Skip to content

Environment variables ​

Every variable the code reads is listed. See Configuration for how the pieces fit.

Required ​

Set these in .env before the first start.

VariableUsed byDefaultMeaning
ENCRYPTION_KEYcompose64 hex characters (openssl rand -hex 32). Encrypts two-factor secrets, stored S3 credentials, SMTP passwords and plugin secrets. Keep it permanently; replacing it makes them unreadable.
POSTGRES_PASSWORDcomposePassword of the bundled PostgreSQL database. Use URL-safe letters and digits: it is placed inside DATABASE_URL.
WEB_ORIGINcomposehttp://localhost:3000The exact origin browsers use for the panel. Used for CORS, the Origin check on cookie requests, WebSocket checks and passkeys.

Deployment ​

Set in .env when your setup needs them.

VariableUsed byDefaultMeaning
API_BINDcompose127.0.0.1Host interface the API port (4000) is published on.
API_INTERNAL_URLcomposehttp://api:4000How the panel's server reaches the API to read the appearance settings (name, colours, logo) before a page is sent. The browser uses NEXT_PUBLIC_API_URL. Compose sets this for you; outside Compose it falls back to NEXT_PUBLIC_API_URL.
APP_VERSIONcompose0.9.1.2The version the panel reports; set by the release you checked out.
GITHUB_REPOSITORYcomposekavaliersdelikt/fledgeowner/name of the GitHub repository the update checker reads releases from.
GITHUB_TOKENcomposeOptional fine-grained token with read-only Contents/Metadata access, for private release checks.
NEXT_PUBLIC_API_URLcomposeBrowser-reachable API origin. Empty means the panel's host on port 4000. Compiled into the panel image: rebuild after changing.
NEXT_PUBLIC_GITHUB_REPOSITORYcomposeRepository the panel links to for releases (build-time).
TRUST_PROXYapi1Behind a reverse proxy: the number of proxy hops (usually 1), or a comma-separated list of proxy addresses or ranges. true trusts every hop. Unset when the API is exposed directly.
WEB_BINDcompose127.0.0.1Host interface the panel port (3000) is published on.

Optional seeds ​

These only seed a form in the panel before it is first saved there; afterwards the database wins.

VariableUsed byDefaultMeaning
ADMIN_IP_ALLOW_DISABLEapitrueBreak-glass: set true to ignore the administrator network allow-list if you locked yourself out.
ALLOWED_IMAGE_PREFIXESapiitzg/minecraft-server:,itzg/minecraft-bedrock-server:,ghcr.io/lloesche/valheim-server:,node:,python:,oven/bun:,golang:,eclipse-temurin:,php:,ruby:,mcr.microsoft.com/dotnet/Comma-separated Docker image prefixes templates may use. Seeds the setting in the panel.
BRAND_NAMEapiMy Game HostingThe panel's name before an administrator has saved anything under Settings, Appearance. Afterwards the saved name wins.
BRANDING_DISABLEDapitrueBreak-glass: set true to show the built-in Fledge look to everyone and refuse changes under Settings, Appearance, for example after a theme made the panel hard to use. Remove it and restart to change the appearance again. See Recovering from a bad theme.
PLUGIN_REGISTRY_URLapihttps://raw.githubusercontent.com/kavaliersdelikt/fledge/main/plugins/registry/index.jsonHTTPS address of the plugin registry index. Empty turns the registry off; bundled plugins always work.
S3_ACCESS_KEYapiSeeds the object storage form (also used by the bundled SeaweedFS service).
S3_BUCKETapiSeeds the object storage form before the first save.
S3_ENDPOINTapiPath-style S3 endpoint. Must be reachable from the API, every node and browsers.
S3_REGIONapius-east-1Seeds the object storage form.
S3_SECRET_KEYapiSeeds the object storage form (also used by the bundled SeaweedFS service).
SMTP_FROMapiFledge <fledge@example.com>Sender, admin@example.com or Fledge <admin@example.com>.
SMTP_HOSTapiSMTP server for invitations, password reset and email notifications.
SMTP_PASSWORDapiSMTP password (stored encrypted once saved in the panel).
SMTP_PORTapi587SMTP port.
SMTP_SECURITYapistarttlsnone, starttls or tls.
SMTP_USERapiSMTP username.
WEBAUTHN_ORIGINSapihttps://panel.example.comComma-separated extra origins allowed for passkeys.
WEBAUTHN_RP_IDapipanel.example.comPasskey relying-party id. Defaults to the host of WEB_ORIGIN; set only for unusual setups.

