Skip to content

Configuration

Comcent is configured with environment variables in ~/comcent-ce/.env. The installer writes this file with generated secrets and marks the values you must supply as replaceMe. After changing .env, apply it with:

Terminal window
cd ~/comcent-ce
docker compose up -d

Replace every replaceMe before the first start.

VariableSecretDescription
COMCENT_DOMAINPublic hostname, e.g. voice.example.com. Its DNS A record must point at PUBLIC_IP. The compose file derives the public URLs, the SIP domain and the browser dialer’s WebSocket URL from it.
LETSENCRYPT_EMAILEmail address Let’s Encrypt uses for certificate renewal notices.
SOURCE_EMAIL”From” address on outgoing email (invites, verification, password resets), e.g. Comcent <noreply@example.com>.
SMTP_URLSecretOutgoing mail server, as smtp://user:pass@host:port. Any provider works. Leave blank to disable email.
STORAGE_BUCKET_NAMES3 (or S3-compatible) bucket for call recordings and uploads.
AWS_ACCESS_KEY_IDSecretAccess key for the bucket. Not needed if the host uses an IAM role.
AWS_SECRET_ACCESS_KEYSecretSecret key for the bucket. Not needed if the host uses an IAM role.

Leave these blank to disable the feature.

VariableSecretDescription
DEEPGRAM_API_KEYSecretEnables transcription and the voice bot.
OPENAI_API_KEYSecretEnables AI summaries and analysis, and the voice bot.
SERVER_SENTRY_DSNSentry DSN for the API server.
PUBLIC_SENTRY_DSNSentry DSN for the web app.
AUTH_OIDC_PROVIDERS_JSONSecretSingle sign-on providers as JSON. The default {} keeps password login only. See OIDC sign-in.
AUTH_PASSWORD_ENABLEDtrue (default) allows email and password sign-in. Set to false to allow SSO only.
ALLOWED_SIGNUP_DOMAINComma-separated email domains that may self-register, e.g. acme.com,acme.co.uk. Empty (the default) means invite-only.

AUTH_OIDC_PROVIDERS_JSON maps a provider id to its OpenID Connect client settings. For example, for Google:

Terminal window
AUTH_OIDC_PROVIDERS_JSON={"google":{"label":"Google","client_id":"…","client_secret":"…","issuer":"https://accounts.google.com"}}
  • issuer is used for discovery (<issuer>/.well-known/openid-configuration).
  • scopes is optional and defaults to openid, email and profile.
  • Register https://<COMCENT_DOMAIN>/auth/callback/<provider id> as the redirect URI with your identity provider.
  • People signing in with SSO still need an invitation, or an email domain listed in ALLOWED_SIGNUP_DOMAIN.
VariableDefaultDescription
BUCKET_REGIONus-east-1Region of the bucket.
S3_ENDPOINT_URLemptyEndpoint of an S3-compatible service (for example MinIO). Leave empty for AWS S3.
S3_PROXY_DOWNLOADSfalseWhen true, the server streams recordings and files to the browser itself. When false, it redirects the browser to a pre-signed bucket URL. Use true if browsers cannot reach your storage endpoint directly.
VariableDefaultDescription
PUBLIC_IPdetected by the installerThe host’s public IPv4. The SBC advertises it in SIP headers and FreeSWITCH advertises it for SIP and RTP media. If detection failed, set it by hand.
SIP_WSS_PORT5063Host port for SIP over secure WebSocket (the browser dialer).
SBC_IP172.20.0.10The SBC’s fixed address on the internal Docker network. Matches the compose file; do not change it unless you also change the network there.
FS_LOCAL_NETWORK172.20.0.0/16The internal Docker subnet, which FreeSWITCH treats as local. Matches the compose file.

The installer generates these. If you create .env by hand, generate long random values yourself (see Installation).

VariableSecretDescription
POSTGRES_PASSWORDSecretPassword for the Postgres database.
RABBITMQ_PASSWORDSecretPassword for RabbitMQ.
INTERNAL_API_PASSWORDSecretPassword the SBC and FreeSWITCH use to call the server’s internal API.
RPC_API_TOKENSecretToken for control-plane calls between the server and the SBC.
SECRET_KEY_BASESecretPhoenix secret used by the API server.
SIGNING_KEYSecretKey that signs user session tokens. Changing it signs everyone out.

Usually left at their defaults.

VariableDefaultDescription
POSTGRES_USER, POSTGRES_DBcomcentDatabase user and name.
RABBITMQ_USERcomcentRabbitMQ user.
INTERNAL_API_USERNAMEinternal_apiUsername for the internal API.
COMCENT_VERSIONlatestImage tag for the server, web app and SBC. Pin a version (e.g. v0.1.0) for production stability.
FREESWITCH_VERSIONlatestImage tag for FreeSWITCH.
VOICE_BOT_VERSIONlatestImage tag for the voice bot.
ENVprodEnvironment name.
CLUSTER_STRATEGYgossipHow server nodes discover each other (gossip, or kubernetes for Kubernetes deployments).

The deployment compose file computes these from the values above, so you do not put them in .env for a standard install. They appear in the repository’s .env.example, which is used for local development.

VariableValue in the deployment
PUBLIC_BASE_URLhttps://${COMCENT_DOMAIN}. Single source for the public URL; the server and web app derive their hostnames and the SIP domain from it.
PUBLIC_SIP_WS_URLwss://${COMCENT_DOMAIN}:${SIP_WSS_PORT}/sip-ws, the browser dialer’s WebSocket URL.
DATABASE_URLBuilt from the POSTGRES_* variables.
REDIS_URLredis://redis:6379
RABBITMQ_URLBuilt from the RABBITMQ_* variables.
INTERNAL_API_BASE_URLThe server’s internal API on the Docker network.

DEV_IP, DEV_RABBITMQ_USERNAME and DEV_RABBITMQ_PASSWORD in .env.example are only used for local development. See Contributing.