Skip to content

Environment Variables

Environment variables and settings.env provide bootstrap defaults. Administration settings saved through the GUI are persisted in data/rct.db. HMAC_SECRET always stays outside the database. Timeouts, retries, cache, limits and intervals remain fixed in code.

A set variable that is an internal setting but not one of these operator names is logged once at start (never its value). Completely unknown variables are ignored.

Variable Default Meaning
HMAC_SECRET generated locally Stable secret, at least 32 characters (openssl rand -base64 32); provide before Docker startup. The old name ADMIN_SECRET still works but logs a deprecation warning
ADMIN_DB_PATH <project>/data/rct.db Location of the encrypted admin database
DISPATCH_DB_PATH <project>/data/rct-dispatch.db Location of the encrypted, crash-durable dispatch state database
DISPATCH_MAX_CHARGE_POWER_W unset Verified maximum grid-charge power; required for dispatch
DISPATCH_MAX_DISCHARGE_POWER_W unset Verified maximum load-following discharge power; required for dispatch
BIND_ADDRESS 127.0.0.1 Listen address
BIND_PORT 8000 Listen port, 1024 to 65535
ALLOW_NON_LOOPBACK_BIND false Explicit consent for a non-loopback listener; does not provide TLS or secure cookies. Compose sets it while publishing only on host loopback
DOCS_PUBLIC false true: serve /docs and /openapi.json without a token; false: both return 404 on every bind address
LOG_LEVEL INFO DEBUG, INFO, WARNING or ERROR
TRUSTED_PROXIES empty Networks (CIDR, comma separated, at most 32) of reverse proxies whose forwarding header is trusted
FORWARDED_HEADER empty Single-address header set by the proxy, for example X-Forwarded-For; requires TRUSTED_PROXIES. Forwarded (RFC 7239) is rejected
ENABLE_METRICS_ENDPOINT true false: GET /metrics answers 404
DB_TYPE and INFLUXDB_* / QUESTDB_* unset Optional push export, see Push export
METRICS_EXPORT_ENABLED true false pauses the push export without losing its connection settings
METRICS_EXPORT_INTERVAL_SECONDS 30 Export interval in seconds, 5 to 3600

The dispatch values are deliberately not guessed. The strategy code and both sign conventions used to live as the three environment variables DISPATCH_SOC_STRATEGY_EXTERNAL_CODE, DISPATCH_BATTERY_DISCHARGE_POSITIVE and DISPATCH_GRID_IMPORT_POSITIVE; this is a non-backward-compatible configuration change: all three are now fields of a persisted, per-device capability record, set through the admin dispatch API after hardware verification, not through the environment. A set value for any of the three is ignored with a WARNING naming the variable (never its value). See Operation for the capability workflow and the engineering-mode escape hatch. The dispatch database must be backed up together with HMAC_SECRET, just like data/rct.db.

GUI-only settings

Authentication, API tokens, devices, write support and reverse-proxy mode are set in the admin GUI. The variables AUTH_REQUIRED, API_TOKENS, API_TOKENS_FILE, BEHIND_REVERSE_PROXY and ENABLE_WRITE_SUPPORT are ignored with a startup warning; DEVICES is ignored with an INFO note.

Validate a configuration

python -m app validate

The command checks the settings, the object registry and the write allowlist and exits with a non-zero status on an invalid configuration.