Skip to main content

Environment Variables

All environment variables of the EUDIPLO backend, generated from its validation schema. The backend refuses to start when a value is invalid or a required variable is missing. KMS providers and the registrar are configured in JSON files instead (KMS config, Registrar); the variables of the eudiplo CLI are listed in the CLI guide.

Authentication​

KeyTypeAllowed valuesNotes
OIDCstring-Enable OIDC mode [optional]
OIDC_INTERNAL_ISSUER_URLstring-Internal issuer URL in OIDC mode [optional] [when OIDC is set → then default=undefined]
OIDC_CLIENT_IDany-Client ID for OIDC [optional] [when OIDC is set → then required]
OIDC_CLIENT_SECRETany-Client secret for OIDC [optional] [when OIDC is set → then required]
OIDC_SUBany-Claim to use as subject [optional] [when OIDC is set → then default="tenant_id"]
OIDC_ALGORITHMany-Expected JWT alg [optional] [when OIDC is set → then default="RS256"]
MASTER_SECRETany-Master secret for JWT signing and encryption key derivation - required, minimum 32 characters [optional] [when OIDC is set → otherwise required]
JWT_ISSUERany-Local JWT issuer [optional] [when OIDC is set → otherwise default="eudiplo-service"]
JWT_EXPIRES_INany-Local JWT expiration [optional] [when OIDC is set → otherwise default="24h"]
AUTH_CLIENT_SECRETany-Client secret (local auth). In OIDC mode, optional bootstrap secret used to create/update a Keycloak admin/root client when AUTH_CLIENT_ID is also set [optional] [when OIDC is set → otherwise required]
AUTH_CLIENT_IDany-Client ID (local auth). In OIDC mode, optional bootstrap client ID used to create/update a Keycloak admin/root client when AUTH_CLIENT_SECRET is also set [optional] [when OIDC is set → otherwise required]
OIDC_UI_CLIENT_IDany-Public client ID for the Angular UI in OIDC mode. Used to register a public Keycloak client for Authorization Code + PKCE login. [optional] [when OIDC is set → then default="eudiplo-ui"]

Configuration​

KeyTypeAllowed valuesNotes
CONFIG_IMPORT_MODEstringdisabled, create, upsert, replaceStartup configuration reconciliation mode. [optional] (default: disabled)
CONFIG_FOLDERstring-Path to config import folder [optional] (default: /path/to/config/folder)
CONFIG_VARIABLE_STRICTalternatives-Strict mode for config import. [optional] (default: skip)

Cryptography​

KeyTypeAllowed valuesNotes
CRYPTO_ALGstringES256The signing algorithm to use [optional] (default: ES256)
CRYPTO_TOLERANCEnumber-Clock tolerance in seconds for JWT verification [optional] (default: 5)

Database​

KeyTypeAllowed valuesNotes
DB_TYPEstringsqlite, postgresDatabase type [optional] (default: sqlite)
DB_HOSTstring-Database host [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required]
DB_PORTnumber-Database port [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required]
DB_USERNAMEstring-Database username [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required]
DB_PASSWORDstring-Database password [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required]
DB_DATABASEstring-Database name [optional] [when DB_TYPE is {"override":true} | "sqlite" → otherwise required]
DB_SSLboolean-Enable SSL/TLS for PostgreSQL database connections [optional] (default: false)
DB_SSL_REJECT_UNAUTHORIZEDboolean-Reject PostgreSQL TLS certificates that cannot be validated against trusted CAs [optional] (default: true)
DB_SSL_CA_PATHstring-Path to CA certificate file used to validate PostgreSQL TLS certificates [optional]
DB_SSL_CERT_PATHstring-Path to client certificate file for PostgreSQL TLS [optional]
DB_SSL_KEY_PATHstring-Path to client private key file for PostgreSQL TLS [optional]
DB_SSL_KEY_PASSPHRASEstring-Passphrase for encrypted DB_SSL_KEY_PATH private key [optional]
DB_SYNCHRONIZEboolean-Enable TypeORM schema synchronization. Intended for development only; fresh installations are created by migrations. [optional] (default: false)
DB_MIGRATIONS_RUNboolean-Run pending database migrations automatically on startup [optional] (default: true)

