---
title: "Docker Composeއާއެކު Quire އިންސްޓޯލްކުރުން"
description: "ތިބާގެ އަމިއްލަ އިންފްރާސްޓްރަކްޗަރގައި Docker Composeއާއެކު Quire އިންސްޓޯލްކުރައްވާ."
image: "https://docs.quirelms.com/og.png"
---

> Documentation Index
> Fetch the complete documentation index at: https://docs.quirelms.com/dv/llms.txt
> Use this file to discover all available pages before exploring further.

# Docker Composeއާއެކު Quire އިންސްޓޯލްކުރުން

<span id="installing-quire-with-docker-compose"></span>

މިއީ އެއް ހޯސްޓެއްގައި ހުރި ފުރިހަމަ ޕްރޮޑަކްޓެކެވެ: LMS، އޭގެ ބެކްގްރައުންޑް ކަންކަން، ރިއަލްޓައިމް އަދި އެއްކޮށްގެން އެޑިޓްކުރާ ޚިދުމަތްތައް، އަދި ޕްރޮފައިލެއްގެ ފަހަތުން ހުރި ހުރިހާ އިޚްތިޔާރީ ޚިދުމަތްތަކެވެ. ޑިޒައިން އަކީ `docs/architecture/23-ops.md` ގެ 2 ވަނަ ސެކްޝަނެވެ.

އެހެން ޓާގެޓްތައް: [Vercel](/dv/ops/vercel/) އަދި [Cloudflare Workers](/dv/ops/cloudflare/) އިން ވެބް ޓިއަރ ފަހަރަށް ހިންގައެވެ. އަޕްގްރޭޑްތައް [upgrade.md](/dv/ops/upgrade/)ގައި އެބަހުރި، އަދި ބެކަޕްތަކާއި ރީސްޓޯރް ޑްރިލް [backup-restore.md](/dv/ops/backup-restore/)ގައި އެބަހުރި.

## ބޭނުންވާ ތަކެތި <!--quire:what-you-need-->

- Compose ޕްލަގިން 2.30 ނުވަތަ އޭގެ ފަހުންގެ ވަރޝަނަކާއެކު Docker Engine 27 ނުވަތަ އޭގެ ފަހުންގެ ވަރޝަނެއް.
- އަސާސީ ސްޓެކްއަށް CPU ކޯރ 4 އަދި މެމޮރީ 8 GB؛ `--profile full` އާއެކު ކޯރ 8 އަދި 16 GB (ClamAV އެކަނި ސޮއިގެ ސިގްނޭޗަރ އަކުރުތައް 1.5 GB ހިފައެވެ).
- ވެބް ޓިއަރއަށް DNS ނަމެއް އަދި ބެއްލެވުނު ނޫން ކޮންޓެންޓަށް ދެވަނަ ނަމެއް. އެއީ ވަކި ހޯސްޓްތަކެއް ވާންވާނެ: SCORM ޕެކޭޖްތަކާއި އަޕްލޯޑްކުރި HTML އެންމެހައި LMS ގެ ކުއީތައް ކިޔޭނެ ނޫންކޮންޓެންޓް origin ގައި ހިންގާތީއެވެ.
- ލޯކަލް ޓެސްޓަކަށް `lvh.me` އަދި `*.localhost` އިން 127.0.0.1 އަށް ރިޒޯލްވެއެވެ، އެއީ `docker/.env.example` ގައި ބޭނުންކުރާ ތަކެތި. ސްޓެކްގެ `proxy` ސަރވިސް ލޯކަލް ސެޓްފިކޭޓް އޮތްމަކަމަށް ދެތަނުގައިވެސް https ދޭނެ، އެހެން ތަކެތި އިންސްޓޯލްކުރަން ނުޖެހޭ ("TLS" ބައި ބައްލަވާ).
- ހޯސްޓުގައި 80 އަދި 443 ޕޯޓުތައް ހުސްކޮށް ހުރުން (`QUIRE_PROXY_HTTP_PORT` އަދި `QUIRE_PROXY_HTTPS_PORT` އިން އެތައް ބަދަލުކުރެވޭނެ).

## ފުރަތަމަ ހިންގުން <!--quire:first-run-->

```sh
QUIRE_APP_ORIGIN=https://learn.example.org \
QUIRE_CONTENT_ORIGIN=https://content.example-content.org \
QUIRE_SETUP_ADMIN_EMAIL=you@example.org \
  docker/scripts/init-env.sh
docker compose -f docker/compose.yaml up -d --build
docker compose -f docker/compose.yaml logs init
```

`docker/scripts/init-env.sh` އިން `docker/.env` އެއީ `docker/.env.example`އިން ހަދާދޭ، ހުރިހާ ސިއްރު ކީތައް ޖެނެރޭޓްކޮށް (ޑޭޓާބޭސް ޕާސްވޯޑްތައް، ސޮއިކުރުމުގެ އަދި މާސްޓަރ ކީތައް، ކޮންޓެންޓް ލޯންޗް ކީޕެއާ)، އަދި `docker/secrets/audit-signing-key.pem`ގައި އޮތް އޮޑިޓް ޗެކްޕޮއިންޓްގެ ސޮއި ކީވެސް؛ Compose އެއީ secret ކަމުގައި worker ތަކަށް mount ކުރެއެވެ. އެއަށް `sh`، `awk` އަދި `openssl` އެކަނި ބޭނުންވެއެވެ، އަދި އެކިވެއްޖެ `docker/.env` އަލުން ލިޔެއެއް ނުދޭނެ. ދެ ފައިލްވެސް ހޯސްޓް ބޭރަށް ކޮޕީކުރާ: `QUIRE_MASTER_KEY` ނެތް ނަމަ ރީސްޓޯރްކުރި ޑޭޓާބޭސްގައި ހުރި credentials ޑީކްރިޕްޓްނުކުރެވޭނެ. ފައިލް އަތުން ފުރަން `cp docker/.env.example docker/.env` ކުރާ؛ ފައިލްގައި ކޮންމެ ސިއްރު ކީ ހެދޭނެކަން ބަޔާންކޮށްފައި އެބަހުރި.

