The API and the worker read their configuration from the environment, once, on startup
(packages/core/src/config.ts). With docker-compose.prod.yml, put them in a .env file next
to it: the compose file passes them on to the services. An empty value counts as “not set”.
The default values are the development ones; NODE_ENV=production, which the image sets
automatically, changes a few of them.
Variable Role DOMAINthe public domain, served over HTTPS by Caddy (production compose) SECRET_KEYthe instance key, 64 hexadecimal characters (openssl rand -hex 32): encrypts the source passwords and embedding secrets OPA_SECRETthe secret placed in the path of the OPA endpoint called by Trino (openssl rand -hex 24) DB_PASSWORDthe password of the catalog’s PostgreSQL (production compose)
SECRET_KEY
Without it, the API refuses to start in production. A value that is not made of 64 hexadecimal
characters is accepted and derived with SHA-256, but prefer the expected format. Changing it
makes already-stored secrets unreadable: generate it once, and back it up with the catalog.
Variable Default Role NODE_ENVdevelopmentproduction makes SECRET_KEY required and turns off by default the demo, the in-process worker and Trino’s localhost aliasPUBLIC_URLhttp://localhost:3100; in production, https://$DOMAINthe public address: sharing links, OIDC callback; https:// makes the session cookie Secure SESSION_DAYS14session lifetime, in days MAX_ROWS2000maximum rows read per interface query QUERY_TIMEOUT_MS120000maximum duration of a query CACHE_TTL300result cache lifetime, in seconds, when nothing else sets it DEMO1 in development, 0 in productioncreates the demo instance on first start INPROCESS_WORKER1 in development, 0 in productionruns the worker inside the API
Variable Default Role DATABASE_URLpostgres://eodia:eodia@localhost:55435/eodiathe catalog’s PostgreSQL database; the production compose builds it with DB_PASSWORD DATABASE_SCHEMAeodiathe catalog schema in that database
Variable Default Role TRINO_URLhttp://localhost:58080; http://trino:8080 in the compose filethe Trino address TRINO_SERVICE_USEReodia-servicethe application’s Trino user (catalogs, synchronization), which the OPA endpoint grants everything TRINO_PASSWORD— the Trino password, if your cluster requires authentication TRINO_LOCALHOST_ALIAShost.docker.internal in developmentthe name through which Trino, in its container, reaches a database declared on localhost OPA_URL— read by Trino : the OPA endpoint address, http://api:4100/internal/opa/<secret>; the compose file builds it
Variable Default Role PASSWORD_LOGIN10 turns off password sign-in: SSO onlyOIDC_ISSUER— the OpenID Connect issuer; enables SSO OIDC_CLIENT_ID— the OIDC client identifier OIDC_CLIENT_SECRET— its secret, for a confidential client OIDC_LABELSe connecter avec SSOthe label of the sign-in button, not translated: e.g. Sign in with SSO OIDC_SCOPESopenid email profilethe requested scopes OIDC_ATTRIBUTE_CLAIMS— the claims copied into attributes, comma-separated: region,departement OIDC_GROUPS_CLAIM— the claim that carries the groups to mirror
See Single sign-on .
Variable Default Role SMTP_URL— the outgoing server, as an SMTP connection URL: smtps://user:password@smtp.example.com:465 SMTP_FROMeodia insights <noreply@localhost>the sender
Without SMTP, no e-mail is sent: an invitation’s link is displayed so it can be passed on by hand.
Variable Default Role AI_PROVIDERanthropic if ANTHROPIC_API_KEY is set, otherwise openai if OPENAI_API_KEY is, otherwise noneanthropic, openai, mistral, openai-compatible or noneAI_API_KEYANTHROPIC_API_KEY, otherwise OPENAI_API_KEYthe provider key AI_MODELclaude-sonnet-5-5 (Anthropic), mistral-large-latest (Mistral), gpt-4.1 (the others)the model AI_BASE_URLthe provider’s address required for openai-compatible AI_HOURLY_QUOTA60copilot messages per person per hour AI_PROVIDER_SSL_VERIFYtruefalse: the provider’s certificate is not checked — its calls only
See Copilot .
Variable Default Read by Role API_PORT, API_HOST4100, 0.0.0.0the API where it listens WEB_PORT3100the image (web role) where the interface listens API_URLhttp://localhost:4100the interface (at build time), the MCP server the API address MCP_PORT, MCP_HOST4200, 0.0.0.0the MCP server where it listens EODIA_URL, EODIA_TOKENhttp://localhost:4100, —the MCP server over stdio the application address and the token WITH_MCP— the image (all role) 1 adds the MCP server to the container
Variable Default Role ACME_EMAIL— the contact address for Let’s Encrypt IMAGEeodia-insights:latestthe image used for api, worker, web and mcp