#!/usr/bin/env bash # Generates random values for the secrets docker-compose.yml requires # (LITELLM_MASTER_KEY, LITELLM_SALT_KEY, LITELLM_DB_PASSWORD, UI_PASSWORD, # PGVECTOR_DB_PASSWORD, LITELLM_PGVECTOR_API_KEY) and writes them into .env — # creating it from .env.example first if it doesn't exist. # # ponytail: only fills in blank values, never overwrites ones you've already # set — safe to re-run. Re-running won't touch LITELLM_SALT_KEY once it's # set; changing it after first run makes existing encrypted data unreadable. set -euo pipefail cd "$(dirname "$0")/.." [ -f .env ] || cp .env.example .env set_if_blank() { local key="$1" value="$2" if grep -qE "^${key}=.*[^[:space:]]" .env; then echo "${key}: already set, skipping." else sed -i "s|^${key}=.*|${key}=${value}|" .env echo "${key}: generated." fi } set_if_blank LITELLM_MASTER_KEY "$(openssl rand -hex 32)" set_if_blank LITELLM_SALT_KEY "$(openssl rand -hex 32)" set_if_blank LITELLM_DB_PASSWORD "$(openssl rand -hex 32)" set_if_blank UI_PASSWORD "$(openssl rand -hex 16)" set_if_blank PGVECTOR_DB_PASSWORD "$(openssl rand -hex 32)" set_if_blank LITELLM_PGVECTOR_API_KEY "$(openssl rand -hex 32)" echo "Done. Review .env, then set OPENWEBUI_LITELLM_KEY, LITELLM_PGVECTOR_EMBEDDING_KEY, and SEARXNG_LAN_IP per docs/proxy-key-onboarding.md and docs/memory-knowledgebase.md."