Skip to content

Configuration

Settings are read from environment variables. In Docker pass them with -e. From source, copy the template and fill it in:

Terminal window
cp .env.template .env

Business settings, e.g. timeouts and allowed networks, live in the database and are changed in the admin UI, see Settings.

Read by the proxy, the API and the management commands.

VariableDescription
DATABASE_URLPostgreSQL URL, e.g. postgres://user:password@host/db_name
ENCRYPTION_KEYFernet key that encrypts private keys of TLS certificates in the database, see TLS
ENCRYPTION_OLD_KEYSComma-separated previous keys, they still decrypt during key rotation
DATABASE_ECHOLog every SQL query, default false. Parameters are always hidden
DATABASE_POOL_SIZEConnections each process keeps open, default 5
DATABASE_POOL_MAX_OVERFLOWExtra connections under load, default 10
DATABASE_POOL_TIMEOUTSeconds to wait for a free connection, default 30
DATABASE_POOL_RECYCLESeconds after which a connection is replaced, default -1 (never)
VariableDescription
PROXY_LISTENAddresses to listen on, default 127.0.0.1:8080, see below
PROXY_GRACEFUL_TIMEOUTSeconds open connections get to finish on shutdown, default 30
PROXY_LOG_LEVELDEBUG, INFO, WARNING, ERROR or CRITICAL, default INFO
PROXY_SETTINGS_POLL_INTERVALSeconds between lookups of the settings from the admin UI, default 5

PROXY_LISTEN is a comma-separated list of host:port pairs. A host is an IP address, a network or a host name, IPv6 goes in brackets. A port may be an inclusive range. Every host listens on every port of its pair:

Terminal window
PROXY_LISTEN=127.0.0.1:8080 # one socket
PROXY_LISTEN=localhost:8080 # every address localhost resolves to
PROXY_LISTEN=0.0.0.0:8080,[::]:8080 # all IPv4 and IPv6 interfaces
PROXY_LISTEN=10.0.0.0/29:10000-10999 # 6 host addresses x 1000 ports

Host names are resolved once, on start.

VariableDescription
API_SECRET_KEYSecret that signs API user tokens, at least 32 characters. Changing it logs everyone out
API_CORS_ORIGINSComma-separated browser origins allowed to call the API, e.g. the admin dev server. Empty blocks all
API_OUTGOING_POOL_MAX_SIZEIPs in one outgoing IP pool at most, default 256
API_POLICIES_MAX_PER_OWNERPolicies assigned to one account or trusted network at most, up to 100, default 32
VariableDescription
SUPERUSER_EMAILcreatesuperuser --no-input: email, if --email isn’t passed
SUPERUSER_PASSWORDcreatesuperuser --no-input: password, there is no flag for it
SUPERUSER_NAMEcreatesuperuser --no-input: name, if --name isn’t passed, default blank
SUPERUSER_SURNAMEcreatesuperuser --no-input: surname, if --surname isn’t passed, default blank

Without --no-input these are ignored: createsuperuser always prompts.

Read only by the image. There DATABASE_URL, ENCRYPTION_KEY and API_SECRET_KEY are optional: unset, the bundled PostgreSQL runs and the keys are generated once, all kept in the volume.

VariableDescription
PROXIUM_SERVICESServices to run, comma-separated: proxy, api, admin. Default all
SUPERUSER_CREATEtrue creates the superuser from SUPERUSER_* on start, an existing one is skipped. Default false
ADMIN_TLSHow the admin UI is served: off, auto, files or internal, see HTTPS for the admin UI. Default off
ADMIN_HOSTAdmin host name, e.g. admin.example.com. Needed by auto and files, internal defaults to localhost
ADMIN_ACME_CAOwn ACME server for auto instead of Let’s Encrypt
ADMIN_HTTP_PORTAdmin HTTP port, default 80
ADMIN_HTTPS_PORTAdmin HTTPS port, default 443
API_BINDWhere the API listens, default the socket unix:/run/proxium/api.sock
ADMIN_API_UPSTREAMWhere the admin UI finds the API, default the same socket. host:port when the API runs in another container