Configure & initialize
Edit .env privately. Set the real application URL and database credentials. The values below are placeholders:
APP_ENV=production
APP_DEBUG=false
APP_DEMO=false
APP_URL=https://hr.example.com
APP_TIMEZONE=UTC
TELESCOPE_ENABLED=false
DB_CONNECTION=mysql
DB_HOST=127.0.0.1
DB_PORT=3306
DB_DATABASE=your_database
DB_USERNAME=your_database_user
DB_PASSWORD=your_private_password
QUEUE_CONNECTION=database
CACHE_STORE=file
SESSION_DRIVER=file
DOCUMENTATION_URL=https://docs.opencorehr.com
APP_URL also controls password reset email links. Configure SMTP before testing recovery. Review locale defaults in .env.example; manage company localization in the app after installation.
Initialize a fresh database
The current initialization uses command-line tools, with no browser installer. On a new, empty database only:
php artisan migrate --force
php artisan db:seed --force
php artisan storage:link
php artisan optimize
Review the supplied seeders and enabled modules before customer use. Current seeders create a known demonstration administrator (superadmin@demo.com, password 123456) and can include module fixtures. APP_DEMO=false disables the optional demo seeder; it does not remove every sample record or change this password.
Keep access restricted while initializing. Immediately change the administrator email/password, review seeded data, and verify role/portal access before opening to employees. A secure customer bootstrap and clean seed-data audit remain release acceptance items.
Never reset a database, run migrate:fresh, re-run demo seeders or regenerate existing keys during updates.
Files and modules
The web process needs write access to storage and bootstrap/cache. Keep private documents private; do not link all of storage publicly. Use authorized application downloads.
Review optional features in Modules. Disabling a module changes app availability; its public documentation remains visible and labels the required module.