Skip to content
Garrul
  • Features
  • Install
  • FAQ
  • Theme builder
  • Configuration
  • About ·Privacy
  • GitHub

Configuration reference

The secrets file for wrangler secret bulk

The short version

Garrul runs as one Cloudflare Worker, and exactly two credentials are required: a Turnstile site key and a Turnstile secret key. Everything else on this page is optional and stays off until you set it. Two more required secrets are generated for you, so you never type them.

On this page

  1. Filling in and uploading the file
  2. Required: two credentials
  3. Optional, by feature
  4. Plain settings are not in this file
  5. Handling the file safely

1. Filling in and uploading the file

The repository ships secrets.example.env, a template with every secret listed, commented out, each with a note on where to get it. You copy it, uncomment what you need, upload it in one call, and delete it.

  1. Copy the template with owner-only permissions.
  2. Uncomment the two Turnstile lines and fill in the values. Uncomment anything optional you want.
  3. Upload every secret at once.
  4. Delete the file.
install -m 600 secrets.example.env secrets.env
# edit secrets.env
npx wrangler secret bulk secrets.env
rm secrets.env

If you would rather not edit a file, npm run setup asks for the same values, generates the random secrets, uploads everything in one call, and puts a working instance on a *.workers.dev URL. No DNS is needed to try Garrul.

2. Required: two credentials

Create a Turnstile widget in the Cloudflare dashboard. It gives you the pair below. Nothing else is required to deploy.

VariableWhat it doesWhere to get it
TURNSTILE_SITE_KEYThe public half of the bot challenge on the comment form.Cloudflare dashboard → Turnstile
TURNSTILE_SECRETThe private half; the Worker uses it to verify each challenge.Cloudflare dashboard → Turnstile

Two further secrets are required but not in the file: JWT_SECRET and IP_HASH_SECRET. npm run setup generates them with openssl rand and streams them straight to Cloudflare, so they are never written to disk. If you deploy by hand, generate them the same way: openssl rand -base64 32 | npx wrangler secret put JWT_SECRET.

3. Optional, by feature

Leave every line in this section commented out unless you want the feature. An unset secret simply means that feature is off.

Email notifications

VariableWhat it doesWhere to get it
RESEND_API_KEYSends reply notifications and moderator email. Unset, no email is sent. Also set the plain settings EMAIL_PROVIDER and EMAIL_FROM; the sending domain must be verified in Resend.resend.com/api-keys

Webhooks

VariableWhat it doesWhere to get it
WEBHOOK_URLLegacy single-URL webhook. New setups should use the /admin/webhooks endpoints instead.Your receiving service

Telegram

VariableWhat it doesWhere to get it
TELEGRAM_BOT_TOKENOutbound notifications to a Telegram bot.BotFather in Telegram
TELEGRAM_WEBHOOK_SECRETShared secret for the bot webhook. Only needed if you want inbound commands.You choose it

Sign-in providers

Each provider is independent, and an ID is useless without its secret, so set both or neither. You can enable one provider or all five.

VariableWhat it doesWhere to get it
GH_CLIENT_IDGitHub sign-in (ID).github.com/settings/developers
GH_CLIENT_SECRETGitHub sign-in (secret).github.com/settings/developers
GOOGLE_CLIENT_IDGoogle sign-in (ID).Google Cloud console → OAuth credentials
GOOGLE_CLIENT_SECRETGoogle sign-in (secret).Google Cloud console → OAuth credentials
FACEBOOK_CLIENT_IDFacebook sign-in (ID).developers.facebook.com → Facebook Login
FACEBOOK_CLIENT_SECRETFacebook sign-in (secret).developers.facebook.com → Facebook Login
TWITTER_CLIENT_IDX/Twitter sign-in (ID). X returns no email address.developer.x.com → OAuth 2.0
TWITTER_CLIENT_SECRETX/Twitter sign-in (secret).developer.x.com → OAuth 2.0
DISCORD_CLIENT_IDDiscord sign-in (ID).discord.com/developers → OAuth2
DISCORD_CLIENT_SECRETDiscord sign-in (secret).discord.com/developers → OAuth2

Anti-spam

VariableWhat it doesWhere to get it
AKISMET_API_KEYAkismet spam checks. Needed only when SPAM_PROVIDER is akismet.akismet.com
AKISMET_SITE_URLThe public site URL registered with Akismet.Your Akismet account
SPAM_FORM_TS_SECRETHMAC key for signed form-timestamp tokens (the fast-submit check).You choose it; openssl rand -base64 32

Usage dashboard and update checks

VariableWhat it doesWhere to get it
CF_API_TOKENTurns on the usage dashboard at /admin/usage, together with the plain setting CF_ACCOUNT_ID. Analytics-read scope only.Cloudflare dashboard → API tokens
GITHUB_TOKENOptional update-check token with no permissions. It only raises GitHub's 60 requests/hour limit.github.com/settings/tokens

4. Plain settings are not in this file

This file holds only secrets. Everything else, such as feature switches, page sizes and retention periods, is a plain variable in wrangler.toml under [vars]. Three of them ship with a placeholder that you must replace before you deploy:

  • ALLOWED_ORIGINS: the origins allowed to embed the widget and call the API.
  • PUBLIC_BASE_URL: the public URL of your Worker.
  • OAUTH_CALLBACK_BASE: usually the same URL; it must match the redirect URI you register with each provider.

The full list, with defaults and examples, is the configuration table in the operations guide on GitHub. The INSTALL guide walks through the whole deploy.

5. Handling the file safely

  • Leave unused lines commented. wrangler secret bulk treats an empty value as a real, empty secret. An uncommented RESEND_API_KEY= would overwrite a live key with nothing.
  • Delete the file after the upload. It holds plaintext credentials. It is gitignored, but it is still on your disk.
  • There is no form on this site that builds the file for you, on purpose. Pasting API keys into any web page is a habit worth not teaching, even when the page runs only in your browser. The template and the setup script keep your credentials on your own machine.

The template is secrets.example.env in the repository. It is generated from a single registry of every variable Garrul reads, so it does not drift from the code. If something on this page is wrong, tell us at [email protected].

GitHub · Sponsor · Ko-fi · Theme builder · Configuration · Privacy · Terms

Built by KingPin. Garrul is open source. License: Apache 2.0.