DocumentationConfiguration

Rust · 0.1.0

Deployment-managed settings

Load authoritative settings from mounted files at startup.

File discovery

The server reads supported direct children of /etc/secrets during startup. An identity-provider file is named memos-idp-<label>.json; an instance-setting file is named memos-instance-setting-<label>.json. Use lowercase kebab-case labels. Each file contains one protobuf-JSON resource, not an envelope or a list. Unknown fields, invalid resources or duplicate stable keys can stop startup.

Runtime ownership

A deployment file overrides the stored resource with the same key for that process lifetime. It is not imported into database settings. UI/API writes to a deployment-managed resource are rejected. Editing a file requires a process restart; removing a file and restarting reveals the stored setting again rather than deleting it.

Protect and validate

Mount the files read-only with restrictive permissions. They can contain provider credentials; never put their contents in public documentation or logs. Supported setting groups include ACCESS, GENERAL, STORAGE, MEMO_RELATED, NOTIFICATION and AI. Validate against the matching store protobuf definitions in your source checkout; public API response schemas are not automatically valid deployment-file schemas.

Start with one non-secret ACCESS file

Create a directory for your deployment files and save the JSON below as memos-instance-setting-access.json. This is a store protobuf resource: key selects the group and accessSetting supplies its matching payload. It intentionally forces private instance access. It does not create users, revoke existing share tokens, or merge with individual fields from the stored ACCESS setting.

{
  "key": "ACCESS",
  "accessSetting": {
    "accessMode": "INSTANCE_ACCESS_MODE_PRIVATE"
  }
}

Mount, restart and check effective behavior

Mount your directory read-only at /etc/secrets. With the Docker Compose starting template, add the bind mount below alongside the existing data volume, then recreate the service with docker compose up -d. Do not drop the data volume. Files must remain readable by the runtime UID/GID; restrictive host permissions that prevent that read will stop startup. A JSON syntax check does not validate protobuf fields or cross-setting rules.

# Under services.memos in compose.yaml:
volumes:
  - memos-data:/var/opt/memos
  - ./deployment-secrets:/etc/secrets:ro

Whole groups replace, they do not patch

When a file supplies GENERAL, STORAGE, AI or another group, omitted scalar fields decode to protobuf defaults; they do not retain their database values. Empty secret fields do not preserve stored secrets. Review the entire group before adding an override. Unknown fields, duplicate keys, mismatched key/payload or files over 1 MiB are startup errors. After restart, verify health and the intended signed-out behavior; an application write to the overridden group should fail with FAILED_PRECONDITION. To return to stored configuration, remove the matching file and restart, then re-check the policy because the older database setting becomes effective again.