Configuration
Configure your self-hosted Runtime instance with environment variables.Required Variables
These must be set for Runtime to function:All Variables
Database
Redis
API Server
Worker
Token Security
Custom Domains (Optional)
Limits (Optional)
Example Configuration
Development (.env)
Production (.env)
Generating Secrets
API Secret
Token Pepper
Security Considerations
Best Practices
Use strong secrets
Use strong secrets
Generate all secrets with
openssl rand:Use TLS in production
Use TLS in production
Set
?sslmode=require on DATABASE_URL.
Use rediss:// (with SSL) for Redis.Restrict CORS origins
Restrict CORS origins
In production, set
CORS_ORIGINS to your specific domains.Secure the Fly.io token
Secure the Fly.io token
Create a deploy-only token, not a full access token:
Pepper Rotation
To rotate the token pepper (e.g., after a breach):-
Add new pepper:
- Wait for old tokens to expire or be revoked
-
Remove old pepper:
Validating Configuration
After setting up, verify your configuration:Next Steps
Admin Commands
Create and manage API tokens
Docker Compose
Service orchestration