ދެ origin އެއްވެސް `https` ވާންވާނެ: production ގައި content ޚިދުމަތް ސާދާ http ނުބަލައެވެ، އަދި ދެއެއްވެސް registrable domain އެއްގެ ތެރޭ ނުވާންވާނެ. `proxy` ޚިދުމަތް ދެއަށް TLS ނިމުންކުރޭނެ ("TLS" ބައި ބައްލަވާ)؛ `init-env.sh` އިން `http://` origin އަދަދު ނުކުރެއެވެ.

ސްޓެކް ނިޒާމީ ތަރުތީބަކަށް ފެށޭނެ، ކޮންމެ މަރުހަލާއެއްގެ ފަހަތުގައި ކުރިއަށް އޮތް އެއްގެ ނަތީޖާ ނުވާހާއިރު އޭގެ ފަހަތް އަންނާނެ:

1. `postgres` އިތުބާރުހުރި ޙާލަތަށް ފޯރޭ. ފުރަތަމަ ފެށުމުގައި އޭގެ init script (`docker/postgres/init/90-passwords.sh`) އިން ހަތަރު role ގެ ޕާސްވޯޑްތައް ހަދާ.
2. `migrate` އިން control ޑޭޓާބޭސްގައާއި ވަކި ވަކި tenant ޑޭޓާބޭސް ހުރިހާއެއްގައި މައިގްރޭޝަންތައް ޖެއްސުމާއި job queue އަސާސްކުރުން ކުރެއެވެ، އެއީ ހުރިހާއެއްގައި އެއްގޮތް ކަމަށް ޗެކްކޮށް، ދެން ބޭރަށް ނުކުމެއެވެ (docs/ops/upgrade.md). ކޮންމެ ހިންގުމެއްގައިވެސް މައިގްރޭޝަން ހިންގާނެ؛ އެއީ idempotent ކަމުން، އަޕްގްރޭޑެއް އަކީ އައު image އަދި restart އެކެވެ.
3. `init` (`apps/web/src/first-run.ts`) އިން `QUIRE_DATABASE_ID` ދަށުން application ޑޭޓާބޭސް ރެކޯޑްކުރޭ، އަދި `QUIRE_SETUP_ADMIN_EMAIL` ސެޓްކޮށްފިނަމަ ފުރަތަމަ އޮގަނައިޒޭޝަނާއި އޭގެ އެޑްމިނިސްޓްރޭޓަރ ހަދާ. ސައިން-އިން އެޑްރެސްއާއި ޖެނެރޭޓްކުރި ޕާސްވޯޑް ފަހަރަކު އެކަނި `docker compose logs init` ގައި ޗާޕްވާނެ.
4. `web`، `content`، `worker`، `scheduler`، `collab` އަދި `centrifugo` ފެށޭ.
5. `proxy` ފެށޭނީ `web` އާއި `content` އިތުބާރުހުރި ޙާލަތަށް ފޯރުމުންނެވެ.

`https://demo.` އަދި ތިބާގެ application domain އެއްކޮށް ހުޅުވާ (ސައިން-އިން އެޑްރެސް އަކީ `init` ލޮގްގައި ފަހުރަކު ޗާޕްވެފައި). ލޯކަލް އިންސްޓޯލެއްގައި ފުރަތަމަ proxy ގެ certificate authority އިތުބާރުކުރާ ("TLS" ބައި ބައްލަވާ). ޖެނެރޭޓްކުރި ޕާސްވޯޑް `/account/security`ގައި ބަދަލުކުރާ.

އެއްވެސް ލާޒިމީ ސިއްރު ކީއެއް ނެތި process ފެށުނުން، ފެށުމަށް ނުދީ ލޮގްގައި ނެތް setting ގެ ނަން ބުނާނެ. ކޮންމެވެސް އެއްޗެއް މެދު އެއްޗެއް ނުހުރެ ސްޓެކް ފެށޭނެ.

