flowplanDocumentationStart page

Self-hosting

Configuration

All environment variables at a glance. Many values can also be set in the interface under Administration → Instance; values set there take precedence.

Required

VariableExampleMeaning
APP_URLhttps://flowplan.example.comThe public address exactly as it appears in the browser – scheme, host, port if any, without a trailing slash. The basis for sign-in redirects, cookies, passkeys, links in e-mails and push notifications and the origin check.

Sign-in

VariableDefaultMeaning
FLOWPLAN_LOCAL_LOGINonfalse turns off e-mail, password and passkeys; then only single sign-on remains.
OIDC_ISSUERemptyThe login provider for single sign-on. Without it there are only e-mail, password and passkeys.
OIDC_CLIENT_ID–Client ID.
OIDC_CLIENT_SECRET–Client secret. Never put it into the image or into Git.
SESSION_HOURS8How long a session lasts in hours (1–24).

The other OIDC variables and everything about passwords and passkeys are described under Sign-in.

Operations

VariableDefaultMeaning
FLOWPLAN_DATA_DIR/app/data in the image, ./data otherwiseData directory for SQLite, uploads, push keys and text recognition data.
FLOWPLAN_WORKSPACE_QUOTA_MBunlimitedDefault storage quota per workspace in MB (0 = unlimited).
FLOWPLAN_SNAPSHOT_RETENTION_DAYS180How long automatic versions are kept, in days (0 = forever).
FLOWPLAN_OCRon0 turns off text recognition for scanned PDFs and images.
FLOWPLAN_METRICS_TOKENemptyAt least 16 characters; enables /api/metrics in Prometheus format.
FLOWPLAN_TRUSTED_PROXIES1Number of proxies in front of Flowplan (Traefik alone: 1, Pangolin in front of Traefik: 2). Decides which entry in X-Forwarded-For is the real address – for limiting sign-in attempts, demo starts and anonymous form answers. Entries made up by the browser are ignored this way.
FLOWPLAN_PUBLIC_SITEemptyOnly for the official instance app.flowplan.org: true allows the public demo. Self-hosted instances leave it empty.

S3 and database backup

VariableDefaultMeaning
S3_BUCKETemptyTurns S3 on. Without this variable everything stays local.
S3_ENDPOINTAWSAPI address of the storage, e.g. http://minio:9000.
S3_ACCESS_KEY_ID / S3_SECRET_ACCESS_KEY–Access keys with read and write access to the bucket.
S3_REGIONus-east-1Region. Garage requires its own value (often garage).
S3_PREFIXflowplanFolder in the bucket; files under <prefix>/uploads/, the database under <prefix>/db/.
FLOWPLAN_LITESTREAMonoff: only mirror files, do not back up the database.

Details: Storage, S3 and backups.

E-mail (SMTP)

VariableDefaultMeaning
SMTP_HOSTemptyTurns on sending e-mail: invitations, address confirmations, password resets and digests of unread notifications.
SMTP_PORT587Port. With 465 Flowplan speaks TLS directly, STARTTLS otherwise.
SMTP_SECUREby porttrue/false forces TLS from the start of the connection.
SMTP_USER / SMTP_PASSWORDemptySign-in at the mail server.
SMTP_FROMFlowplan <SMTP_USER>Sender, e.g. Flowplan <[email protected]>.

Check delivery under Administration → Instance → Send test e-mail.

Integrations

VariableDefaultMeaning
FLOWPLAN_WEBHOOK_ALLOW_PRIVATEemptytrue allows webhooks to internal addresses and http:// – such as Home Assistant or n8n in the same network. Without this variable only public HTTPS addresses are allowed.

Voice notes (Whisper)

Voice notes in the editor are always stored as audio. With a Whisper service in your own network, Flowplan also turns them into text; the recording never leaves your server.

VariableDefaultMeaning
WHISPER_URLemptyAddress of an OpenAI-compatible Whisper server (POST /v1/audio/transcriptions), e.g. http://whisper:8000. Turns transcription on.
WHISPER_MODELSystran/faster-whisper-smallThe model name as the service expects it.
WHISPER_LANGUAGEdeLanguage of the recordings (e.g. en).
WHISPER_API_KEYemptyOnly if the service requires a key.

Example with speaches (formerly faster-whisper-server) in the same Compose project:

  whisper:
    image: ghcr.io/speaches-ai/speaches:latest-cpu
    volumes:
      - whisper-models:/home/ubuntu/.cache/huggingface/hub
    restart: unless-stopped

Then set WHISPER_URL=http://whisper:8000 for Flowplan. Newer speaches versions do not download models by themselves; download it once, for example from the Flowplan container:

node -e "fetch('http://whisper:8000/v1/models/Systran/faster-whisper-small',{method:'POST'}).then(r=>console.log(r.status))"

small needs about 1 GB of memory and transcribes roughly in real time on a normal CPU; base is faster and less accurate, medium more accurate and considerably slower. Do not make the Whisper service publicly reachable – only Flowplan talks to it.

Push notifications

VariableMeaning
WEB_PUSH_SUBJECTContact for the push services, e.g. mailto:[email protected].
WEB_PUSH_PUBLIC_KEY / WEB_PUSH_PRIVATE_KEYVAPID key pair. If not given, Flowplan creates one in FLOWPLAN_DATA_DIR/web-push-keys.json.

The keys must not change, otherwise all devices lose their subscription. Outgoing HTTPS to the push services of Apple, Google and Mozilla must be possible.

Do not set

The image sets NODE_ENV, PORT, HOSTNAME and NEXT_TELEMETRY_DISABLED itself. FLOWPLAN_DIST_DIR is only meant for parallel development servers, OIDC_ALLOW_LOCAL_HTTP only for tests with a provider on http://localhost.

In the interface

Under Administration → Instance, administrators set:

  • the instance name and a notice banner for everyone,
  • the default storage quota and how long versions are kept,
  • the maximum upload size,
  • whether everyone may create workspaces of their own,
  • whether anyone may sign up with e-mail and password,
  • the daily database backup and how many copies are kept,
  • after how many days without sign-in accounts are locked,
  • on app.flowplan.org: whether the website offers a demo (running and total started demos are shown under Administration → Operations).

Empty fields fall back to the environment variables.