Encryption​

KeyTypeAllowed valuesNotes
ENCRYPTION_KEY_SOURCEstringenv, vault, aws, azureSource for encryption key: env (dev), vault/aws/azure (prod - key only in RAM) [optional] (default: env)
VAULT_ADDRstring-URL of the HashiCorp Vault server, e.g. http://vault:8200. Required when ENCRYPTION_KEY_SOURCE=vault [optional]
VAULT_TOKENstring-Token for the HashiCorp Vault server. Required when ENCRYPTION_KEY_SOURCE=vault [optional] 🔒
VAULT_ENCRYPTION_KEY_PATHstring-Path to encryption key in Vault KV secrets engine [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "vault" → then default="secret/data/eudiplo/encryption-key"]
AWS_REGIONstring-AWS region, e.g. eu-central-1. Required when ENCRYPTION_KEY_SOURCE=aws [optional]
AWS_ENCRYPTION_SECRET_NAMEstring-Name of the encryption key secret in AWS Secrets Manager [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "aws" → then required]
AWS_ENCRYPTION_SECRET_KEYstring-JSON key within the AWS secret (if secret is JSON) [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "aws" → then default="key"]
AZURE_KEYVAULT_URLstring-Azure Key Vault URL (e.g., https://myvault.vault.azure.net) [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "azure" → then required]
AZURE_ENCRYPTION_SECRET_NAMEstring-Name of the encryption key secret in Azure Key Vault [optional] [when ENCRYPTION_KEY_SOURCE is {"override":true} | "azure" → then required]

General​

KeyTypeAllowed valuesNotes
FOLDERstring-Root working folder for temp files [optional] (default: ../../tmp)
PUBLIC_URLstring-The public URL of the issuer [optional] (default: http://localhost:3000)
INTERNAL_URLstring-Internal URL used by the backend to resolve its own authorization-server JWKS [optional] (default: http://127.0.0.1:3000)
PORTstring-Port the HTTP(S) server listens on (default: 3000) [optional]
CORS_ORIGINSstring-Comma-separated list of origins allowed to call the management API (/api/*) from a browser, e.g. https://console.example.com. Protocol and public endpoints stay open to all origins. If unset, all origins are allowed everywhere. [optional]

Issuer​

KeyTypeAllowed valuesNotes
ISSUER_MULTI_CONSUMPTIONboolean-Enable or disable multi-consumption for the issuer [optional] (default: false)

Logging​

KeyTypeAllowed valuesNotes
LOG_LEVELstringtrace, debug, info, warn, error, fatalApplication log level [optional] (default: debug)
LOG_ENABLE_HTTP_LOGGERboolean-Enable HTTP request logging [optional] (default: false)
LOG_HTTP_RESPONSE_BODYboolean-Capture and log HTTP response bodies (buffered up to LOG_HTTP_RESPONSE_BODY_MAX_LENGTH bytes). Disabled by default because response bodies may contain access tokens, credentials, or other sensitive data. [optional] (default: false)
LOG_HTTP_RESPONSE_BODY_MAX_LENGTHnumber-Maximum number of bytes to capture for HTTP response bodies. Set to 0 to disable truncation. [optional] (default: 4096)
LOG_REDACT_SENSITIVE_DATAboolean-Redact sensitive request/response fields from logs. Disable only for debugging. [optional] (default: true)
LOG_OID4VP_DECRYPTED_RESPONSEboolean-Log decrypted OID4VP authorization responses. Disable by default because responses may contain personal data and credentials. [optional] (default: false)
LOG_ENABLE_SESSION_LOGGERboolean-Enable session flow logging [optional] (default: false)
LOG_SESSION_STOREstringoff, errors, all, verboseControls whether session log entries are persisted to the database. 'off' disables storage, 'errors' stores only warn/error entries, 'all' stores everything, 'verbose' stores everything including full request/response bodies and error stacks. [optional] (default: off)
LOG_TO_FILEboolean-Enable logging to file in addition to console [optional] (default: false)
LOG_FILE_PATHstring-File path for log output when LOG_TO_FILE is enabled [optional] (default: ./logs/session.log)
AUDIT_LOG_RETENTION_DAYSnumber-Delete tenant activity audit log entries older than N days. Set to 0 to disable time-based pruning. [optional] (default: 0)
OTEL_SDK_DISABLEDboolean-Disable OpenTelemetry SDK (and OTel log forwarding) [optional] (default: false)
AUDIT_LOG_MAX_ENTRIES_PER_TENANTnumber-Keep only the newest N tenant activity audit log entries per tenant. Set to 0 to disable count-based pruning. [optional] (default: 0)

