Environment Variables¶
Regardless of where the application is deployed, these are the available environment variables for the different target scopes:
| Variable Name | Requirement Status | Target Scope | Platform | Default Value | Description |
|---|---|---|---|---|---|
| POSTGRES_HOST | Required | DB Migration | All | None | Hostname or IP address of the database instance |
| POSTGRES_PASSWORD | Required | DB Migration | All | None | Password to connect to the database instance |
| POSTGRES_USERNAME | Required | DB Migration | All | None | Username to connect to the database instance |
| OTEL_OTLP_USER_ID | Conditional | DB Migration | All | None | If OTEL_OTLP_ENDPOINT is set, then define the user name or ID to authenticate to the remote OpenTelemetry collector to push the logs |
| OTEL_OTLP_TOKEN | Conditional | DB Migration | All | None | If OTEL_OTLP_ENDPOINT is set, then define the token to authenticate the remote OpenTelemetry collector to push the logs |
| CI_ENVIRONMENT_SLUG | Required | Backend and Frontend | All | None | Current environment, mainly used for logging |
| DEFAULT_STORAGE_SIZE_LIMIT_BYTES | Optional | Backend and Frontend | All | 524288000 |
Default storage size limit (in bytes) for storing all the uploaded files |
| EMAIL_SENDER | Required | Backend | All | None | Source email address for sending out email |
| EMAIL_TOKEN_EXPIRY_DURATION_SECS | Required | Backend | All | None | Duration of validity of any tokens sent by email |
| JWT_PAT_SECRET_KEY | Required | Backend and Frontend | All | None | Secret key to decode SON Web Token (JWT) personal access token |
| JWT_SECRET_KEY | Required | Backend and Frontend | All | None | Secret key to decode SON Web Token (JWT) auth access token |
| ORIGIN | Required | Backend and Frontend | All | None | Origin URL of the application |
| POSTGRES_CONNECTION_STRING | Required | Backend | AWS and On-Prem | None | Connection string for the app to connect to the database in the format of Server=<db-instance-hostname-or-ip>;Database=<db-name>;Port=<db-port>;Userid=<db-user>;Password=<db-password> |
| PUBLIC_COOKIE_DOMAIN | Required | Backend and Frontend | All | None | Define the scope of the cookies. It dictates which domains and subdomains can access or receive the cookie during HTTP requests |
| PUBLIC_MAX_FILE_UPLOAD_SIZE_MiB | Required | Backend and Frontend | All | None | Max file size (in MiB) allowed for the upload |
| S3_BUCKET | Conditional | Backend | AWS | None | If STORAGE_MODE is S3, then this points to the s3 bucket to store the uploaded files |
| STORAGE_MODE | Optional | Backend | All | FILESYSTEM |
Set the storage to either S3 (for s3 bucket), FILESYSTEM (for local filesystem) or AZURE (for blob storage) |
| VERIFY_EMAIL_TOKEN_EXPIRY_DURATION_SECS | Optional | Backend | All | 300 |
Duration of validity (in seconds) of email verification token |
| EMAIL_SERVICE_PROVIDER | Optional | Backend | All | SES |
Set the email service to be used to send out emails. Currently accepts ACS,SES or SMTP |
| SMTP_HOST | Conditional | Backend | All | None | If EMAIL_SERVICE_PROVIDER is SMTP, then set this variable to the SMTP hostname or domain |
| SMTP_USERNAME | Conditional | Backend | All | None | If EMAIL_SERVICE_PROVIDER is SMTP, then set this variable to the SMTP username |
| SMTP_PASSWORD | Conditional | Backend | All | None | If EMAIL_SERVICE_PROVIDER is SMTP, then set this variable to the SMTP password for the given username |
| SMTP_PORT | Optional | Backend | All | 587 |
If EMAIL_SERVICE_PROVIDER is SMTP, then set this variable to the SMTP port to connect |
| SMTP_INSECURE_CONNECTION | Optional | Backend | All | false |
If EMAIL_SERVICE_PROVIDER is SMTP, then set this variable to true or false |
| DEV_ACCOUNT_EMAIL | Required | Backend and DB Migration | All | None | Dev account to be seeded for the first time into the database. If the email already exists, then that account will be upgraded to a dev account |
| OTEL_USE_GRPC | Optional | Backend and Frontend | All | false |
Use OTLP/GRPC instead of OTLP/HTTP (Protobuf) as an exporter protocol for OpenTelemetry |
| OTEL_OTLP_ENDPOINT | Optional | All | All | None | Set the OpenTelemetry exporter endpoint URL (with port number) to push the observability data |
| AZURE_COMMUNICATION_SERVICE_CONNECTION_STRING | Conditional | Backend | Azure | None | Required if EMAIL_SERVICE_PROVIDER is set as ACS. This value can be retrieved from the Azure Communication Services page under the Keys section |
| PUBLIC_ENDPOINT | Required | Frontend | All | None | URL of the app's backend endpoint |
| PUBLIC_INTERNAL_ENDPOINT | Required | Frontend | All | None | Internal (private) URL of the app's backend endpoint. This application uses a backend for frontend architecture and SSR, meaning that the frontend has it's own backend. This URL points the backend of the frontend to the API backend when in the private network. |
