Configuration
Engine settings and all secrets come from environment variables. They never live in the content repo.
trunkcms runs in GitHub mode unless TRUNKCMS_CONTENT_DIR is set, which switches it to local mode and ignores the GitHub settings. Secrets marked † can also be read from a file: set NAME_FILE to the file’s path instead of setting NAME.
GitHub
| Variable | Notes |
|---|---|
TRUNKCMS_REPO |
Content repo: owner/name, github.com/owner/name, or a full URL. Required in GitHub mode. |
TRUNKCMS_SITE_URL |
The site’s URL, e.g. https://myblog.com. Used for OAuth callbacks; https:// makes session cookies Secure. |
TRUNKCMS_GITHUB_APP_ID |
GitHub App ID. |
TRUNKCMS_GITHUB_PRIVATE_KEY † |
App private key (RSA PEM). |
TRUNKCMS_GITHUB_CLIENT_ID |
App OAuth client ID, for sign-in. |
TRUNKCMS_GITHUB_CLIENT_SECRET † |
App OAuth client secret. |
TRUNKCMS_SESSION_KEY † |
Base64 key that decodes to 32 bytes. Comma-separate to rotate, newest first. |
TRUNKCMS_WEBHOOK_SECRET † |
Verifies push webhooks. Without it, changes arrive by polling only. |
TRUNKCMS_REPO_PATH |
Subdirectory holding the site, e.g. blog1. Default: repo root. |
TRUNKCMS_BRANCH |
Branch to serve and commit to. Default main. |
TRUNKCMS_GITHUB_INSTALLATION_ID |
Looked up from the repo if unset. |
TRUNKCMS_GITHUB_API_URL |
API base URL, for GitHub Enterprise Server. |
TRUNKCMS_GITHUB_WEB_URL |
Web base URL, for GitHub Enterprise Server. |
Runtime
| Variable | Notes |
|---|---|
TRUNKCMS_POLL_INTERVAL |
How often to check for new commits. Default 30s (2s in local mode). 0 disables polling. |
TRUNKCMS_DATA_DIR |
Scratch space for snapshots and rendered files. Default $TMPDIR/trunkcms-$PORT. |
TRUNKCMS_LOG_JSON |
Set to any value to log JSON. |
PORT |
Port to listen on. Default 8080. |
Local mode
| Variable | Notes |
|---|---|
TRUNKCMS_CONTENT_DIR |
Serve and edit this directory instead of GitHub. |
TRUNKCMS_DEV_USERS |
Dev logins as login:role pairs. Default dev-admin:admin,dev-editor:editor,dev-author:author. |
Several sites in one repo
Set TRUNKCMS_REPO_PATH to serve a subdirectory, and run one instance per site. Each instance reads and commits only inside its own directory. Keep in mind:
- Permissions are per repo. Anyone with push access is an admin on every site in it.
- A push to any site rebuilds all of them, since each instance tracks the branch head.
- A GitHub App has one webhook URL, so only one instance receives pushes directly. The others pick up changes by polling.