Set by Compose or the image ​

Normally not edited. Listed for people running the API outside Compose.

VariableUsed byDefaultMeaning
BUNDLED_PLUGINS_DIRapiWhere the bundled plugins are read from; defaults to the copy inside the image.
DATABASE_URLapiPostgreSQL connection string. Compose builds it from POSTGRES_PASSWORD.
HOSTapi0.0.0.0Interface the API listens on inside its container.
NODE_ENVapiproduction makes cookies Secure; set by the Compose file.
PLUGIN_HOST_URLapiAddress of the plugin host (http://plugins:4020); set by Compose. Empty disables plugins.
PLUGIN_TOKEN_FILEplugin-host/run/fledge-plugins/tokenShared bearer token file between the API and the plugin host.
PORTapi4000API listen port (plugin host: 4020).
TRANSFER_DIRapi/var/lib/fledge/transfersSpool directory for file transfers when object storage is off.
UPDATE_TOKEN_FILEapi/run/fledge-updater/tokenShared token file between the API and the updater.
UPDATER_URLapiAddress of the updater service; set by Compose.

Node agent ​

Environment of the fledge-agent service on a node (the connector writes them into the unit).

VariableUsed byDefaultMeaning
ALLOW_INSECURE_HTTPagenttrue allows an HTTP panel URL; local evaluation only.
API_URLagentThe panel's API address.
CREDENTIAL_FILEagent/var/lib/fledge/agent.credentialWhere the node credential is stored (mode 0600).
DATA_ROOTagent/var/lib/fledge/serversWhere server data lives.
ENROLLMENT_TOKENagentOne-time token; cleared from the process after reading.
NODE_IDagentThe node's UUID.
SFTP_HOST_KEYagentPath of the SFTP host key. Defaults to sftp_host_key beside the credential file.
VM_QEMU_USERagentlibvirt-qemuQEMU account granted access to managed VM storage.
VM_UEFI_CODEagent/usr/share/OVMF/OVMF_CODE_4M.fdUEFI firmware code image.
VM_UEFI_SECURE_CODEagent/usr/share/OVMF/OVMF_CODE_4M.ms.fdSecure Boot firmware code image.
VM_UEFI_SECURE_VARSagent/usr/share/OVMF/OVMF_VARS_4M.ms.fdUEFI variable template with enrolled trusted keys for Secure Boot profiles. An empty variable store does not enforce Secure Boot.
VM_UEFI_VARSagent/usr/share/OVMF/OVMF_VARS_4M.fdTemplate for per-VM UEFI variables.

Test switches ​

Never set these in production. They exist for the test suites.

VariableUsed byDefaultMeaning
FLEDGE_DOCKER_TEST_IMAGEtestAgent tests only: an image already on the local engine for the live stdin test.
FLEDGE_TEST_ALLOW_LOCAL_FETCHtestTests only: lets notification webhooks and plugin registry fetches use local HTTP addresses. Never set in production.
FLEDGE_TEST_CAPTCHA_URLtestTests only: address the sign-up bot check is verified against, so tests need no real Turnstile or hCaptcha account. Never set in production.
INSTALL_PLUGIN_WAIT_ATTEMPTSscriptTests only: how many times install.sh checks the plugin host.
PLUGIN_HOST_NO_LISTENtestTests only: import the plugin host without listening.
PLUGIN_HOST_UNSAFE_TEST_ALLOW_LOCALtestTests only: lets the plugin host reach local HTTP. Never set in production.
PLUGIN_HOST_UNSAFE_TEST_HOST_MAPtestTests only: map host names to local test servers.
RATE_LIMIT_AUTH_WRITEtestTests only: raises the authentication write rate limit.
SLOW_SWEEP_MStestTests only: interval of the slower sweep (default 60000).
SWEEP_INTERVAL_MStestTests only: how often the API's background sweep runs (default 15000).
UPDATE_POLL_SECONDSscriptTests only: polling interval of the update scripts.

Released under the AGPL-3.0-only license.