GoDoxy
Getting Started

Environment Variables

GoDoxy server environment settings and migration

App settings use the first non-empty value in this order: GODOXY_, legacy GOPROXY_, then the unprefixed name. HTTPS_ADDR is the exception: the first present value wins, and an explicitly empty value disables shared HTTPS. The unprefixed fallback is deprecated but remains supported; rename app variables to GODOXY_ names. Compose inputs use their exact names and are not deprecated.

Copy .env.example to .env, set credentials, and uncomment only settings you override. The Compose example keeps socket-proxy. Its required deployment inputs are active in the example; missing Compose inputs fail with an instruction to set them in .env. GODOXY_DOCKER_HOST=tcp://${LISTEN_ADDR} selects that proxy. Compose does not inject or override a Docker endpoint, so another value in .env is respected. Keep the endpoint consistent with the chosen Docker service. When updating Compose while keeping an older .env, add GODOXY_DOCKER_HOST=tcp://${LISTEN_ADDR} (or retain an existing explicit endpoint). Without any endpoint setting, the server defaults to a Unix socket that this Compose example does not mount.

At startup, GoDoxy warns on unrecognized GODOXY_* names and selected unprefixed aliases, without printing their values. Custom names referenced by configuration interpolation still work, but are not recognized built-in settings. An info-level report shows effective server environment settings and their selected source; derived booleans may differ from the source value. Secrets, identity fields, and potentially credential-bearing URLs are redacted. These are environment settings, not per-route overrides or a report of active listeners.

Defaults below describe normal execution. TEST is also enabled in Go test executables; DEBUG defaults to effective TEST, but an explicit false overrides it. TRACE requires effective DEBUG. Server and websocket debug also honor explicit DEBUG=true, not test-derived debug. Durations use Go duration syntax; lists are comma-separated. Empty values fall through to aliases or the default except for HTTPS_ADDR.

For HTTP-only deployment, set GODOXY_HTTPS_ADDR=. This disables shared HTTPS, its HTTP/3 listener and shared TCP SNI routing, but not dedicated route listeners. redirectHTTP does not redirect in this mode. Direct HTTP login also requires GODOXY_API_JWT_SECURE=false; keep secure cookies when clients use an external TLS-terminating proxy. Unset HTTPS_ADDR still defaults to :443 and requires a certificate.

Compose inputs

VariableTypeDefaultDescription
TAGstringlatestContainer image tag.
TZstringEtc/UTCIANA timezone for log timestamps.
GODOXY_UIDint1000Container user ID; must own mounted directories.
GODOXY_GIDint1000Container group ID; must own mounted directories.
DOCKER_SOCKETstring/var/run/docker.sockHost Docker socket path; use /var/run/podman/podman.sock for Podman.
LISTEN_ADDRaddress127.0.0.1:2375Socket-proxy listener used by the Compose example.

Server settings

VariableTypeDefaultDescription
GODOXY_HTTP_ADDRaddress:80HTTP proxy listener.
GODOXY_HTTPS_ADDRaddress:443Shared HTTPS proxy listener; explicitly empty disables it (including shared HTTP/3 and TCP SNI routing). Dedicated route listeners are unaffected.
GODOXY_HTTP3_ENABLEDboolfalseEnable HTTP/3 on HTTPS, except with PROXY protocol.
GODOXY_SNI_ROUTING_FOR_TCP_ROUTESbooltrueRoute TCP over the shared HTTPS listener using TLS SNI.
GODOXY_API_ADDRaddress127.0.0.1:8888API and WebUI backend listener.
GODOXY_LOCAL_API_ADDRaddressemptyUnauthenticated local API listener; empty disables it.
GODOXY_LOCAL_API_ALLOW_NON_LOOPBACKboolfalseAllow unauthenticated local API outside loopback. Exposes unrestricted access.
GODOXY_API_JWT_SECUREbooltrueRequire HTTPS for login cookies.
GODOXY_API_JWT_SECRETstringemptyJWT signing key; generate with openssl rand -base64 32. Empty generates a temporary random key.
GODOXY_API_JWT_TOKEN_TTLduration24hLogin token lifetime.
GODOXY_API_USERstringemptyWebUI username; required with password unless OIDC or disabled authentication is used.
GODOXY_API_PASSWORDstringemptyWebUI password.
GODOXY_OIDC_ISSUER_URLstringemptyOIDC issuer URL; empty disables OIDC.
GODOXY_OIDC_CLIENT_IDstringemptyOIDC client ID.
GODOXY_OIDC_CLIENT_SECRETstringemptyOIDC client secret.
GODOXY_OIDC_SCOPESlistopenid, profile, email, groupsOIDC scopes; add offline_access if supported by the identity provider.
GODOXY_OIDC_ALLOWED_USERSlistemptyComma-separated users allowed to log in.
GODOXY_OIDC_ALLOWED_GROUPSlistemptyComma-separated groups allowed to log in.
GODOXY_OIDC_RATE_LIMITint10OIDC login requests allowed per period.
GODOXY_OIDC_RATE_LIMIT_PERIODduration1sOIDC login rate limit period.
GODOXY_FRONTEND_ALIASESlistgodoxyLegacy WebUI aliases, used only when webui.aliases is empty.
GODOXY_SHORTLINK_PREFIXstringgoPath prefix for short links.
GODOXY_INIT_TIMEOUTduration1mStartup initialization timeout; unavailable providers retry in the background.
GODOXY_DOCKER_HOSTstringunix:///var/run/docker.sockEndpoint used by providers configured as $DOCKER_HOST.
GODOXY_METRICS_DISABLE_CPUboolfalseDisable cpu metrics collection.
GODOXY_METRICS_DISABLE_MEMORYboolfalseDisable memory metrics collection.
GODOXY_METRICS_DISABLE_DISKboolfalseDisable disk metrics collection.
GODOXY_METRICS_DISABLE_NETWORKboolfalseDisable network metrics collection.
GODOXY_METRICS_DISABLE_SENSORSboolfalseDisable sensors metrics collection.
GODOXY_MAXMIND_COUNTRY_ONLYboolfalseUse Country instead of City databases; opt out of City downloads when unavailable. Country databases do not support timezone rules.
GODOXY_FORCE_RESOLVE_COUNTRYboolfalseAlways resolve the client country with GeoIP.
GODOXY_DEBUGboolfalseGeneral debug logging. Defaults to TEST or a Go test executable; explicit false overrides that default.
GODOXY_TRACEboolfalseTrace logging; effective only when DEBUG is enabled.
GODOXY_SERVER_DEBUGboolfalseHTTP server debug logging; explicit DEBUG=true also enables this, but test-derived DEBUG does not.
GODOXY_WEBSOCKET_DEBUGboolfalseWebsocket debug logging; explicit DEBUG=true also enables this, but test-derived DEBUG does not.

Development and testing only

Never enable these in production. DEBUG_DISABLE_AUTH disables authentication entirely.

VariableTypeDefaultDescription
GODOXY_API_SKIP_ORIGIN_CHECKboolfalseSkip API origin checks. Development only.
GODOXY_DEBUG_DISABLE_AUTHboolfalseDisable authentication entirely. Never enable in production.
GODOXY_TESTboolfalseTest mode; Go test executables always enable this. Development only.

On this page