Skip to main content

Configuration

Configure your self-hosted Runtime instance with environment variables.

Required Variables

These must be set for Runtime to function:

All Variables

Database

Redis

API Server

Worker

Token Security

Custom Domains (Optional)

Limits (Optional)

Example Configuration

Development (.env)

Production (.env)

Generating Secrets

API Secret

Token Pepper

Security Considerations

Never commit .env files to version control. Add .env to .gitignore.

Best Practices

Generate all secrets with openssl rand:
Set ?sslmode=require on DATABASE_URL. Use rediss:// (with SSL) for Redis.
In production, set CORS_ORIGINS to your specific domains.
Create a deploy-only token, not a full access token:

Pepper Rotation

To rotate the token pepper (e.g., after a breach):
  1. Add new pepper:
  2. Wait for old tokens to expire or be revoked
  3. Remove old pepper:
See admin commands for the guided rotation process.

Validating Configuration

After setting up, verify your configuration:

Next Steps

Admin Commands

Create and manage API tokens

Docker Compose

Service orchestration