From 2b625b04f22bc41e5bd6b6aa1e7b6f8550d64b86 Mon Sep 17 00:00:00 2001 From: "Andrey A." <56412611+aantti@users.noreply.github.com> Date: Mon, 16 Feb 2026 15:12:03 +0100 Subject: [PATCH] fix: add minio password generator and amend docs --- apps/docs/content/guides/self-hosting/docker.mdx | 4 ++++ docker/utils/generate-keys.sh | 4 ++++ 2 files changed, 8 insertions(+) diff --git a/apps/docs/content/guides/self-hosting/docker.mdx b/apps/docs/content/guides/self-hosting/docker.mdx index eced3b834fb..365055a18b6 100644 --- a/apps/docs/content/guides/self-hosting/docker.mdx +++ b/apps/docs/content/guides/self-hosting/docker.mdx @@ -182,6 +182,10 @@ Edit the following settings in the `.env` file: - `PG_META_CRYPTO_KEY`: encryption key for securing connection strings used by Studio against postgres-meta. (Must be at least 32 characters; generate with `openssl rand -base64 24`) - `LOGFLARE_PUBLIC_ACCESS_TOKEN`: API token for log ingestion and querying. Used by Vector and Studio to send and query logs. (Must be at least 32 characters; generate with `openssl rand -base64 24`) - `LOGFLARE_PRIVATE_ACCESS_TOKEN`: API token for Logflare management operations. Used by Studio for administrative tasks. Never expose client-side. (Must be at least 32 characters; generate with `openssl rand -base64 24`) +- `S3_PROTOCOL_ACCESS_KEY_ID`: Access key ID (username-like) for authenticating API requests to S3-compatible storage. (Generate with `openssl rand -hex 16`) +- `S3_PROTOCOL_ACCESS_KEY_SECRET`: Secret key (password-like) used with S3_PROTOCOL_ACCESS_KEY_ID to sign and authorize S3 storage operations. (Generate with `openssl rand -hex 32`) +{/* supa-mdx-lint-disable-next-line Rule003Spelling */} +- `MINIO_ROOT_PASSWORD`: Root administrator password for the MinIO server. (Must be 8+ characters; generate with `openssl rand -hex 16`) Review and change URL environment variables: diff --git a/docker/utils/generate-keys.sh b/docker/utils/generate-keys.sh index e67c6957bc6..d9a16395bf6 100644 --- a/docker/utils/generate-keys.sh +++ b/docker/utils/generate-keys.sh @@ -60,6 +60,8 @@ logflare_private_access_token=$(gen_base64 24) s3_protocol_access_key_id=$(gen_hex 16) s3_protocol_access_key_secret=$(gen_hex 32) +minio_root_password=$(gen_hex 16) + echo "" echo "JWT_SECRET=${jwt_secret}" echo "" @@ -75,6 +77,7 @@ echo "LOGFLARE_PUBLIC_ACCESS_TOKEN=${logflare_public_access_token}" echo "LOGFLARE_PRIVATE_ACCESS_TOKEN=${logflare_private_access_token}" echo "S3_PROTOCOL_ACCESS_KEY_ID=${s3_protocol_access_key_id}" echo "S3_PROTOCOL_ACCESS_KEY_SECRET=${s3_protocol_access_key_secret}" +echo "MINIO_ROOT_PASSWORD=${minio_root_password}" echo "" postgres_password=$(gen_hex 16) @@ -114,6 +117,7 @@ sed \ -e "s|^LOGFLARE_PRIVATE_ACCESS_TOKEN=.*$|LOGFLARE_PRIVATE_ACCESS_TOKEN=${logflare_private_access_token}|" \ -e "s|^S3_PROTOCOL_ACCESS_KEY_ID=.*$|S3_PROTOCOL_ACCESS_KEY_ID=${s3_protocol_access_key_id}|" \ -e "s|^S3_PROTOCOL_ACCESS_KEY_SECRET=.*$|S3_PROTOCOL_ACCESS_KEY_SECRET=${s3_protocol_access_key_secret}|" \ + -e "s|^MINIO_ROOT_PASSWORD=.*$|MINIO_ROOT_PASSWORD=${minio_root_password}|" \ -e "s|^POSTGRES_PASSWORD=.*$|POSTGRES_PASSWORD=${postgres_password}|" \ -e "s|^DASHBOARD_PASSWORD=.*$|DASHBOARD_PASSWORD=${dashboard_password}|" \ .env