS12the longest a login lasts
TUCK_FREEZE_AFTER6timed lockouts before the account freezes
TUCK_MAX_FILE_MB25the largest file
TUCK_MAX_ITEMS5000items per account
TUCK_MAX_STORAGE_MB1024storage per account

the front door

variabledefault
TUCK_GATE_PASSWORDhides the login page until it's typed. see the front door
TUCK_GATE_WORDtuck.what the hidden page shows, up to 64 characters

the database

variabledefault
POSTGRES_PASSWORDthe bundled postgres only. letters and digits
TUCK_DATABASE_URLyour own postgres only. see your own postgres
TUCK_DB_SCHEMAtuckthe schema tuck's tables live in
TUCK_DB_ALLOW_PLAINTEXTfalseallow a remote database without tls

compose

variabledefault
TUCK_VERSIONlatestthe image tag to run
TUCK_BIND127.0.0.1the address compose publishes tuck on
TUCK_PORT8080the port compose publishes tuck on

commands

docker compose exec tuck /tuck assets

prints the sha-256 of every file tuck serves, so you can check them against your own build. /tuck healthcheck is what docker's health check runs.