Server configuration, read at startup: where the database is, where
files go, limits. Changing it needs a restart. It’s described on this
page.
Site settings, stored in the database and changed while the site
runs: the site’s name, registration, the approval queue, the default
blacklist. Change them under Admin → Settings or with
moekura admin settings.
moekura.toml in the working directory, or the file given with
--config <path> or MOEKURA_CONFIG,
environment variables.
Every key has an environment variable MOEKURA_<SECTION>__<KEY> (two
underscores), for example MOEKURA_DATABASE__URL or
MOEKURA_STORAGE__S3__BUCKET. Lists are written as TOML, e.g.
MOEKURA_SERVER__TRUSTED_PROXIES='["10.0.0.0/8"]'. Unknown keys are refused, so
a typo fails loudly instead of being ignored.
moekura check-config validates the configuration and prints the result
with passwords redacted.
Lets people log in through an OpenID Connect provider (single sign-on):
Authentik, Keycloak, Kanidm, Zitadel, Google and others. Leave the section
out to turn it off.
Key
Default
Meaning
issuer
(required)
the provider’s issuer URL, which describes itself at /.well-known/openid-configuration under it; https://, or http:// on the same machine
client_id
(required)
from registering Moekura with the provider
client_secret
(empty)
likewise; empty for a public client
button_label
"Log in with single sign-on"
the button on the login page
scopes
["openid", "email", "profile"]
must include openid
Register the redirect URI https://your.site/login/oidc/callback (from
server.public_url) with the provider. Logins use the authorization code
flow with PKCE.
Someone logging in through the provider for the first time gets a new
account (with no password) when registration is open, or one waiting for
approval when it’s approval; with invite or closed, only people who
linked an existing account can. A new
account takes its name from the provider (the next free one if it’s
taken), and the provider’s email address if it says it’s verified,
nobody here uses it yet, and the site accepts its domain.
A captcha service for the sign-up form and new accounts’ comments: where
it’s asked for is chosen under Admin → Settings (nowhere, until
then). Leave the section out to turn it off.
Key
Default
Meaning
provider
(required)
"turnstile" (Cloudflare Turnstile) or "hcaptcha"
site_key
(required)
the public key the provider gives you
secret_key
(required)
the private key tokens are checked with
verify_url
(the provider’s)
where tokens are checked, for a proxy or a compatible service
The page asking for it loads the provider’s script and frame, which the
content security policy then allows from the provider’s origin.
Outgoing mail over SMTP, for email verification and password resets.
Messages are sent by the job workers, so a slow mail server doesn’t hold
up the site, and failed sends are retried.
Key
Default
Meaning
host
(empty)
the SMTP server; empty turns mail off, along with the features that need it
tls
"starttls"
"starttls" (upgrade a plain connection; required), "tls" (TLS from the start) or "none" (only for a relay on the same machine or network)
port
(by tls)
587 for starttls, 465 for tls, 25 for none
username, password
(empty)
the login, if the server needs one
from
(empty)
the sender, as address@example.com or Site name <address@example.com>; required with host
timeout_secs
30
connecting or sending one message gives up after this
Check the settings with moekura admin send-test-mail you@example.com,
which sends straight away and prints any error.
ugoira is Pixiv’s zip of animation frames; add "jxl" for JPEG XL (off by default: libvips doesn’t consider its decoder hardened against malicious files)
thumbnail_sizes
[250, 500]
thumbnail boxes, 1x and 2x for high-density screens
sample_size
1600
larger images also get a resized copy for the post page
variant_format
"webp"
"webp" or "avif" (smaller, slower) for thumbnails and samples