Docs › Configuration
Configuration
All configuration is done via environment variables. Settings with a default value are optional.
Core
| Variable | Description | Default |
|---|---|---|
DATABASE_URL |
sqlite:///path.db or postgresql://… — see Database |
sqlite:///data/garden.db |
SECRET_KEY |
Session/CSRF signing key (≥32 bytes recommended) | dev-secret-change-me (dev only; fails fast in prod) |
ADMIN_PASSWORD |
Password for admin login | (unset, login disabled unless OAuth configured) |
DEBUG |
Enable debug mode | false |
Warning:
SECRET_KEYdefaults to an insecure dev value. When the database isn't local (aDATABASE_URLthat is neither SQLite norlocalhost) andDEBUG=false, the app refuses to start until you set a real key. Generate one withopenssl rand -hex 32.
Authentication
| Variable | Description | Default |
|---|---|---|
OAUTH_CLIENT_ID |
OAuth2/OIDC client ID | (unset) |
OAUTH_CLIENT_SECRET |
OAuth2/OIDC client secret | (unset) |
OAUTH_ISSUER_URL |
OAuth provider issuer URL | (unset) |
OAUTH_REDIRECT_URI |
OAuth callback URL | (unset) |
OAUTH_ALLOWED_GROUP |
Restrict admin access to this group | (unset, any authenticated user is admin) |
OAUTH_SCOPE |
OAuth scopes requested | openid profile email groups |
OAUTH_PROVIDER_NAME |
Display name for the OAuth provider | oauth |
Warning: If
OAUTH_ALLOWED_GROUPis empty, any user who can authenticate against the issuer is granted admin access. Always set it in production.
Storage
These can also be configured in Settings in the admin. Environment variables take effect as fallbacks when no database setting exists. The S3_SECRET_ACCESS_KEY is write-only in the admin UI — it is never echoed back; leave the field blank when saving to keep the stored value.
| Variable | Description | Default |
|---|---|---|
STORAGE_BACKEND |
local or s3 |
local |
S3_BUCKET |
S3-compatible bucket name | (unset) |
S3_REGION |
S3 region | us-east-1 |
S3_ENDPOINT_URL |
Custom S3 endpoint (R2, MinIO) | (unset) |
S3_ACCESS_KEY_ID |
S3 access key | (unset) |
S3_SECRET_ACCESS_KEY |
S3 secret key (write-only) | (unset) |
S3_PREFIX |
Object key prefix | (unset) |
S3_PUBLIC_URL |
Public CDN URL for direct media serving | (unset) |
MEDIA_ROOT |
Local storage folder (media and md/) |
data/media |
MD_SEED_DIR |
Markdown copied into empty storage on start | data/md |
Performance
| Variable | Description | Default |
|---|---|---|
STATELESS |
Reload content and settings from DB on every request | false |
Observability (optional)
| Variable | Description | Default |
|---|---|---|
OTEL_RESOURCE_ATTRIBUTES |
OpenTelemetry resource attributes | (unset) |
OTEL_EXPORTER_OTLP_ENDPOINT |
OTLP collector endpoint | (unset) |
OTEL_EXPORTER_OTLP_INSECURE |
Allow insecure OTLP | (unset) |
OTEL_EXPORTER_OTLP_PROTOCOL |
OTLP protocol (grpc/http) |
(unset) |
OTEL_METRICS_EXPORTER |
Metrics exporter (none to disable) |
(unset) |