## ޚިދުމަތްތަކާއި ޕްރޮފައިލްތައް <!--quire:services-and-profiles-->

| ޚިދުމަތް | ޕްރޮފައިލް | ކަމެއް |
| --- | --- | --- |
| postgres | ހުރިހާއިރު | ޑޭޓާބޭސް (PostgreSQL 18 pgvectorއާއެކު، `docker/postgres.Dockerfile`އިން ބިލްޑްކުރެވޭ)، ފުރަތަމަ boot އިން WAL archiveއެކު |
| migrate, init | ހުރިހާއިރު | އެއް ފަހަރު އެކަނި: މައިގްރޭޝަން، ދެން ފުރަތަމަ ހިންގުން |
| web | ހުރިހާއިރު | LMS، `QUIRE_HTTP_PORT` (8080) ގައި |
| content | ހުރިހާއިރު | ނޫންކޮންޓެންޓް origin، `QUIRE_CONTENT_PORT` (8081) ގައި |
| worker | ހުރިހާއިރު | ބެކްގްރައުންޑް ޖޮބްތައް: އީމެއިލް، ރިޕޯޓް، ފައިލް ޕްރޮސެސިންގ، webhook |
| scheduler | ހުރިހާއިރު | އަލުން ހިންގޭ ޖޮބްތައް: runtime schedule 64 ރަޖިސްޓަރީކޮށް worker އަށް ދޭ؛ އެއް ލީޑަރެއް އެކަނި |
| collab | ހުރިހާއިރު | އެއްކޮށް އެޑިޓްކުރާ websocket، `QUIRE_COLLAB_HTTP_PORT` (1234) ގައި |
| centrifugo | ހުރިހާއިރު | ރިއަލްޓައިމް ފެންވަރުން ފެތުރުން، `QUIRE_REALTIME_PORT` (8000) ގައި |
| proxy | ހުރިހާއިރު | Caddy، ޕޯޓް 80 އަދި 443 ގައި TLS ގެ ފުރަތަމަ ދޮރު ("TLS" ބައި ބައްލަވާ) |
| valkey | `cache` | cache އަދި rate limit |
| clamav | `scan` | އަޕްލޯޑްތަކުގެ malware ޗެކްކުރުން |
| gotenberg | `preview` | Office އިން PDF preview އަދި certificate ރެންޑަރކުރުން |
| imgproxy | `images` | އިމޭޖް ބޮޑު/ކުޑަކޮށް format ބަދަލުކުރުން |
| transcoder | `video` | video rendition އަށް LGPL-only ffmpeg އެއް ހުރި worker image |
| seaweedfs | `storage` | މި ހޯސްޓުގައި S3 އާއި ބަރާބަރު އޮބްޖެކްޓް ސްޓޯރޭޖް |
| otelcol | `observability` | OpenTelemetry ކަލެކްޓަރ |
| mailpit | `devmail` | Quire ޓްރައިކުރާއިރު ބޭރުވާ ހުރިހާ މެއިލް ކެއްތުން |
| backup | `backup` | އެއް ފަހަރުގެ base backup؛ backup-restore.md ބައްލަވާ |
| backup-scheduler, backup-offsite | `backup` | `QUIRE_BACKUP_INTERVAL_HOURS` އިން ހަފްތާއަކު އެއް ފަހަރުގެ base backup، ދުރުން އެންކްރިޕްޓްކުރި ކޮޕީތައް އަދި ހަފްތާއަކު ވެރިފިކޭޝަން ޑްރިލް |
| h5p | `h5p` | `QUIRE_H5P_IMAGE`ގައި ތިބާ ދޭ H5P LTI 1.3 ޓޫލް އިމޭޖް، `QUIRE_H5P_PORT` (8090)ގައި؛ "Connecting an H5P provider" ބައި ބައްލަވާ |

`--profile full` އިން `backup` އަދި `h5p` ފިޔަވައި ހުރިހާ އިޚްތިޔާރީ ޚިދުމަތް ފެށޭ. `docker compose -f docker/compose.yaml --profile scan up -d` ހިންގާށެވެ. އިޚްތިޔާރީ ޚިދުމަތެއް ނެތިވެސް Quire ހިންގާނެ އަދި ނެތްކަން ބުނާނެ: scanner ނެތްނަމަ އަޕްލޯޑްތައް scan ނުކުރެވި ސްޓޯރްވެ، އެޑްމިނިސްޓްރޭޓަރއަށް އެންގޭނެ؛ Gotenberg ނެތްނަމަ ފައިލް ޑައުންލޯޑްކުރެވޭ ނޫނީ preview ނުލިބޭ؛ transcoder ނެތްނަމަ video އަސްލު ފައިލް ގޮތުގައި ނަގައެވެ.

ކޮންމެ ތިންވަނަ ޕާޓީގެ image އަދި އޭގެ ލައިސަންސް ލާޒިމުތައް `docker/third-party-containers.yaml`ގައި ލިޔެފައި އެބަހުރި.

### H5P provider ގުޅުވުން <!--quire:connecting-an-h5p-provider-->

Quire އިން H5P runtime އެއްވެސް އެންބެޑްނުކުރެ، ނުވަތަ sidecar އެއްވެސް އެކުގައި ނުދޭ (ADR 0019). H5P ބޭނުންކުރާނަމަ، ތިބާގެ އަމިއްލަ hosted subscription އެއް ނުވަތަ Quireއިން ވަކިކޮށް ހިންގާފައިވާ self-hosted H5P އިންސްޓާންސެއް ދޭށެވެ. އެ provider އެއީ LTI 1.3 external tool ގޮތަށް ރަޖިސްޓަރީކޮށް، އޭގެ content ކޯސްތަކަށް tool activity ގޮތަށް އިތުރުކުރާށެވެ. Quire އިން LTI Assignment and Grade Services (AGS) މެދުވެރިކޮށް ގްރޭޑްތަކާއި activity/grading ގެ ކުރިއަރުވުން ދިމާކުރެއެވެ. provider އިން xAPI statementތައްވެސް ފޮނުވާނަމަ، Quireގެ xAPI statement storeއަށް އެއްވަކިން configure ކުރާށެވެ؛ AGS ގެ grade/progress މުބާދަލާތުން xAPI statementތައް ނުފޮނުވޭ. Moodle އިން importކުރިއިރު H5P activityތައް LTI tool connection ބޭނުންވާކަމަށް ރިޕޯޓްކުރޭ. H5P runtime، authoring، content bank އަދި attempt history ގެ ޒިންމާ provider އަށެވެ.

މި ހޯސްޓުގައި ތިބާގެ self-hosted instance ހިންގާނަމަ، `QUIRE_H5P_IMAGE` އަށް އޭގެ image ސެޓްކޮށް `h5p` profile ފެށާށެވެ. Compose އިން `QUIRE_H5P_PORT` (8090) ގައި ޕަބްލިޝްކޮށް، އޭގެ data `h5p-data` volumeގައި ބެހެއްޓޭ؛ imageއާއި އޭގެ ލާޒިމުތައް ތިބާގެ ޒިންމާއެވެ.

