Admin commands
These commands run inside the app container with docker exec (or docker compose exec), so only someone with access to the server can use them. Passwords are read from the environment or a file, never from the command line, so they don’t end up in your shell history.
set-password
Section titled “set-password”Gives a user a password and makes them an admin. Creates the user, with the default spaces, if the email is new.
docker compose exec -e ADMIN_PASSWORD='change-me-please' app \ node scripts/admin.mjs set-password you@example.comIt also:
- marks the email as verified, since you’re vouching for it;
- signs the user out of every existing session;
- marks first-run setup as complete, closing
/setupif it was still open.
Use it to recover a locked-out admin, or to reset anyone’s password without email.
Read the password from a file
Section titled “Read the password from a file”docker compose exec -e ADMIN_PASSWORD_FILE=/run/secrets/admin_password app \ node scripts/admin.mjs set-password you@example.comOne trailing newline is removed from the file.
bootstrap
Section titled “bootstrap”Runs automatically every time the container starts; you don’t normally run it yourself. While no admin exists, it creates one from ADMIN_EMAIL or prints a setup token. Once an admin exists, it only marks setup as complete. See First-run setup.
docker compose exec app node scripts/admin.mjs bootstrapSee also
Section titled “See also”- First-run setup: how the first admin is created
- Users and sign-up: manage users from the app