Self-hosting
Self-hosting is a first-class option, not a downgrade. There is no licence key, no subscription and no call home to us. A self-hosted instance performs every core presentation function on its own.
| Variable | Default | Description |
|---|---|---|
PORT | 3000 | HTTP port for the application. |
DATA_DIR | ./data | Persistent data root. Keep this outside the release directory so updates never overwrite user data. |
SESSION_SECRET | — | Required in production. Long random string used to sign session tokens. |
NODE_ENV | development | Set to production to require HTTPS cookies and reject default secrets. |
TRUST_PROXY | 0 | Set 1 behind CloudPanel/nginx so client IPs and secure cookies behave correctly. |
INSTANCE_NAME | Simple Worship Presenter | Name shown in the interface and health output. |
PUBLIC_URL | — | Public base URL of the instance, if any. |
DEFAULT_QUOTA_BYTES | 262144000 | Storage quota for new accounts (250 MB by default). |
MAX_UPLOAD_BYTES | 262144000 | Maximum single upload size. |
ALLOW_REGISTRATION | 1 | Set to 0 to close public registration on your instance. |
LOG_LEVEL | info | debug, info, warn or error. |
RATE_LIMIT_MAX_AUTH | 10 | Sign-in attempts per minute per IP address. |
server.js.npm ci in the application directory.PORT to the port CloudPanel assigns.DATA_DIR to a persistent path outside the release, for example /home/cloudpanel/htdocs/simple-worship-data.SESSION_SECRET and TRUST_PROXY=1.The included docker-compose.yml mounts a named volume at the data directory and exposes a health check at /api/health.
DATA_DIR.npm ci.Database schema changes run automatically as numbered migrations on startup. Migrations are additive and never delete existing user data. If a data file cannot be read, the instance preserves a copy named *.corrupt-<timestamp> rather than overwriting it.
Stopping the process before copying gives the most consistent snapshot, because the database is a single JSON document rewritten atomically on save.
GET /api/health returns the instance name, version, schema version and uptime. Use it for load balancer and monitoring checks.
Browser applications cannot force a specific physical monitor on every operating system. The supported workflow is to open the audience display window and drag it to the projector, then press F for fullscreen. Windows, macOS and Linux may each handle this slightly differently.
TRUST_PROXY=1 and serve over HTTPS.MAX_UPLOAD_BYTES and the user quota, and check the reverse proxy body size limit.*.corrupt-* file next to it and restore from backup.