## Settings <!--quire:settings-->

ކޮންމެ processއެއް `docker/.env` ކިޔައެވެ. ޓެމްޕްލޭޓް `docker/.env.example` ގައި ކޮންމެ settingއެއްގެ default އެބަހުރި. ގުރޫޕްތަކަކީ:

### އެޑްރެސްތައް <!--quire:addresses-->

| Setting | މާނަ |
| --- | --- |
| `QUIRE_APP_ORIGIN` | LMS ގެ އާންމު އެޑްރެސް، މިސާލަކަށް `https://learn.example.com` |
| `QUIRE_CONTENT_ORIGIN` | ވަކި ހޯސްޓެއްގައި ހުރި content origin |
| `QUIRE_PLATFORM_DOMAINS` | އޮގަނައިޒޭޝަންތައް ހުރި domainތައް، commaއިން ވަކިކުރާ |
| `QUIRE_MARKETING_ORIGIN` | Optional. The marketing site, default `https://quirelms.com`. The only origin the waitlist form (`POST /api/waitlist`, `POST /waitlist`) accepts and redirects to. Comma separated; a `www.` variant is allowed only if listed |
| `QUIRE_DEPLOY_TARGET` | މިތަނުގައި `compose`؛ `vercel` އަދި `cloudflare`އަށް އެހެން ގައިޑްތައް ބައްލަވާ |
| `QUIRE_TRUSTED_PROXY_CIDRS` | `X-Forwarded-For` އިތުބާރުކުރާ proxyތައް |

### ސިއްރު ކީތައް <!--quire:secrets-->

| Setting | މާނަ |
| --- | --- |
| `QUIRE_SECRET_KEY` | sessionތަކާއި tokenތައް ސޮއިކުރާ؛ hex އަކުރު 64 |
| `QUIRE_MASTER_KEY` | SSO އަދި webhook ސިއްރުތައް ފަދަ ބެހެއްޓި credentials އަށް ކަވަރ ލާ؛ base64ގައި 32 byte. web އާއި worker އަކަށްވެސް އެއް value ބޭނުންވެއެވެ. ބަދަލުކުރުމަށް: [key-rotation.md](/dv/ops/key-rotation/) |
| `QUIRE_MASTER_KEY_VERSION` | master key ގެ version ނަން، ނުސެޓްނަމަ `v1`؛ key rotateކުރާއިރު މިއީ ބޮޑުކުރާ |
| `QUIRE_MASTER_KEY_RETIRED` | ކުރިން ހުރި master keyތައް، އޭގެ އަޑުން ސީލްކުރި އެއްޗެތި ކިޔާން ލާޒިމުވޭތީ، `v1=<base64>` ގޮތަށް؛ އަދި އެއްޗެއް unresolved ނުވާހިނދު rotation ނިމުނީމަ ފުހެލާ |
| `QUIRE_COLLAB_SIGNING_KEY` | web އާއި collab އިން editing token ސޮއިކުރަން އެއްކޮށް ބޭނުންކުރާ |
| `QUIRE_BACKUP_SIGNING_KEY` | course backup ސޮއިކުރާ (އިޚްތިޔާރީ) |

`QUIRE_MASTER_KEY` މި ހޯސްޓްފިޔަވައި އެހެންތަނެއްގައި ކޮޕީކޮށް ބެހެއްޓާ. އެއީ ނެތި ޑޭޓާބޭސް ރީސްޓޯރްކުރިއަސް، އޭގައި ހުރި credentials ޑީކްރިޕްޓް ނުކުރެވޭނެ.

### Database <!--quire:database-->

| Setting | މާނަ |
| --- | --- |
| `POSTGRES_PASSWORD` | superuser؛ container އަދި backup އިން ބޭނުންކުރާ |
| `QUIRE_DB_APP_PASSWORD`, `QUIRE_DB_MIGRATOR_PASSWORD`, `QUIRE_DB_REPORT_PASSWORD`, `QUIRE_DB_AUDIT_PASSWORD` | ފުރަތަމަ ހިންގުމުގައި ސެޓްވާ role ޕާސްވޯޑްތައް |
| `DATABASE_URL` | application role؛ އޭގެ ކޮންމެ queryއަކަށް row-level security ލާޒިމުކުރެވޭ |
| `DATABASE_MIGRATOR_URL`, `QUIRE_MIGRATION_URL` | `migrate` އަދި `init` އަށް migrator role |
| `QUIRE_SUPERUSER_URL` | ފުރަތަމަ ހިންގުމަށް އެކަނި ބޭނުންކުރާ |
| `QUIRE_REPORT_DATABASE_URL` | ރިޕޯޓްއަށް read-only report role އަދި report builder |
| `QUIRE_AUDIT_DATABASE_URL` | audit console އަދި SIEM export އަށް audit role |
| `QUIRE_DATABASE_ID` | އެއް UUID، އިންސްޓޯލްގެ ދުވަސްވަރު އެއްގޮތަށް ބެހެއްޓޭ |

ޑޭޓާބޭސް volume ފުރަތަމަ ހެދޭއިރުއެކަނި role ޕާސްވޯޑް ލާޒިމުކުރެވޭ. ފަހުން އެއް ބަދަލުކުރާނަމަ `ALTER ROLE` ބޭނުންކޮށް، ފަހުން އެއާއި ގުޅޭ URL އަޕްޑޭޓްކުރާ.

`QUIRE_REPORT_DATABASE_URL` އިން `DATABASE_URL` އިން configure ކުރި physical database ބޭނުންކުރެއެވެ. އެހެން ރަޖިސްޓަރީކުރި physical database އެއްގައި، web އާއި worker environmentތަކަށް އޭގެ އަމިއްލަ `quire_report` connection URL ސެޓްކޮށް، އެ database ގެ **Reporting environment variable** ގައި އެ variable ގެ ނަން `env:NAME` ގޮތަށް ލިޔާ. އެ reference އިން app connection ގައިވާ އެއް databaseއަށް ފަހުރަކު ނުވަތަ އޭގެ read replicaއަށް ދާންވާނެ. ކޮންމެ report surfaceއެއްވެސް tenantއާއެކު އޭގެ database ގެ report connection އަށް ދާނެ: report builder އާއި saved reportތައް، scheduled deliveryތައް، report exportތައް، analytics، audit log، REST audit resourceތައް އަދި assistantގެ audit search. އެއްވެސް އެހެން database ގެ report URL އެއް ދައްކަނީ ނޫނެވެ. databaseއެއްގައި report connection ނެތްނަމަ، އާންމު reportތައް އެ databaseގެ އަމިއްލަ application connection އިން ހިންގާ؛ analytics އާއި audit ކިޔުންތައް ނުކުރެވޭ ކަމާއެކު އޭގެ ސަބަބު ބުނާ، އެއީ application role އިން audit trail ކިޔާން ނޭނގޭތީއެވެ.

