Configuration
All settings are loaded from .env in the backend directory.
All settings are loaded from .env in the backend directory.
Backend .env
SECRET_KEY=your-long-random-secret-key
ADMIN_USERNAME=admin
ADMIN_PASSWORD_HASH=$2b$12$... # bcrypt hash
SERVICES_BASE_DIR=/opt/pycon # file browser root
ALLOWED_ORIGINS=http://YOUR_IP:3000
VENV_PYTHON=/usr/bin/python3| Variable | Required | Description |
|---|---|---|
SECRET_KEY | required | Random secret for JWT signing. Generate with python3 -c "import secrets; print(secrets.token_hex(32))" |
ADMIN_USERNAME | required | Login username for the admin account |
ADMIN_PASSWORD_HASH | required | bcrypt hash of your password |
SERVICES_BASE_DIR | required | Root directory exposed by the file browser and project manager |
ALLOWED_ORIGINS | required | CORS allowed origins — must match the URL you open in the browser exactly |
VENV_PYTHON | optional | Python binary used to create virtual envs. Defaults to /usr/bin/python3 |
Generate Password Hash
cd /opt/pycon/backend && venv/bin/python3 -c "
import bcrypt
hash = bcrypt.hashpw(b'your-password', bcrypt.gensalt()).decode()
with open('.env', 'r') as f: content = f.read()
import re
content = re.sub(r'ADMIN_PASSWORD_HASH=.*', f'ADMIN_PASSWORD_HASH={hash}', content)
with open('.env', 'w') as f: f.write(content)
print('Hash written to .env')
"Warning —
ALLOWED_ORIGINSmust match your browser URL exactly. If you access the dashboard athttp://1.2.3.4:3000, setALLOWED_ORIGINS=http://1.2.3.4:3000. Usinglocalhostwhile accessing by server IP causes login to fail silently.
Frontend .env.local
NEXT_PUBLIC_API_URL=http://YOUR_SERVER_IP:8000Warning — This value is baked in at build time. Set it before running
npm run build— changing it afterwards requires a rebuild.