TALLYNOTE_HOST=127.0.0.1 TALLYNOTE_PORT=3000 TALLYNOTE_DATA_DIR=/var/lib/tallynote TALLYNOTE_INSTALL_PREFIX=/opt/tallynote TALLYNOTE_CONFIG_DIR=/etc/tallynote TALLYNOTE_PUBLIC_ORIGIN=http://127.0.0.1:3000 TALLYNOTE_COOKIE_SECURE=false TALLYNOTE_ALLOW_INSECURE_HTTP=false TALLYNOTE_TIMEZONE=Asia/Shanghai TALLYNOTE_UPDATE_STRATEGY=systemd TALLYNOTE_UPDATE_METADATA_URL=https://git.awaioi.com/api/v1/repos/awaioi/TallyNote/releases/latest TALLYNOTE_UPDATE_ALLOWED_HOSTS=git.awaioi.com TALLYNOTE_UPDATE_TIMEOUT_SECONDS=30 TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=false TALLYNOTE_UPDATE_CHECK_COOLDOWN_SECONDS=60 TALLYNOTE_UPDATE_DOWNLOAD_COOLDOWN_SECONDS=15 TALLYNOTE_UPDATE_APPLY_COOLDOWN_SECONDS=15 # Optional: configure a root-managed Ed25519 public key and set # TALLYNOTE_UPDATE_REQUIRE_SIGNATURE=true to require detached signatures. # TALLYNOTE_UPDATE_PUBLIC_KEY_FILE=/etc/tallynote/update-signing-key.pub # Reverse proxy trust. Leave this empty (or false) when TallyNote is reached # directly. When the service runs behind a reverse proxy, set the exact number # of proxy hops that terminate the client connection (a single nginx or caddy # layer uses 1). Without it every request appears to come from the proxy # address, so per-IP login lockouts degrade into a single shared global limit # and the API rate limiter below counts all clients as one. `true` is rejected # in production because it would let a client spoof its address. # TALLYNOTE_TRUST_PROXY=1 # Global API rate limit, per client address, in requests per minute. This is a # coarse anti-flood backstop for /api/* only; the login lockout, dangerous # operation confirmation and update cooldowns remain stricter and separate. # Defaults to 600 when unset, which is sufficient for normal browser use. # TALLYNOTE_RATE_LIMIT_PER_MINUTE=600