### Driverތައް <!--quire:drivers-->

| Setting | މި releaseގައި | ތަފްސީލު |
| --- | --- | --- |
| `QUIRE_STORAGE_DRIVER` | `local` (default)، `s3` ނުވަތަ `azure` | `local` އިން `files` volumeގައި ފައިލްތައް ބެހެއްޓޭ. `s3` އިން AWS S3، R2، GCS interoperability އަދި އެހެން S3-compatible storeތައް ބެހެއްޓޭ، އަދި multipart upload ކުރިއަރުވާތާއި އެކު ބެހެއްޓޭ |
| `QUIRE_REALTIME_DRIVER` | `inprocess` (default)، `sse`، `centrifugo` ނުވަތަ `durable_objects` | އެއް web container އަށް `inprocess` އެންމެ ރަނގަޅު؛ ގިނަ container ހުރިނަމަ `centrifugo` ނުވަތަ `sse` ބޭނުންކުރާ |
| `QUIRE_CACHE_DRIVER` | `memory` (default)، `postgres` ނުވަތަ `valkey` | `memory` ކޮންމެ processއަކަށް ވަކި؛ containerތަކާއެކު rate limit އެއްގޮތްކޮށް ބެހެއްޓުމަށް `valkey` ނުވަތަ `postgres` ބޭނުންކުރާ |
| `QUIRE_VIDEO_DRIVER` | `ffmpeg` (default) ނުވަތަ `progressive_mp4` | އަދި hosted providerއެއް: Cloudflare Stream، Mux ނުވަތަ Bunny، އެތަކެތިގެ keyތަކާއެކު |
| `QUIRE_IMAGE_DRIVER` | `noop` (default)، `imgproxy` ނުވަތަ `cloudflare` | `noop` އިން ކޮންމެ އިމޭޖެއް އަސްލު ސައިޒުގައި ދޭ. `imgproxy` އަށް `images` profile އާއި ތިރީގެ settingތައް ބޭނުންވޭ؛ `cloudflare` އިން Cloudflare Images ބޭނުންކުރޭ |
| `QUIRE_MEETING_PROVIDER` | `bbb`، `zoom`، `teams`، `meet`، `jitsi` ނުވަތަ `in_process` | ލައިވް ސެޝަނަށް platform default. ސެޓްނުކުރާނަމަ، އޮގަނައިޒޭޝަނެއް Integrations، Live session provider ދަށުން އަމިއްލަ account ގުޅުވާހިނދު ފަހަރަށް live session ތައް configure ނުކުރެވިފައި ކަން ދައްކާ. އޮގަނައިޒޭޝަންގެ އަމިއްލަ account އެއްވެސް މި valueއަށް ފަހަތަށް ކަނޑައެޅޭ. މިތަނުގައި ނަންދެވި providerއަށް އެކަނި އޭގެ settingތައް (`BBB_URL` އަދި `BBB_SECRET`، `ZOOM_*`، `TEAMS_*`، `GOOGLE_MEET_*` އަދި `JITSI_*` variableތައް) ކިޔެވޭ |
| `QUIRE_MEETING_REGIONS` | commaއިން ވަކިކުރި `eu`، `uk`، `us` ގެ list | platform default provider އިން ކޮން regionގައި meeting processކުރާކަން. ސެޓްނުކުރާނަމަ، ކުރިންވެސް ހިންގިހެން، އޮގަނައިޒޭޝަން regionއެއްގައި pinކުރިކަމާއި ގުޅުވައި ޗެކްނުކުރޭ. އޮގަނައިޒޭޝަންގެ accountގެ regionތައް އޭގެ ސަފްހާގައި ބުނެފައި އެބަހުރި |

މި releaseގައި ނެތް driver valueއެއް ލިބުނުން، web tier ފެށުމުގައި ނަން ދައްކައި ނުބަލާނެ؛ defaultއަށް އަޑިއަށް ބަދަލުނުކުރެވޭނެ.

### އިމޭޖްތައް <!--quire:images-->

ސަފްހާތަކުން `/api/files/{id}/image/{size}` މެދުވެރިކޮށް ހަތަރު fixed sizeއެއްގައި އިމޭޖް އެދޭ؛ އެއީ ފައިލަކަށްވާ އެއް access ޗެކްކޮށް، ދެން image serviceއަށް redirectކުރޭ. ކޮންމެ އޮގަނައިޒޭޝަނަކު ގަޑިއެއްގައި `QUIRE_IMAGE_SPECS_PER_HOUR` (default 2000) އާއި އަލުން އިމޭޖް/size ޖޯޑުތައް އެދިދާނެ؛ އެ ގަޑިއެއްގައި ހަދާފައި އޮތް size ތައް ނުގުނޭ. ގިނަ web container ހުރިނަމަ rate limit ތައް އެއްގޮތަށް ހިފުމަށް `valkey` ނުވަތަ `postgres` ބޭނުންކުރަން `QUIRE_CACHE_DRIVER` ގައި ސެޓްކުރާ.

