Configuration
Upvora is configured entirely through environment variables. The essentials are below; anything not set falls back to a sensible default.
Core
| Variable | Description |
|---|---|
BASE_URL | Public URL, e.g. https://feedback.example.com. |
DATABASE_URL | Postgres connection string. |
JWT_SECRET | Long random secret used to sign sessions. |
EMAIL_NOREPLY | The "from" address for outgoing mail. |
Email providers
Choose one provider with EMAIL (or it is inferred from whichever keys are set). EMAIL_NOREPLY must be an address on a domain your provider is allowed to send from.
| Provider | Variables |
|---|---|
| SMTP | EMAIL=smtp, EMAIL_SMTP_HOST, EMAIL_SMTP_PORT, EMAIL_SMTP_USERNAME, EMAIL_SMTP_PASSWORD, EMAIL_SMTP_ENABLE_STARTTLS |
| Mailgun | EMAIL=mailgun, EMAIL_MAILGUN_API, EMAIL_MAILGUN_DOMAIN, EMAIL_MAILGUN_REGION |
| Amazon SES | EMAIL=awsses, EMAIL_AWSSES_REGION, EMAIL_AWSSES_ACCESS_KEY_ID, EMAIL_AWSSES_SECRET_ACCESS_KEY |
| Resend | EMAIL=resend, EMAIL_RESEND_API_KEY |
Resend: set EMAIL_RESEND_API_KEY and make sure EMAIL_NOREPLY is on a domain you've verified in Resend. Upvora sends one request per recipient and retries briefly on rate limits.
Social sign-in
Google and GitHub are two env vars each; any other OAuth2/OIDC provider (Microsoft, Authentik, Keycloak…) is added from Admin → Authentication.
| Variable | Description |
|---|---|
OAUTH_GOOGLE_CLIENTID / OAUTH_GOOGLE_SECRET | Google sign-in. |
OAUTH_GITHUB_CLIENTID / OAUTH_GITHUB_SECRET | GitHub sign-in. |
OAuth callback URLs follow BASE_URL/oauth/<provider>/callback.
Other
- Passwordless email magic-link sign-in works out of the box.
- Prometheus metrics on
:4000(keep internal). - Tag-on-post is enabled by default.
Upvora is open source under AGPL-3.0 — a friendly fork of Fider, not affiliated with it.
· Built & maintained by