Skip to content

Environment variables

The API and the worker read their configuration from the environment, once, on startup (packages/core/src/config.ts). With docker-compose.prod.yml, put them in a .env file next to it: the compose file passes them on to the services. An empty value counts as “not set”.

The default values are the development ones; NODE_ENV=production, which the image sets automatically, changes a few of them.

VariableRole
DOMAINthe public domain, served over HTTPS by Caddy (production compose)
SECRET_KEYthe instance key, 64 hexadecimal characters (openssl rand -hex 32): encrypts the source passwords and embedding secrets
OPA_SECRETthe secret placed in the path of the OPA endpoint called by Trino (openssl rand -hex 24)
DB_PASSWORDthe password of the catalog’s PostgreSQL (production compose)
VariableDefaultRole
NODE_ENVdevelopmentproduction makes SECRET_KEY required and turns off by default the demo, the in-process worker and Trino’s localhost alias
PUBLIC_URLhttp://localhost:3100; in production, https://$DOMAINthe public address: sharing links, OIDC callback; https:// makes the session cookie Secure
SESSION_DAYS14session lifetime, in days
MAX_ROWS2000maximum rows read per interface query
QUERY_TIMEOUT_MS120000maximum duration of a query
CACHE_TTL300result cache lifetime, in seconds, when nothing else sets it
DEMO1 in development, 0 in productioncreates the demo instance on first start
INPROCESS_WORKER1 in development, 0 in productionruns the worker inside the API
VariableDefaultRole
DATABASE_URLpostgres://eodia:eodia@localhost:55435/eodiathe catalog’s PostgreSQL database; the production compose builds it with DB_PASSWORD
DATABASE_SCHEMAeodiathe catalog schema in that database
VariableDefaultRole
TRINO_URLhttp://localhost:58080; http://trino:8080 in the compose filethe Trino address
TRINO_SERVICE_USEReodia-servicethe application’s Trino user (catalogs, synchronization), which the OPA endpoint grants everything
TRINO_PASSWORD—the Trino password, if your cluster requires authentication
TRINO_LOCALHOST_ALIAShost.docker.internal in developmentthe name through which Trino, in its container, reaches a database declared on localhost
OPA_URL—read by Trino: the OPA endpoint address, http://api:4100/internal/opa/<secret>; the compose file builds it
VariableDefaultRole
PASSWORD_LOGIN10 turns off password sign-in: SSO only
OIDC_ISSUER—the OpenID Connect issuer; enables SSO
OIDC_CLIENT_ID—the OIDC client identifier
OIDC_CLIENT_SECRET—its secret, for a confidential client
OIDC_LABELSe connecter avec SSOthe label of the sign-in button, not translated: e.g. Sign in with SSO
OIDC_SCOPESopenid email profilethe requested scopes
OIDC_ATTRIBUTE_CLAIMS—the claims copied into attributes, comma-separated: region,departement
OIDC_GROUPS_CLAIM—the claim that carries the groups to mirror

See Single sign-on.

VariableDefaultRole
SMTP_URL—the outgoing server, as an SMTP connection URL: smtps://user:password@smtp.example.com:465
SMTP_FROMeodia insights <noreply@localhost>the sender

Without SMTP, no e-mail is sent: an invitation’s link is displayed so it can be passed on by hand.

VariableDefaultRole
AI_PROVIDERanthropic if ANTHROPIC_API_KEY is set, otherwise openai if OPENAI_API_KEY is, otherwise noneanthropic, openai, mistral, openai-compatible or none
AI_API_KEYANTHROPIC_API_KEY, otherwise OPENAI_API_KEYthe provider key
AI_MODELclaude-sonnet-5-5 (Anthropic), mistral-large-latest (Mistral), gpt-4.1 (the others)the model
AI_BASE_URLthe provider’s addressrequired for openai-compatible
AI_HOURLY_QUOTA60copilot messages per person per hour
AI_PROVIDER_SSL_VERIFYtruefalse: the provider’s certificate is not checked — its calls only

See Copilot.

VariableDefaultRead byRole
API_PORT, API_HOST4100, 0.0.0.0the APIwhere it listens
WEB_PORT3100the image (web role)where the interface listens
API_URLhttp://localhost:4100the interface (at build time), the MCP serverthe API address
MCP_PORT, MCP_HOST4200, 0.0.0.0the MCP serverwhere it listens
EODIA_URL, EODIA_TOKENhttp://localhost:4100, —the MCP server over stdiothe application address and the token
WITH_MCP—the image (all role)1 adds the MCP server to the container
VariableDefaultRole
ACME_EMAIL—the contact address for Let’s Encrypt
IMAGEeodia-insights:latestthe image used for api, worker, web and mcp

eodia insights is free software by Eodia.