| Setting | Driver | ތަފްސީލު |
| --- | --- | --- |
| `IMGPROXY_URL` | `imgproxy` | browserތަކުން imgproxyއަށް ފޯރާ އެޑްރެސް، މިސާލަކަށް `https://images.example.org`. `images` profileއިން `QUIRE_IMAGES_PORT` (8082) ގައި publishކުރޭ |
| `IMGPROXY_KEY`, `IMGPROXY_SALT` | `imgproxy` | hex stringތައް، imgproxy ފެށުމަށް ބޭނުންވާ އެއް valueތައް. ކޮންމެއް `openssl rand -hex 32`އިން ހަދާ. Quire އިން ކޮންމެ image addressއެއްވެސް މިތަކެތިން ސޮއިކުރޭ، އެހެންވެ Quire އެދިފައި ނުވާ imageއެއް imgproxy ރެންޑަރ ނުކުރޭ |
| `QUIRE_IMAGE_SOURCE_ORIGIN` | local storageއާއެކު `imgproxy` | imgproxy އިން original image ނެގޭ ތަން. Compose އިން `http://web:3000` ސެޓްކުރޭ. `s3` ނުވަތަ `azure` storage އާއެކު imgproxy bucketއިން ނަގާ، މި setting ނުބޭނުންވޭ |
| `CLOUDFLARE_ACCOUNT_ID`, `CLOUDFLARE_IMAGES_TOKEN`, `CLOUDFLARE_IMAGES_ACCOUNT_HASH` | `cloudflare` | Images edit permission ހުރި API token، އަދި Images، Developer resourcesއިން account hash. accountއަށް flexible variantތައް onކުރާ |
| `CLOUDFLARE_IMAGES_SIGNING_KEY` | `cloudflare` | އިޚްތިޔާރީ. މިއީ ސެޓްކުރާނަމަ imageތައް privateވެ، ކޮންމެ addressއެއް ސޮއިކުރެވި expiresވޭ. މިއީ ނެތްނަމަ، imageތައް publicވެ `QUIRE_SECRET_KEY`އިން ނިމުނު addressތަކުގައިވާނެ، ނުކިޔައިނުނެގޭ |

Cloudflare Images އިން ދޭ ކޮންމެ originalގެ އަމިއްލަ ކޮޕީއެއް ބެހެއްޓޭ. ފައިލެއް ފުހެފިނަމަ، worker އިން original ފުހުމުގެ ކުރިން އެ ކޮޕީ ފުހެލާ.

### Queue <!--quire:queue-->

ބެކްގްރައުންޑް jobތައް އެއް Postgres databaseގައިވާ pg-boss ބޭނުންކުރޭ، އެހެން queue serviceއެއް ހިންގުމާއި configureކުރުން ނެތެވެ. jobތައް އެއް transactionގައި enqueueވާތީ، އެ job ހެދި ބަދަލާއި އެކުގައިވެ، crashއެއްގައި ނާއްތަނީ ނުވަތަ ދެފަހަރު ނުފޮނުވޭ. މިތަނުގައި `QUIRE_QUEUE_DRIVER` އަކީ default `pgboss`؛ `vercel` އަދި `cloudflare`އިން ކުޑަ notification އަދި webhook deliveryތައް platformގެ queueއަށް ބަދަލުކުރޭ، އޭގެ ފަސޭހަކަންތަކާއި އެ web tierތަކުން enqueueކުރާގޮތް Vercel އަދި Cloudflare guideތަކުގައި ބުނެފައިވޭ.

### Email <!--quire:email-->

މިއެއްގެ އެއް ސެޓްކުރާ:

- `QUIRE_EMAIL_PROVIDER_CONFIG`: HTTP provider އަދި އޭގެ credentialތައް ބުނާ JSON objectއެއް، މިސާލަކަށް `{"provider":"postmark","token":"..."}`. Postmark، Amazon SES، Mailgun، SendGrid އަދި Resend ބޭނުންކުރެވޭ.
- `QUIRE_SMTP_URL`: `smtp://user:password@host:587`. މި targetއަށްއެކަނި؛ serverless targetތައް SMTP ބްލޮކްކުރޭ.

`QUIRE_MAIL_FROM` އީ ފޮނުވާނެ އެޑްރެސް. Quire ޓްރައިކުރަން `devmail` profile ފެށިގެން `QUIRE_SMTP_URL=smtp://mailpit:1025` ސެޓްކޮށް `http://localhost:8025`ގައި މެއިލް ކިޔާ.

### އިޚްތިޔާރީ ޚިދުމަތްތައް <!--quire:optional-services-->

| Setting | Profile އާއެކު |
| --- | --- |
| `CLAMAV_URL=tcp://clamav:3310` | `scan` |
| `GOTENBERG_URL=http://gotenberg:3000` | `preview` |
| `IMGPROXY_KEY`, `IMGPROXY_SALT` | `images` |
| `VALKEY_URL=redis://valkey:6379` | `cache` |
| `QUIRE_OPENSEARCH_URL` ނުވަތަ `QUIRE_MEILISEARCH_URL` | External search؛ ނޫނީ Postgres full text |
| `QUIRE_BREACH_CHECK_PROVIDER=off`, `QUIRE_BREACH_CHECK_URL` | ޕާސްވޯޑް breach check. ޑިފޯލްޓުން on ކޮށް `api.pwnedpasswords.com` އަށް ބަލާ (hashގެ ފުރަތަމަ 5 އަކުރު ފިޔަވައި ނުފޮނުވޭ)؛ `off` އިން disableކުރޭ، URL އިން ތިބާގެ range API ދައްކާ |

### ބަލައިގަތުން <!--quire:observability-->

`OTEL_EXPORTER_OTLP_ENDPOINT` އިން ކޮންމެ processއަކު trace އާއި metric ފޮނުވާ collector ގެ ނަން ދޭ؛ `observability` profileއާއެކު `http://otelcol:4318` އެވެ، އަދި `docker/otel-collector.yaml`އަކީ ތިބާގެ backend އަށް exporter އިތުރުކުރާ ތަނެވެ. މިއީ ސެޓްކުރާނަމަ web tier، worker، scheduler، content އަދި collab processތައް OTLP/HTTP މެދުވެރިކޮށް spanތައް (web request، tenant database transaction، worker job އަދި ބޭރުގެ callތައް) ފޮނުވައި، ކޮންމެ މިނެޓަކުން އެއް endpointއަށް metricތައްވެސް ފޮނުވާ (`OTEL_METRICS_EXPORTER=none` އިން އެތައް offކުރޭ). `OTEL_TRACES_SAMPLER_ARG` އިން ބެހެއްޓޭ traceގެ ނިސްބަތް ސެޓްކުރޭ. logތައް `LOG_LEVEL` ގައި standard outputއަށް ދާ، Compose އިން rotationކުރޭ. traceތަކުގައި މީހުންގެ ޚާއްސަ މައުލޫމާތެއް ނުހުންނާނެ.

