Skip to content

Backend configuration ​

Download the example configuration file

The file is mounted into the container at /flip/cfg/config.yaml.

Configuration scope

The file contains the settings controlled on the installation side: connections to external services, the domain, secrets and the authentication method. Background job intervals, token and cache lifetimes, limits and plan restrictions are fixed in the image and are not set in the configuration file.

Secrets

All fields marked as "secret" are required and must be unique to each installation. To generate a value:

bash
openssl rand -hex 16

Configuration fields ​

Domain ​

  • Domain: Base URL of the application, including the /app path. Used in links in emails and for SSO sign-in.
    Example: https://example.flip-chart.ru/app

LogLevel ​

  • LogLevel: Logging level: debug, info, warn, error.
    Example: info

Server ​

  • Host: Address the server listens on.
    Example: 0.0.0.0
  • Port: Server port. Must match the upstream in the nginx configuration and flipApi.internalUrl in the mcp-server configuration.
    Example: 9000
  • Timeout: HTTP request processing timeout.
    Example: 10s

Postgres ​

  • Address: PostgreSQL server address.
    Example: flip-postgres
  • Port: PostgreSQL port.
    Example: 5432
  • User: Username.
    Example: flip
  • Password: Password.
    Example: secret-passwd
  • Database: Database name.
    Example: flip
  • Driver: Migration driver. Always postgres.
  • SSLmode: SSL connection mode: disable, require, verify-full.
    For a Standalone installation with PostgreSQL in a container, use disable; for an external database, use require or verify-full.
    Example: disable
  • SSLRootCert: Path to the root certificate inside the container. Required with SSLmode: verify-full; the file must be mounted into the container.
    Example: /flip/certs/ca.pem
  • MigrationDir: Migrations directory inside the container. Always /flip/migrations.

Migrations

Database migrations are applied automatically every time the backend container starts.

S3 ​

  • AwsAccessKey: S3 storage access key.
    Example: flip-minioadmin
  • AwsSecretKey: Secret key.
    Example: flip-minioadminsecret
  • AwsRegion: Storage region. For MinIO, any value will do.
    Example: ru-central1
  • AwsUrl: S3 storage URL.
    Example: http://flip-minio:9000
  • AWSPartitionID: AWS partition ID. Leave empty.
    Example: ""
  • BucketName: Bucket name.
    Example: flip
  • Folders: Prefixes for storing data inside the bucket. The values are fixed.
    • FlipsAvatarsFolder: flips-avatars/
    • TeamsAvatarsFolder: teams-avatars/
    • UsersAvatarsFolder: avatars/
    • ElementsFolder: elements/
    • CommentsFolder: comments/
    • DocsFolder: documents/
    • LinksFolder: links/
    • PresentationFolder: presentations/
    • ShapesFolder: shapes/

Important

The backend and file-handlers services must be connected to the same S3 storage and the same bucket.

RedisClient (Valkey) ​

  • Address: Valkey server address.
    Example: flip-valkey:6379
  • Username: Username. Leave empty if ACLs are not used.
    Example: ""
  • Password: Password. Leave empty if not used.
    Example: ""
  • DB: Database number.
    Example: 0

Important

The backend, file-handlers and mcp-server services must be connected to the same Valkey instance. Only the Valkey standalone mode is supported (no Sentinel or Cluster).

Mail ​

  • Host: SMTP server address.
    Example: smtp.example.ru
  • Port: SMTP server port.
    Example: 587
  • User: SMTP username.
    Example: user
  • Password: SMTP password.
    Example: password
  • From: Sender address.
    Example: welcome@example.ru

Auth ​

Authentication settings section.

CommonAuthConfig ​

  • CommonRegistrationFlow: Self-registration of users by email. When false, users can access the application only by invitation or via SSO/LDAP.
    Example: true

ConfirmationConfig ​

  • CodeDigits: Number of digits in the email confirmation code.
    Example: 6
  • Secret: Secret used to sign confirmation codes.
    Example: 3f1c9a7e2b8d4c6a1e5f0b9d7c3a2e81

HashPasswordSalt ​

  • HashPasswordSalt: Salt for password hashing. Secret.

FlipPasswordCipherSecret ​

  • FlipPasswordCipherSecret: Secret used to encrypt board access passwords.

TokenConfig ​

  • AccessToken.Secret: Secret used to sign access tokens.
  • RefreshToken.Secret: Secret used to sign refresh tokens.
  • FlipPasswordToken.Secret: Secret used to sign access tokens for password-protected boards.

KeyCloakAuthConfig ​

Direct integration with Keycloak. Not used for SSO via OIDC/SAML — see SSO setup.

  • Enable: Enables the integration.
    Example: false
  • Address: Keycloak server address.
    Example: https://keycloak.example.ru
  • ClientID: Client ID.
  • ClientSecret: Client secret.
  • Realm: Realm name.

LdapAuthConfig ​

See LDAP integration.

  • Enable: Enables LDAP authentication.
    Example: false
  • Address: LDAP server URL.
    Example: ldap://ldap.example.ru:389
  • BaseDN: Base DN for user searches.
    Example: dc=example,dc=ru
  • BindDN: DN of the service account used to connect.
    Example: cn=admin,dc=example,dc=ru
  • BindPassword: Service account password.
  • UseTLS: Whether to run STARTTLS after connecting.
    Example: false
  • Attributes: LDAP attribute names.
    • DN: dn
    • CN: attribute with the user's display name, for example cn
    • Mail: attribute with the email address, for example mail
    • AccountStatus: account status attribute, for example accountStatus

Important

Only one provider can be enabled at a time: KeyCloakAuthConfig or LdapAuthConfig.

SessionConfig ​

  • Secret: Secret used to sign user sessions.

InvitationConfig ​

  • Secret: Secret used to sign invitation links.

FileHandlerServiceConfig ​

  • Enable: Enables interaction with the file-handlers service (document upload, conversion, previews).
    Example: true
  • Address: API address of the file-handlers service.
    Example: http://flip-file-handlers:8080/api

Documents ​

  • Enable: Enables the documents feature on boards.
    Example: true

McpAgentTokens ​

Authorization of AI agents through the MCP server.

  • Enable: Enables issuing tokens to agents via OAuth. Must be true when the MCP server is used.
    Example: true
  • OAuth.Clients: List of OAuth clients. By default, it contains the built-in flip-mcp client (matches flipApi.clientId in the mcp-server configuration) with the callback URLs http://localhost:*, https://claude.ai/api/mcp/auth_callback, https://claude.com/api/mcp/auth_callback and the scopes flip:read, flip:write, comment:read. Set it only if you need to replace the built-in list; the value you set replaces that list entirely.
    • id: Client ID.
    • name: Display name shown on the access consent screen.
    • redirectURIPatterns: Allowed callback URLs of MCP clients.
    • scopes: Scopes granted to the client.
    • isPublic: Public client (PKCE, no client secret). Value: true.

flip on-premise and cloud documentation