Docs › Installation guide
Configuration
All settings live in the .env file next to docker-compose.yml. After any
change, apply it with:
docker compose up -d
Only the services whose settings changed are recreated. The complete list is in Environment variables.
Domain and HTTPS
DEPMAP_DOMAIN is the public name of your server, without https://.
Caddy obtains and renews a Let's Encrypt certificate for it automatically
and redirects HTTP to HTTPS.
To also answer on other names (for example www.), list them in
DEPMAP_REDIRECT_HOSTS, separated by spaces. Each needs a DNS record
pointing at the server; Caddy redirects them to DEPMAP_DOMAIN.
Changing the domain later
Passkeys are bound to the domain. If you move InfraMole to a different domain, users must register their passkeys again (passwords and 2FA keep working).
Emails are used for address verification, password reset and invitations.
SMTP_URL=smtps://user:password@smtp.example.com:465
MAIL_FROM="InfraMole <inframole@example.com>"
Use smtp://…:587 for STARTTLS. When email is configured, new accounts must
verify their address before signing in. Without it, emails are not sent and
invitation links are shown on screen for you to share.
Encrypted backups
Nightly backups are written to ./backups. To encrypt them before they
touch the disk, create an age key pair on
another machine and put only the public key in .env:
age-keygen -o inframole-backup-key.txt # keep this file OFF the server
# Public key: age1…
BACKUP_AGE_RECIPIENT=age1...
See Backup and restore.
Sign in with Google or Microsoft
Optional. Create an OAuth app with the provider, register the redirect URI and set the client id and secret:
| Provider | Redirect URI | Variables |
|---|---|---|
https://<your domain>/api/auth/callback/google |
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET |
|
| Microsoft (Entra ID) | https://<your domain>/api/auth/callback/microsoft |
MICROSOFT_CLIENT_ID, MICROSOFT_CLIENT_SECRET, MICROSOFT_TENANT_ID |
MICROSOFT_TENANT_ID=organizations accepts work and school accounts only;
set your tenant id to restrict sign-in to your organisation.
Agent downloads
The enrollment dialog shows commands that download the agent from the
official releases, verify its
checksum and install it in one go. To use your own mirror, set
AGENT_DOWNLOAD_BASE_URL to its …/latest/download address.
Ports
Caddy publishes ports 80 and 443. HTTP_PORT and HTTPS_PORT change the
host ports, but Let's Encrypt only works on 80/443 — other ports are for
setups with CADDY_TLS=tls internal.
Local trial without a public name
For an evaluation on a laptop or a private network:
DEPMAP_DOMAIN=localhost
CADDY_TLS=tls internal
Caddy then issues certificates from its own authority. Browsers warn until you trust it; agents on other machines will not trust it. Do not use this for production.
Invite-only sign-up
By default anyone who can reach your server can create an account. To make the installation invite-only, create your own account first, then set:
SIGNUP=closed
and run docker compose up -d. From then on only people you invite from
Settings › Members can create an account (with the invited address). The
very first account of an installation can always be created.
Business licence
Several workspaces, priority support or a commercial licence instead of the
AGPL are part of InfraMole Business.
Set it in .env and restart:
EDITION=business
DEPMAP_LICENSE_KEY=dml1....
The licence is verified offline — InfraMole never calls home. See Editions and limits.
