Configuration

Engine settings and all secrets come from environment variables. They never live in the content repo.

trunkcms runs in GitHub mode unless TRUNKCMS_CONTENT_DIR is set, which switches it to local mode and ignores the GitHub settings. Secrets marked † can also be read from a file: set NAME_FILE to the file’s path instead of setting NAME.

GitHub

Variable Notes
TRUNKCMS_REPO Content repo: owner/name, github.com/owner/name, or a full URL. Required in GitHub mode.
TRUNKCMS_SITE_URL The site’s URL, e.g. https://myblog.com. Used for OAuth callbacks; https:// makes session cookies Secure.
TRUNKCMS_GITHUB_APP_ID GitHub App ID.
TRUNKCMS_GITHUB_PRIVATE_KEY † App private key (RSA PEM).
TRUNKCMS_GITHUB_CLIENT_ID App OAuth client ID, for sign-in.
TRUNKCMS_GITHUB_CLIENT_SECRET † App OAuth client secret.
TRUNKCMS_SESSION_KEY † Base64 key that decodes to 32 bytes. Comma-separate to rotate, newest first.
TRUNKCMS_WEBHOOK_SECRET † Verifies push webhooks. Without it, changes arrive by polling only.
TRUNKCMS_REPO_PATH Subdirectory holding the site, e.g. blog1. Default: repo root.
TRUNKCMS_BRANCH Branch to serve and commit to. Default main.
TRUNKCMS_GITHUB_INSTALLATION_ID Looked up from the repo if unset.
TRUNKCMS_GITHUB_API_URL API base URL, for GitHub Enterprise Server.
TRUNKCMS_GITHUB_WEB_URL Web base URL, for GitHub Enterprise Server.

Runtime

Variable Notes
TRUNKCMS_POLL_INTERVAL How often to check for new commits. Default 30s (2s in local mode). 0 disables polling.
TRUNKCMS_DATA_DIR Scratch space for snapshots and rendered files. Default $TMPDIR/trunkcms-$PORT.
TRUNKCMS_LOG_JSON Set to any value to log JSON.
PORT Port to listen on. Default 8080.

Local mode

Variable Notes
TRUNKCMS_CONTENT_DIR Serve and edit this directory instead of GitHub.
TRUNKCMS_DEV_USERS Dev logins as login:role pairs. Default dev-admin:admin,dev-editor:editor,dev-author:author.

Several sites in one repo

Set TRUNKCMS_REPO_PATH to serve a subdirectory, and run one instance per site. Each instance reads and commits only inside its own directory. Keep in mind:

  • Permissions are per repo. Anyone with push access is an admin on every site in it.
  • A push to any site rebuilds all of them, since each instance tracks the branch head.
  • A GitHub App has one webhook URL, so only one instance receives pushes directly. The others pick up changes by polling.