Configuration
Comcent is configured with environment variables in ~/comcent-ce/.env. The installer writes this file with generated secrets and marks the values you must supply as replaceMe. After changing .env, apply it with:
cd ~/comcent-cedocker compose up -dRequired
Section titled “Required”Replace every replaceMe before the first start.
| Variable | Secret | Description |
|---|---|---|
COMCENT_DOMAIN | Public hostname, e.g. voice.example.com. Its DNS A record must point at PUBLIC_IP. The compose file derives the public URLs, the SIP domain and the browser dialer’s WebSocket URL from it. | |
LETSENCRYPT_EMAIL | Email address Let’s Encrypt uses for certificate renewal notices. | |
SOURCE_EMAIL | ”From” address on outgoing email (invites, verification, password resets), e.g. Comcent <noreply@example.com>. | |
SMTP_URL | Secret | Outgoing mail server, as smtp://user:pass@host:port. Any provider works. Leave blank to disable email. |
STORAGE_BUCKET_NAME | S3 (or S3-compatible) bucket for call recordings and uploads. | |
AWS_ACCESS_KEY_ID | Secret | Access key for the bucket. Not needed if the host uses an IAM role. |
AWS_SECRET_ACCESS_KEY | Secret | Secret key for the bucket. Not needed if the host uses an IAM role. |
Optional features
Section titled “Optional features”Leave these blank to disable the feature.
| Variable | Secret | Description |
|---|---|---|
DEEPGRAM_API_KEY | Secret | Enables transcription and the voice bot. |
OPENAI_API_KEY | Secret | Enables AI summaries and analysis, and the voice bot. |
SERVER_SENTRY_DSN | Sentry DSN for the API server. | |
PUBLIC_SENTRY_DSN | Sentry DSN for the web app. | |
AUTH_OIDC_PROVIDERS_JSON | Secret | Single sign-on providers as JSON. The default {} keeps password login only. See OIDC sign-in. |
AUTH_PASSWORD_ENABLED | true (default) allows email and password sign-in. Set to false to allow SSO only. | |
ALLOWED_SIGNUP_DOMAIN | Comma-separated email domains that may self-register, e.g. acme.com,acme.co.uk. Empty (the default) means invite-only. |
OIDC sign-in
Section titled “OIDC sign-in”AUTH_OIDC_PROVIDERS_JSON maps a provider id to its OpenID Connect client settings. For example, for Google:
AUTH_OIDC_PROVIDERS_JSON={"google":{"label":"Google","client_id":"…","client_secret":"…","issuer":"https://accounts.google.com"}}issueris used for discovery (<issuer>/.well-known/openid-configuration).scopesis optional and defaults toopenid,emailandprofile.- Register
https://<COMCENT_DOMAIN>/auth/callback/<provider id>as the redirect URI with your identity provider. - People signing in with SSO still need an invitation, or an email domain listed in
ALLOWED_SIGNUP_DOMAIN.
Storage
Section titled “Storage”| Variable | Default | Description |
|---|---|---|
BUCKET_REGION | us-east-1 | Region of the bucket. |
S3_ENDPOINT_URL | empty | Endpoint of an S3-compatible service (for example MinIO). Leave empty for AWS S3. |
S3_PROXY_DOWNLOADS | false | When true, the server streams recordings and files to the browser itself. When false, it redirects the browser to a pre-signed bucket URL. Use true if browsers cannot reach your storage endpoint directly. |
Network
Section titled “Network”| Variable | Default | Description |
|---|---|---|
PUBLIC_IP | detected by the installer | The host’s public IPv4. The SBC advertises it in SIP headers and FreeSWITCH advertises it for SIP and RTP media. If detection failed, set it by hand. |
SIP_WSS_PORT | 5063 | Host port for SIP over secure WebSocket (the browser dialer). |
SBC_IP | 172.20.0.10 | The SBC’s fixed address on the internal Docker network. Matches the compose file; do not change it unless you also change the network there. |
FS_LOCAL_NETWORK | 172.20.0.0/16 | The internal Docker subnet, which FreeSWITCH treats as local. Matches the compose file. |
Generated secrets
Section titled “Generated secrets”The installer generates these. If you create .env by hand, generate long random values yourself (see Installation).
| Variable | Secret | Description |
|---|---|---|
POSTGRES_PASSWORD | Secret | Password for the Postgres database. |
RABBITMQ_PASSWORD | Secret | Password for RabbitMQ. |
INTERNAL_API_PASSWORD | Secret | Password the SBC and FreeSWITCH use to call the server’s internal API. |
RPC_API_TOKEN | Secret | Token for control-plane calls between the server and the SBC. |
SECRET_KEY_BASE | Secret | Phoenix secret used by the API server. |
SIGNING_KEY | Secret | Key that signs user session tokens. Changing it signs everyone out. |
Service settings
Section titled “Service settings”Usually left at their defaults.
| Variable | Default | Description |
|---|---|---|
POSTGRES_USER, POSTGRES_DB | comcent | Database user and name. |
RABBITMQ_USER | comcent | RabbitMQ user. |
INTERNAL_API_USERNAME | internal_api | Username for the internal API. |
COMCENT_VERSION | latest | Image tag for the server, web app and SBC. Pin a version (e.g. v0.1.0) for production stability. |
FREESWITCH_VERSION | latest | Image tag for FreeSWITCH. |
VOICE_BOT_VERSION | latest | Image tag for the voice bot. |
ENV | prod | Environment name. |
CLUSTER_STRATEGY | gossip | How server nodes discover each other (gossip, or kubernetes for Kubernetes deployments). |
Set by the compose file
Section titled “Set by the compose file”The deployment compose file computes these from the values above, so you do not put them in .env for a standard install. They appear in the repository’s .env.example, which is used for local development.
| Variable | Value in the deployment |
|---|---|
PUBLIC_BASE_URL | https://${COMCENT_DOMAIN}. Single source for the public URL; the server and web app derive their hostnames and the SIP domain from it. |
PUBLIC_SIP_WS_URL | wss://${COMCENT_DOMAIN}:${SIP_WSS_PORT}/sip-ws, the browser dialer’s WebSocket URL. |
DATABASE_URL | Built from the POSTGRES_* variables. |
REDIS_URL | redis://redis:6379 |
RABBITMQ_URL | Built from the RABBITMQ_* variables. |
INTERNAL_API_BASE_URL | The server’s internal API on the Docker network. |
DEV_IP, DEV_RABBITMQ_USERNAME and DEV_RABBITMQ_PASSWORD in .env.example are only used for local development. See Contributing.