Configuration
Most settings can be configured from the frontend. A few must be set in the .env file.
For interactive setup:
bash gen-env.shOr manually copy .env-sample to .env and edit.
Secure Cookies
Bayanat uses secure cookies by default (requires HTTPS). For development:
SECURE_COOKIES=FalseDANGER
Do not disable secure cookies in production.
Secret Key
SECRET_KEY keeps sessions secure. Generate a strong key:
python3 -c "import secrets; print(secrets.token_hex(32))"WARNING
Changing the secret key logs out all users.
PostgreSQL
Required for Docker deployment. Optional for native installs on the same host.
POSTGRES_DB: Database name (default:bayanat)POSTGRES_HOST: Host (empty for local,postgresfor Docker)POSTGRES_PASSWORD: Password (not required for local)POSTGRES_USER: Username (not required for local)
Redis
Required for Docker deployment.
REDIS_HOST: Host (empty for local,redisfor Docker)REDIS_PASSWORD: Password, if set
Password Salt
SECURITY_PASSWORD_SALT must be generated and kept secret:
python3 -c "import secrets; print(secrets.token_hex(32))"DANGER
Changing the password salt invalidates all user passwords.
Two-Factor Authentication
Generate a TOTP secret for SECURITY_TOTP_SECRETS:
python3 -c "import secrets; print(secrets.token_hex(32))"See Flask Security docs.
DANGER
Changing this secret invalidates all 2FA configurations.
Storage
Local
Media files stored in enferno/media/ relative to the application directory. An installer-managed v5 host keeps them in /opt/bayanat/shared/media, which the release symlinks into place, so the application path is the same either way.
Amazon S3
Configure the S3 bucket with correct policies, block public access, and set up CORS.
S3-compatible providers
Other S3-compatible services (for example OVHcloud, Cloudflare R2, MinIO, Wasabi or Backblaze B2) work the same way. Add the provider's endpoint to .env and restart Bayanat:
AWS_ENDPOINT_URL=https://s3.eu-west-par.io.cloud.ovh.net- Enter the bucket, access keys and region in the storage settings as usual. Use the region name exactly as your provider writes it, for example
eu-west-parorauto. - When the Content Security Policy is enabled, media from this endpoint is allowed automatically.
- If your provider rejects uploads because of checksums, also set
AWS_REQUEST_CHECKSUM_CALCULATION=when_requiredin.env. - The endpoint applies to every S3 connection Bayanat makes, including S3 backups.
S3 does not hold everything
Uploads made through the interface go straight to the bucket, but inline images in descriptions do not. They are always written to enferno/media/inline/ on the server, with no S3 path, so bucket versioning and replication do not cover them.
Back up that directory as well as the bucket. Imported files are staged locally and removed once uploaded, so they need no separate handling.
Large Files
For files over a few gigabytes, use server path import rather than browser upload. The file is read from disk, so no upload request is held open and no chunks are reassembled. See Media Import for the ETL_ALLOWED_PATH setup.
If you upload through the browser anyway, the file is sent in small chunks, so request body limits do not apply to the whole file. The last chunk assembles the file and moves it to storage in a single request, which must not time out:
- Raise Media Max Upload Size in System Administration. The default is 1000 MB, and larger files are rejected.
- Installs made with the installer need nothing else: Caddy and uWSGI set no request timeout there.
- On Docker, raise
UWSGI_HARAKIRIabove your slowest upload. See Docker. - Behind your own nginx, raise
proxy_read_timeout, which defaults to 60 seconds.
Search
Interactive searches run under a database statement timeout. When a search exceeds it, the query is cancelled and re-run by a background worker instead of failing, and the user is notified when the results are ready. See Search for what this looks like in the interface.
| Variable | Default | Purpose |
|---|---|---|
SEARCH_TIMEOUT | 30 | Seconds an interactive search may run before it is handed to the background. 0 disables the behaviour and searches run unbounded. |
BACKGROUND_SEARCH_TIME_LIMIT | 600 | Seconds the background re-run may take before it is abandoned. |
Background searches require a running Celery worker. Without one, users receive the "continuing in the background" message but never get results.
WARNING
Lowering SEARCH_TIMEOUT far below the default sends ordinary searches to the background, including the initial page load of a list view. Raise it instead if legitimate searches are being deferred.
Sessions and Login Throttling
| Variable | Default | Purpose |
|---|---|---|
SESSION_LIFETIME | 3600 | Seconds of inactivity before a session expires and the user must sign in again. |
LOGIN_RATE_LIMIT_PER_USERNAME | 10 per 15 minutes | Failed-login throttle applied per account, so one targeted account cannot be brute-forced from many addresses. |
LOGIN_RATE_LIMIT_PER_IP | 30 per 15 minutes | Failed-login throttle applied per source address, so one address cannot spray many accounts. |
Both throttles use the limits string syntax, for example 5 per minute or 100 per hour. They apply to the login endpoint only. Lowering SESSION_LIFETIME too far is a common cause of complaints about constant re-authentication.
Configuration File Location
| Variable | Default | Purpose |
|---|---|---|
BAYANAT_CONFIG_FILE | config.json | Path to the feature-toggle configuration file. |
Installer-managed deployments set this to a path outside the release directory, because releases are read-only to the services and config.json is written at runtime from the admin interface. Set it explicitly if you deploy releases as read-only trees.
Data Import
Enable path scanning with ETL_ALLOWED_PATH.
WARNING
Only enable path scanning when needed.
Backups
See Backups for configuration.
Offline Maps
For offline or privacy-focused deployments, run your own tile server using openstreetmap-tile-server. Update the Maps API Endpoint in system settings.