Configuration

Every environment variable the application reads.

All production configuration is environment variables, read when the application starts. Values in .env are passed through by the compose file.

Required

Variable Meaning
DATABASE_URL ecto://USER:PASSWORD@HOST/DATABASE.
SECRET_KEY_BASE At least 64 random bytes, base64. Signs sessions and tokens.
CLOAK_KEY 32 random bytes, base64. Encrypts secrets at rest. Rotating it requires re-entering every stored secret.
PHX_HOST The public host name used in links and emails.

Web

Variable Default Meaning
PHX_SCHEME https Scheme of public URLs.
PHX_URL_PORT 443 for https, else PORT Port in public URLs, when the proxy uses an unusual one.
PORT 4000 Port the application listens on.
POOL_SIZE 10 Database connections per node (the main pool).
ECTO_IPV6 unset Set to true when the database is reached over IPv6.
DNS_CLUSTER_QUERY unset A DNS name whose A records are the other nodes, for clustering; see Clustering.
CSP unset (enforced) Pages are sent a Content-Security-Policy that lets them load and talk to the application, your attachment storage and nothing else. report sends it without enforcing it, so the browser console shows what would be blocked; off sends none. See Troubleshooting.
RELEASE_COOKIE unset The Erlang cookie shared by clustered nodes; required with DNS_CLUSTER_QUERY.

Email

Variable Default Meaning
SMTP_HOST unset Switches the mailer to SMTP. Without it, production sends nothing.
SMTP_PORT 587
SMTP_USERNAME, SMTP_PASSWORD unset Authentication; unset means none.
SMTP_TLS if_available never, if_available or always.
SMTP_TLS_VERIFY true Verifies the mail server's certificate against the system CA store (the image ships ca-certificates). Set to false only for a server with a self-signed certificate.
MAIL_FROM no-reply@albaticket.com The sender of every email: an address, sent under the name "Alba Ticket", or Your Name <address> to choose the name as well. It must be a sender your mail provider delivers for.

Receiving mail is set up in the application rather than the environment, under Administration, Email (see Email in the user guide, and Incoming email here for a mail server or mailbox of your own). With a Postmark account, create a server with an inbound stream, switch on its "include raw email content" option so the stored copy is the message as received, and point its webhook at https://user:password@your-host/webhooks/mail/postmark, the user and password being the ones typed on the Email page; give the page the address the stream receives at (an MX record for a domain of yours, or the address Postmark assigns the stream) and switch it on.

Every message is sent as plain text with an HTML part beside it, in the application's light theme; the HTML loads no image, font, stylesheet or script from anywhere, so opening an email tells nobody anything. Login links and invitations are sent by background jobs, so a slow or unreachable mail server never delays or fails the request that asked for them; a failed delivery is retried by the job queue and shows up in the Oban tables rather than as an error to the person.

Variable Default Meaning
TYPESENSE_URL unset The Typesense server, for example http://typesense:8108. Until it is set, searches match exact ticket keys only.
TYPESENSE_API_KEY unset The key the server was started with (--api-key).

The application creates its collections per installation (tickets and their comments, knowledge base pages, time entries) and fills them as records change. After pointing at a new or emptied Typesense, run Rebuild index on the Search page under Administration, which rebuilds all of them.

Attachment storage

These create the default storage location on first start; administrators can change it afterwards.

Variable Default Meaning
STORAGE_ENDPOINT unset The S3 endpoint the application uses, for example https://s3.eu-west-1.amazonaws.com or http://rustfs:9000.
STORAGE_BUCKET
STORAGE_ACCESS_KEY_ID, STORAGE_SECRET_ACCESS_KEY
STORAGE_REGION us-east-1
STORAGE_FORCE_PATH_STYLE false true for RustFS, MinIO and most self-hosted stores.
STORAGE_PUBLIC_BASE_URL unset The address browsers use when it differs from the endpoint.
STORAGE_PATH_PREFIX, STORAGE_NAME unset, Default
MAX_UPLOAD_BYTES 100 MiB Largest attachment accepted.

Behaviour

Which modules and features an installation uses is not configuration: it is chosen in the application, under Administration, Modules and features, asked once at first-run setup and changeable at any time (see Modules and features). No environment variable switches a module, the REST API or the MCP server on or off.

Variable Default Meaning
REGISTRATION_MODE invite_only open, invite_only or sso_only. The setting in Administration takes precedence once changed there.
CHROME_EXECUTABLE /usr/bin/chromium in the image The Chrome or Chromium binary that prints invoices to PDF, when it is not on the PATH under a usual name.
CHROME_NO_SANDBOX true in the image true lets Chromium run without its sandbox, which a container that grants no user namespaces needs. The document printed is the application's own HTML, offline and with scripts disabled, so the sandbox guards nothing there.

Analytics

Off unless you switch it on. It measures the public pages only: the home page as a visitor sees it, the legal pages and the documentation. Nothing is measured for anyone who is logged in, so no project, ticket or person inside the installation is ever sent. Query strings are removed before anything leaves the browser, and no cookies are set.

Variable Default Meaning
PLAUSIBLE_DOMAIN unset The site, as named in Plausible, that page views are reported to. It need not match the host name: Plausible keeps the host name as a dimension of every view.
PLAUSIBLE_ENDPOINT https://plausible.io/api/event The events endpoint of a self-hosted Plausible, or of a proxy in front of it.