Pin the release and set the minimum contract.
Use an explicit 2.0.0 image tag or immutable digest. Configure the database password, public URL values, NEXTAUTH_SECRET, API_KEY_SECRET, and the stable 64-hex-character ENCRYPTION_KEY. Other provider or API secrets are conditional on the features you enable.
OPSKNIGHT_IMAGE=ghcr.io/opsknight-labs/opsknight:2.0.0
POSTGRES_PASSWORD=<unique-password>
NEXTAUTH_URL=http://localhost:3000
NEXT_PUBLIC_APP_URL=http://localhost:3000
NEXTAUTH_SECRET=<random-base64-secret>
API_KEY_SECRET=<separate-base64-secret>
ENCRYPTION_KEY=<64-hex-character-key>