### އޭޔޫ ބޭރުގެ ގުޅުން (EU ޑޭޓާ ރެޒިޑެންސީ) <!--quire:regional-egress-eu-data-residency-->

`QUIRE_REGION=eu` އިން މި stackއިން ޔޫރަޕިއަން ޔުނިއަން އޮގަނައިޒޭޝަންތައް ޚިދުމަތްކުރާކަން ދައްކާ. ދެން EU regionއަށް pinކުރި އޮގަނައިޒޭޝަނަކަށް ހެދޭ ކޮންމެ outbound requestއެއް worker އިން allowlistއަށް ބަލާ (21-compliance.md ގެ 8.1 ވަނަ ސެކްޝަން). Allowlistގައި region އަށް configureކުރި ޚިދުމަތްތަކުން ދެއްކޭ hostތައް (storage endpoint، email provider، hosted video provider، އޮގަނައިޒޭޝަންގެ storage target، AI provider އަދި email account)، ހިންގޭ derogationއެއްގެ ޚިދުމަތްތަކުގެ hostތައް، އަދި `QUIRE_EGRESS_ALLOW_HOSTS`ގައި ތިބާ ލިޔުއްވި hostތައް ހިމެނޭ. އެހެން public hostއަކަށް ދާ requestއެއް ފޮނުވުމުގެ ކުރިން މަނާކޮށް، މަނާކުރިކަން އޮގަނައިޒޭޝަންގެ audit trailގައި `privacy/egress_refused` ގޮތަށް ލިޔެ، Compliance، Data residency ދަށުން ދައްކާ.

| Setting | Valueތައް | އަސަރު |
| --- | --- | --- |
| `QUIRE_EGRESS_ALLOW_HOSTS` | commaއިން ވަކިކުރި hostname list، ނުވަތަ ކޮންމެ subdomainއަކަށް `*.example.org` | EU ގެ އޮގަނައިޒޭޝަނަކަށް އަދި ފޯރުވާ hostތައް. Webhook، xAPI އަދި SIEM endpointތައް، blog feed އަދި Amazon SES hostތައް މިތަނަށް ލާ؛ އެއީ އޮގަނައިޒޭޝަންގެ އަމިއްލަ އިޚްތިޔާރުތަކެވެ، ޚިދުމަތަކުން ދައްކާ ތަކެއްޗެއް ނޫނެވެ. Loopback، private address އަދި `web` ނުވަތަ `clamav` ފަދަ އެއް label ހުރި ނަންތަކަކީ ތިބާގެ އަމިއްލަ networkއެވެ، އޭތި ފަހުރަކު ޗެކް ނުކުރެވޭ |

UK އަދި US ގެ އޮގަނައިޒޭޝަންތައް host listއަކަށް ބަންދެއް ނުކުރެވޭ؛ އެތަނަށް ޚިދުމަތް ކޮން regionގައިކަން ޗެކްކުރުން އެބަހުރި. workerގައި މި list ސެޓްކުރާ؛ allowlist ދައްކަން admin page އިން web tierއިން ކިޔާތީ، ކޮންމެ serviceއެއްވެސް ކިޔާ `docker/.env`ގައި ލިޔާ.

application checkއިން ސާފު errorއެއް އަދި audit entryއެއް ދޭ، އެއީ ޔަގީންކަން ނޫނެވެ: code ގައި ގޯސް ވެދާނެ. ޔަގީންކަން ލިބޭނީ networkއިންނެވެ. Compose އިން ތިބާއަށް އެއީ ނުކުރެއެވެ. region stackއަކަށް `worker` އާއި `web` ޚިދުމަތް `internal: true` networkއަކަށް ލާ؛ ބޭރަށް ދާނެ އެއް މަގަކީ egress proxyއެއް (މިސާލަކަށް Squid ނުވަތަ tinyproxy container) އެވެ. އެއީ `QUIRE_EGRESS_ALLOW_HOSTS`ގައިވާ hostތަކާއި configureކުރި serviceތަކުގެ hostތައް ހުއްދަދޭންވާނެ؛ އެ serviceތަކަށް `HTTPS_PROXY` ސެޓްކުރާ. residency page އިން applicationއިން ހުއްދަދޭ ފުރިހަމަ hostތައް ދައްކާތީ ދެ list ތައް އަޅާކިޔާލެވޭނެ.

## ހެލްތު <!--quire:health-->

| Endpoint | މާނަ |
| --- | --- |
| `/healthz` | ލައިވްނެސް: process އިން ޖަވާބުދޭ. Compose health checkއިން މިއީ ބޭނުންކުރޭ |
| `/readyz` | ތައްޔާރުކަން: dependencyތައް ފޯރާ، އަދި އިޚްތިޔާރީ ޚިދުމަތަކަކު ތައްޔާރު ނުވަތަ ނޫންކަން ބުނޭ. ތިބާގެ load balancer މިތަނަށް ދައްކާ |

`docker compose -f docker/compose.yaml ps` އިން ކޮންމެ serviceއެއްގެ health ދައްކާ.