| PUBLIC_GRAFANA_FARO_COLLECTOR_URL | Optional | Frontend | All | None | For frontend observability, if you plan to use Grafana Faro, set the collector URL generated from Grafana settings page |
| PUBLIC_GRAFANA_FARO_SAMPLING_RATE | Optional | Frontend | All | 1 |
Set the sampling rate for Grafana Faro, decimal value between 0 and 1 |
| IMAGE_STORAGE_PATH | Conditional | Backend | All | None | If STORAGE_MODE is FILESYSTEM, then set the path in the system to store the uploads |
| JWT_ACCESS_TOKEN_EXPIRY_DURATION_SECS | Optional | Backend | All | 300 |
Sets the lifetime (time-to-live) of a JSON Web Token (JWT) in seconds before it becomes invalid. Once this duration has elapsed after a token is issued, the server will reject it, requiring the user to either log in again or use a refresh token to obtain a new access token |
| JWT_REFRESH_TOKEN_EXPIRY_DURATION_SECS | Optional | Backend | All | 3600 |
Set the lifetime (time-to-live) of a JSON Web Token (JWT) refresh token in seconds. Because refresh tokens are meant to keep a user logged in across sessions or app restarts, this duration is typically much longer than an JWT_ACCESS_TOKEN_EXPIRY_DURATION_SECS lifespan |
| DEFAULT_STORAGE_GRACE_PERCENTAGE | Optional | Backend | All | 5 |
Set the default buffet limit (in percentage) that lets users to upload files that go slightly over the storage quota, as long as the extra usage stays under this limit |
| MIN_LOGGING_LEVEL | Optional | Backend | All | Warning |
Define the minimum logging level by setting one of the values: Verbose, Debug, Info, Warning, Error, or Fatal |
| PUBLIC_FT_DISABLE_SEND_EMAIL_VERIFICATION | Optional | Backend and Frontend | All | false |
Feature toggle to disable sending of email verification when a new user signs up |
| PUBLIC_FT_DISABLE_USER_SIGN_UP | Optional | Backend and Frontend | All | false |
Feature toggle to disable any new user sign ups |
| PUBLIC_FT_DISABLE_CONTACT_REQUEST | Optional | Backend and Frontend | All | false |
Feature toggle to disable contact request for instaNDT service/subscription |
| PUBLIC_FT_ENABLE_AZURE_SSO | Optional | Backend and Frontend | All | false |
Feature toggle to enable Azure SSO login button for the users |
| PUBLIC_AZURE_SSO_AUTHORITY | Conditional | Backend and Frontend | All | None | If PUBLIC_FT_ENABLE_AZURE_SSO is set to true, then set the endpoint address (ex: https://login.microsoftonline.com/ |
| PUBLIC_AZURE_SSO_TENANT | Conditional | Backend and Frontend | All | None | If PUBLIC_FT_ENABLE_AZURE_SSO is set to true, then set Microsoft Entra tenant ID (Directory ID), which is a unique 36-character GUID including hyphens (e.g., 12345678-abcd-1234-abcd-123456789abc), used to configure the SSO in Microsoft Entra ID |
| PUBLIC_AZURE_SSO_CLIENT_ID | Conditional | Backend and Frontend | All | None | If PUBLIC_FT_ENABLE_AZURE_SSO is set to true, then set the client ID (also known as application ID) as per the configuration in Microsoft Entra ID |
| PUBLIC_AZURE_SSO_REDIRECT_URI | Conditional | Backend and Frontend | All | None | If PUBLIC_FT_ENABLE_AZURE_SSO is set to true, then set the reply URL, which is the exact security endpoint where Microsoft Entra ID sends the authentication token after a user successfully signs in |
| OTEL_AUTH | Optional | Backend and Frontend | All | None | If the remote OpenTelemetry collector requires authentication, set the authorization token for the OTLP request header (ex: Bearer <Token>) |
| CONTACT_REQUEST_EMAIL | Conditional | Backend | All | None | If PUBLIC_FT_DISABLE_CONTACT_REQUEST is set to false, then define a valid email address as a contact point for instaNDT service/subscription requests |
| PUBLIC_APP_ENVIRONMENT | Optional | Backend and Frontend | All | None | Set this to the current deployment environment, which will be used to label the deployment environment tag for observability |
| AZURE_POSTGRESQL_CONNECTIONSTRING | Required | Backend | Azure | None | Connection string for the app to connect to the database in the format of Server=<db-instance-hostname-or-ip>;Database=<db-name>;Port=<db-port>;Userid=<db-user>;Password=<db-password> |
| AZURE_STORAGE_ACCOUNT_NAME | Conditional | Backend | Azure | None | If STORAGE_MODE is set to azure, then define the globally unique name of your Azure Storage account |
| AZURE_CONTAINER_NAME | Conditional | Backend | Azure | None | If STORAGE_MODE is set to azure, then set the specific bucket or folder partition inside the Azure Storage Account to where the files are uplaode |
| DEFAULT_USER_LIMIT | Optional | Backend | All | 5 |
Set the default system-wide quota for total number of users that can be created |