Features
cf config init-envgenerates the web UI login. The generated.envnow contains a randomCF_WEB_PASSWORD(useradmin), and the command prints the login once. Before, it wrote a commented-out placeholder, so a Docker setup that skipped the extra manual step answered every request through the reverse proxy with 403.- Re-running with
--forcekeeps an existing password (read the way Docker Compose reads it:export, quotes, comments), so saved logins keep working; a kept password is not printed. .envis now written with0600permissions, since it holds a credential.- A warning appears when
CF_WEB_USERNAMEorCF_WEB_PASSWORDis set in your shell, because Docker Compose then uses that value instead of.env.
- Re-running with
Improvements
- Clearer 403 for remote access without a password. The message now also names
CF_WEB_NO_AUTH=1and explains that olderdocker-compose.ymlfiles don't pass these variables to the container (CF_WEB_PASSWORDneeds v1.22.0 or later,CF_WEB_NO_AUTHv1.22.1 or later). This is what locks out existing Docker users after an image update. - Docs: the Docker Quick Start no longer needs a manual
openssl randstep and has an upgrade note; the README's Docker section and the configuration reference mention the generated login.
Full changelog: v1.25.0...v1.26.0