## TLS <!--quire:tls-->

`proxy` service (Caddy، Apache-2.0، `docker/caddy/Caddyfile`) އީ default stackގެ ބައެކެވެ. އެއީ 80 އަދި 443 ޕޯޓުގައި ޖަވާބުދީ، ތިރީގައި ބުނާގޮތަށް routeކުރޭ:

| Host ނުވަތަ path | ދާނެ ތަން |
| --- | --- |
| `QUIRE_PROXY_CONTENT_HOST` | `content` |
| `QUIRE_PROXY_APP_HOST`، ކޮންމެ tenant subdomain އަދި custom domain | `web` |
| `/_collab/` މި hostތަކުގައި | `collab` (`QUIRE_COLLAB_URL`ގެ websocket) |
| `/_realtime/connection/` މި hostތަކުގައި | `centrifugo`ގެ client websocket؛ server API ފަހުރަކު ނުހުޅުވޭ |
| `/_images/` މި hostތަކުގައި | `imgproxy`، `images` profileއާއެކު (`IMGPROXY_URL`) |

`init-env.sh` އިން ދެ originއިން `QUIRE_PROXY_APP_HOST`، `QUIRE_PROXY_CONTENT_HOST`، `QUIRE_PROXY_HTTPS_PORT`، `QUIRE_COLLAB_URL` އަދި `IMGPROXY_URL` ހިސާބުކުރޭ، އެހެންވެ ދިމާވަރު ބަދަލުނުވާނެ. originއެއް އަތުން ބަދަލުކުރާނަމަ މިތަކެތި އެއްކޮށް editކުރާ.

Certificateތައް `QUIRE_PROXY_TLS` އިން ނިންމާ:

- `internal` (default): `localhost`، `*.localhost` އަދި `lvh.me` އަށް Caddyގެ އަމިއްލަ certificate authority. އޭގެ root އެއްފަހަރު އިތުބާރުކޮށް، ދެން ބަލާ:

  ```sh
  docker compose -f docker/compose.yaml cp \
    proxy:/data/caddy/pki/authorities/local/root.crt ./quire-local-ca.crt
  ```

  `quire-local-ca.crt` އެއީ system ނުވަތަ browser trust storeއަށް އިތުރުކުރާ. `curl`އަށް `--cacert` އިން މި އެއްޗި ދެވޭ.
- e-mail addressއެއް: އަސްލު hostnameތަކަށް automatic ACME certificate (ފުރަތަމަ Let's Encrypt، ފަހުން ZeroSSL). ދެ origin އަދި tenant hostތަކުގެ DNS މިތަނަށް ދާންވާނެ، އަދި internetއިން 80 އަދި 443 ޕޯޓު ފޯރާންވާނެ.

Tenant hostތައް ފުރަތަމަ ބަލާއިރު ލިބޭގޮތަށް ދެވޭ؛ އެއީ web އިން މި installއާއި ނަމެއް ގުޅުންކަން ޔަގީންކުރުމަށް ފަހުއެވެ (`/tls-allowed`، Compose networkއިން އެދޭ). wildcard certificate ނުވަތަ DNS provider plugin އެއް ނުބޭނުންވޭ؛ އަދި hostއަށް ނަނެއް ދައްކާ މަދު މީހަކު އޭނާގެ certificate ނުވަތަ އެއްޗެއް އެދި ނުލެވޭނެ. certificateތަކާއި ލޯކަލް authority `caddy-data` volumeގައިވޭ؛ `internal` ބޭނުންކުރާނަމަ އެތަކެތިވެސް އެހެން backupތަކާއެކު ކުރާށެވެ.

Web އިން proxyއިން ފޮނުވާ `X-Forwarded-For` އެކަނި އިތުބާރުކުރޭ: proxy އަށް fixed address (`QUIRE_PROXY_ADDRESS`، default `172.29.64.10`) އަދި fixed subnet (`QUIRE_COMPOSE_SUBNET`) އެބަހުރި، `QUIRE_TRUSTED_PROXY_CIDRS` އިން އެ address ބުނެދޭ. subnet އެއް ހޯސްޓުގެ network އާއި ދިމާވާނަމަ، ދެއެއްވެސް ބަދަލުކޮށް ފުރަތަމަ `docker compose down` ހިންގާ، ދެން `up` ހިންގާ.

## ތިބާގެ އަމިއްލަ reverse proxy ގެ ފަހަތުގައި <!--quire:behind-your-own-reverse-proxy-->

ކުރިން ހިންގައިފައިވާ load balancer ނުވަތަ proxy ބޭނުންކުރާނަމަ، `proxy` ނުހިމެނި ދޫކޮށް (`docker compose up -d --scale proxy=0`) އަދި TLS އެއީ `web` (8080)، `content` (8081)، `collab` (1234، websocket) އަދި `centrifugo` (8000، websocket) ގެ ކުރިމަތިން ނިމުންކުރާ. އާންމު addressތައް `QUIRE_APP_ORIGIN`، `QUIRE_CONTENT_ORIGIN` އަދި `QUIRE_COLLAB_URL` (`wss://`)ގައި ސެޓްކޮށް، proxyގެ address range `QUIRE_TRUSTED_PROXY_CIDRS`ގައި ލިޔާ.

## ދަތިތައް ޙައްލުކުރުން <!--quire:troubleshooting-->

- `init` އިން "QUIRE_DATABASE_ID is not a UUID" ބުނެ ނިންމާނަމަ، `uuidgen`އިން އެއް ސެޓްކުރާ.
- `web` އިން "did not start on compose" ބުނެ އަލުން ހިންގާނަމަ، އޭގެ ލޮގްގައި ކޮން settingއެއް ބޭނުންކުރެވޭކަން ނުކުރެވޭ އަދި އެއްޗަށް ބަދަލު ކޮބާކަން ލިޔެފައި އެބަހުރި.
- ފުރަތަމަ ފެށުމަށް ފަހު `.env`ގައި role password ބަދަލުކުރިޔަސް އެއްޗެއް ނުވާނަމަ، init script އެއްފަހަރު އެކަނި ހިންގޭތީ؛ `ALTER ROLE` ބޭނުންކުރާ.
- `CLAMAV_URL` ސެޓްކޮށްފައި ހުރިއިރު scan errorއެއްގެ ސަބަބުން uploadތައް failވާނަމަ، ClamAV އިން ފުރަތަމަ bootގައި signatureތައް downloadކުރެއެވެ، އެއަށް މަދު މިނެޓް ނަގާނެ.

Source: https://docs.quirelms.com/dv/ops/install/index.mdx
