Skip to main content

Environment variables

All configuration comes from the environment. See .env.example in the repo root. Secrets must come from a secret store in production, never a committed file.

Postgres​

VariableNotes
POSTGRES_USERDefault zeallm
POSTGRES_PASSWORDRequired — compose fails if unset
DATABASE_URLFull URL; local tooling uses host port 55432

Portal​

VariableNotes
AUTH_SECRETNextAuth secret (32 random bytes). Rotating invalidates sessions
AUTH_URLPortal public URL
ZEALLM_ENCRYPTION_KEYAES-256-GCM master key (64 hex / base64) or akv:<secret-name>
ZEALLM_ENCRYPTION_KEY_FALLBACKPrevious key during rotation
ZEALLM_ADMIN_EMAILSComma-separated bootstrap admins
ZEALLM_ALLOWED_DOMAINEmail domain restriction
AUTH_DEV_BYPASStrue = password-less sign-in. Local/dev only. Ignored when NODE_ENV=production. Keep false in production .env and rebuild portal after auth changes
AZURE_AD_CLIENT_ID / _SECRET / _TENANT_IDEntra ID SSO (required in production)
NEXT_PUBLIC_DOCS_URLDocumentation site URL. Default http://localhost:3002
ZEAGATE_PUBLIC_URLPublic gateway URL shown to clients (portal only)
ZEAGATE_INTERNAL_URLGateway URL the portal calls itself (key "Send test request"), e.g. http://zeagate:8080. Falls back to ZEAGATE_PUBLIC_URL
ZEALLM_TIMEZONESame value as the gateway's; the portal uses it for budget forecast dates (default: server time zone)
OPENAI_API_KEYSeeds an OpenAI credential on first portal boot
CRON_SECRETBearer secret (32+ random characters) for scheduled jobs on /api/cron/*, e.g. the weekly digest. Unset = jobs disabled (503)
APPROVAL_LINKS_REQUIRE_SIGNINtrue = Approve/Reject links in approval emails also require signing in. Default false: email links are bound to the recipient and work without a session. Slack/Teams links always require sign-in

Gateway​

VariableNotes
DATABASE_URLRequired
ZEALLM_ENCRYPTION_KEYRequired
REDIS_URLShared rate limits + cache invalidation
ZEALLM_TIMEZONEBudget reset timezone (default UTC)
ZEALLM_BUDGET_RESET_TIMEHH:MM (default 00:00)
AZURE_KEY_VAULT_URLResolves akv: refs
ZEAGATE_PORTListen port (default 8080)
ZEAGATE_CACHE_TTL_SECONDSIn-memory cache TTL (default 15)
ZEALLM_PORTAL_URLPortal URL for gateway internals

AI Subscriptions​

VariableNotes
SUBSCRIPTION_COMPANY_ONLYDefault on: AI Subscriptions tracks only company-paid accounts. Set false to let account creators manage their own accounts and to allow device collection
SUBSCRIPTION_DEVICE_COLLECTION_ENABLEDtrue (with SUBSCRIPTION_COMPANY_ONLY=false) shows Enroll my collector. Default off

Docs site (build arguments)​

The docs image reads these at build time (docker build --build-arg … or build.args in Compose). Without them the navbar links point at the local stack.

VariableNotes
DOCS_SITE_URLPublic URL of this site, used for canonical links and the sitemap. Default http://localhost:3002
DOCS_PORTAL_URLTarget of the navbar Portal link. Default http://localhost:3000
DOCS_GATEWAY_URLGateway base URL; the navbar Gateway link opens <url>/health. Default http://localhost:8080

Email​

VariableNotes
SMTP_HOSTOptional; without it invites still create accounts
SMTP_PORTDefault 587
SMTP_USER / SMTP_PASS / SMTP_FROMSMTP auth and from-address

Do not reuse developer .env values in production. Generate fresh secrets and rotate anything that was ever shared.