tide
Contents +

Configuration

tide reads only these environment variables. All are optional. With none, tide runs without sign-in on http://localhost:8080. tide does not start if a required variable is missing or too short.

Server

Variable Default Meaning
TIDE_ADDR :8080 Listen address.
TIDE_BASE_URL http://localhost:8080 The address people open, with https://. No trailing slash.
TIDE_SESSION_SECRET random at each start, without sign-in Required with sign-in, 32+ characters. Signs session cookies. Use random data.
TIDE_DB_PATH ./data/tide.db The SQLite database, with sign-in. The image uses /data/tide.db. Put a durable volume at /data.
TIDE_DEV_MODE false For local development only. Do not use it in production.

Sign-in

Variable Default Meaning
TIDE_OIDC_ISSUER none: no sign-in Turns sign-in on. Use the issuer URL exactly as the provider shows it. Without it, anyone can make a room.
TIDE_OIDC_CLIENT_ID tide The client ID.
TIDE_OIDC_CLIENT_SECRET — Required with sign-in, 16+ characters. The client secret.
TIDE_USER_GROUPS empty Groups that can sign in, with commas between them. Empty lets all users sign in.
TIDE_ADMIN_GROUPS empty Groups that can manage all rooms, with commas between them.

Media

Variable Default Meaning
TIDE_MEDIA_NODE_IP 127.0.0.1 on localhost, else found The IPv4 address that browsers send media to. Set it only behind a load balancer or NAT. With recording, the recorder must also reach it.
TIDE_MEDIA_UDP_PORT 7882 Media over UDP. Open it to the internet.
TIDE_MEDIA_TCP_PORT 7881 Media when UDP is blocked. Open it to the internet.
TIDE_MEDIA_API_PORT 7880 The media server's API, on 127.0.0.1 only. Change it to run two tides on one host.
TIDE_MEDIA_API_KEY random at each start Required with recording. The media key. tide and the recorder use the same one. Letters, digits, - and _.
TIDE_MEDIA_API_SECRET random at each start Required with recording, 32+ characters. The secret for the media key.
TIDE_MEDIA_URL none: built in An external media server. Only for old installations. It needs the key, the secret and TIDE_MEDIA_PUBLIC_URL.
TIDE_MEDIA_PUBLIC_URL the base URL, as ws or wss The external media server, as browsers reach it. Only with TIDE_MEDIA_URL.

Recording

Variable Default Meaning
TIDE_S3_ENDPOINT none: no recording Turns recording on. Needs sign-in. The bucket address, as tide reaches it.
TIDE_S3_PUBLIC_ENDPOINT TIDE_S3_ENDPOINT The bucket address, as browsers reach it. Use HTTPS.
TIDE_S3_RECORDER_ENDPOINT TIDE_S3_ENDPOINT The bucket address, as the recorder reaches it.
TIDE_S3_BUCKET tide-recordings The bucket. tide puts recordings in recordings/.
TIDE_S3_REGION us-east-1 The bucket region.
TIDE_S3_ACCESS_KEY — Required with recording. The access key.
TIDE_S3_SECRET_KEY — Required with recording, 16+ characters. The secret key.
TIDE_RECORDER_REDIS_PASSWORD — Required with recording, 32+ characters. The Redis password. tide and the recorder use the same one. Use hex.
TIDE_RECORDER_REDIS_ADDR 127.0.0.1:6379 The Redis that tide and the recorder use, as host:port. Keep it private: jobs contain the bucket keys. Use one Redis for each tide.
TIDE_RECORDER_TEMPLATE_URL TIDE_BASE_URL + /egress-template The page that the recorder opens to draw a meeting. Beside tide, use http://127.0.0.1:8080/egress-template.

Rate limits

Variable Default Meaning
TIDE_TRUSTED_PROXIES empty The addresses of your proxy, as IPs or CIDRs with commas between them. tide then trusts their X-Forwarded-For.
TIDE_JOIN_RATE_LIMIT 10 Joins for each client in a minute. Also limits new rooms without sign-in.
TIDE_WAIT_RATE_LIMIT 20 Lobby waits for each client in a minute.
TIDE_LOGIN_RATE_LIMIT 10 Sign-ins for each client in a minute.
TIDE_PAIR_RATE_LIMIT 10 Machine pairings for each client in a minute.

Transcripts

Variable Default Meaning
TIDE_TRANSCRIPTS false Turns transcripts on. Needs recording.