Skip to content

Environment variables

eodia analytics is configured through environment variables. In development, copy .env.example to .env at the root of the repository: the API, the worker, the web app and Docker Compose all read it. A variable already present in the environment (Docker, CI) always wins; .env.local, if it exists, wins over .env.

VariableDefault (development)Role
NODE_ENVdevelopmentproduction makes SECRET_KEY mandatory and turns off the demo and the built-in worker
DATABASE_URLpostgres://eodia:eodia@localhost:55436/analyticsthe database; the user owns the three schemas
READER_PASSWORDeodia-analytics in developmentthe password of the eodia_analytics read role; if absent in production, the role exists but cannot sign in
SECRET_KEYa development key64 hexadecimal characters: encrypts the site secrets. Mandatory in production
SESSION_DAYS14the length of a sign-in session, in days
Fenêtre de terminal
# An instance key:
openssl rand -hex 32
VariableDefaultRole
PUBLIC_URLhttp://localhost:3600the address of the administration (invitation links, OIDC); https:// makes the session cookie Secure
COLLECT_URLhttp://localhost:4600 in development, PUBLIC_URL in productionthe public address of /a.js and /collect: the one used in the installation snippets. See the collection domain
API_PORT4600the port the API listens on
API_HOST0.0.0.0the address the API listens on
API_URLhttp://localhost:4600the address of the API, to which the interface relays /api/*
VariableDefaultRole
TRUST_PROXY0 in development, 1 in productionread the visitor’s address from X-Forwarded-For; only behind a trusted proxy
GEOIP_DB—the .mmdb country file (DB-IP Lite, CC BY 4.0); without it, only the proxy header (CF-IPCountry, X-Country-Code) gives the country
COLLECT_RATE120events per minute and per visitor, at most
COLLECT_FLUSH_MS1000the maximum delay before a batch is written, in milliseconds
VariableDefaultRole
INSIGHTS_URL—the insights address: the Statistics button, and the only origin listened to by preview mode
INSIGHTS_EMBED_KID—the identifier of the embedding secret created in insights
INSIGHTS_EMBED_SECRET—its value
INSIGHTS_EMBED_TTL240the validity of a signed link, in minutes

See the Statistics button.

VariableDefaultRole
OIDC_ISSUER—the OpenID Connect issuer; enables SSO
OIDC_CLIENT_ID—the client identifier
OIDC_CLIENT_SECRET—the client secret, if it is confidential
OIDC_LABELSe connecter avec SSOthe button label
OIDC_SCOPESopenid email profilethe requested scopes
OIDC_GROUPS_CLAIM—the groups claim to mirror onto the groups with the same name
PASSWORD_LOGIN10 to keep only SSO

See single sign-on.

VariableDefaultRole
SMTP_URL—the outgoing mail server: smtp://user:password@smtp.example.com:587; without it, invitation links are copied by hand
SMTP_FROMeodia analytics <noreply@localhost>the sender
VariableDefaultRole
DEMO1 in development, 0 in productioncreates the admin@eodia.local account and the demo sites (Maison Arvor, the Arvor blog)
INPROCESS_WORKER1 in development, 0 in productionruns the worker inside the API process

docker-compose.prod.yml also reads:

VariableRole
DOMAINthe public domain, served over HTTPS by Caddy
ACME_EMAILthe contact address for certificates (default admin@DOMAIN)
DB_PASSWORDthe database password
IMAGEthe image to use (default eodia-analytics:latest)

eodia analytics is free software by Eodia.