Observability​

KeyTypeAllowed valuesNotes
GRAFANA_URLstring-Base URL of the Grafana instance for deep linking from the dashboard UI [optional]
GRAFANA_DATASOURCE_TEMPO_UIDstring-UID of the Tempo data source in Grafana [optional] (default: tempo)
GRAFANA_DATASOURCE_LOKI_UIDstring-UID of the Loki data source in Grafana [optional] (default: loki)
OTEL_EXPORTER_OTLP_ENDPOINTstring-Base URL of the OTLP/HTTP endpoint (e.g. the OpenTelemetry Collector) that receives traces, metrics and logs (default: http://localhost:4318) [optional]
OTEL_SERVICE_NAMEstring-Service name attached to exported traces, metrics and logs (default: eudiplo-backend) [optional]

Session​

KeyTypeAllowed valuesNotes
SESSION_TIDY_UP_INTERVALnumber-Interval in seconds to run session tidy up [optional] (default: 3600)
SESSION_TTLnumber-Default time to live for sessions in seconds. Can be overridden per tenant. [optional] (default: 86400)
SESSION_CLEANUP_MODEstringfull, anonymizeDefault cleanup mode when sessions expire. 'full' deletes the entire session, 'anonymize' keeps metadata but removes personal data. Can be overridden per tenant. [optional] (default: full)

Skip Flags​

Every switch that turns off a check of the normal flow is named SKIP_<CHECK> and defaults to false. The startup log lists active skip flags as warnings. Use them only for development and interoperability tests.

KeyTypeAllowed valuesNotes
SKIP_OVERASKING_CHECKboolean-Skip verifying that the registration certificate authorizes every credential in the DCQL query (overasking prevention). Intended for development and interoperability testing only. [optional] (default: false)

Status​

KeyTypeAllowed valuesNotes
STATUS_CAPACITYnumber-The default capacity of the status list. Can be overridden per tenant. [optional] (default: 10000)
STATUS_BITSnumber1, 2, 4, 8The default number of bits used per status entry. Can be overridden per tenant. [optional] (default: 1)
STATUS_TTLnumber-The default TTL in seconds for status list JWTs. Verifiers can cache the JWT until expiration. Can be overridden per tenant. [optional] (default: 3600)
STATUS_IMMEDIATE_UPDATEboolean-If true, regenerate status list JWT immediately on every status change. If false (default), use lazy regeneration when TTL expires. Can be overridden per tenant. [optional] (default: false)
STATUS_ENABLE_AGGREGATIONboolean-If true (default), include aggregation_uri in status list JWTs. This allows relying parties to pre-fetch all status lists for offline validation per RFC draft-ietf-oauth-status-list Section 9. Can be overridden per tenant. [optional] (default: true)

Storage​

KeyTypeAllowed valuesNotes
STORAGE_DRIVERstringlocal, s3The storage driver to use [optional] (default: local)
LOCAL_STORAGE_DIRstring-The directory to store files in when using local storage [optional] [when STORAGE_DRIVER is {"override":true} | "local" → then default=undefined]
S3_REGIONstring-The AWS region for the S3 bucket [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then required]
S3_BUCKETstring-The name of the S3 bucket [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then required]
S3_ACCESS_KEY_IDstring-The access key ID for the S3 bucket. Optional when using IRSA or instance profile credentials. [optional] [when STORAGE_DRIVER is {"override":true} | "s3"]
S3_SECRET_ACCESS_KEYstring-The secret access key for the S3 bucket. Optional when using IRSA or instance profile credentials. [optional] [when STORAGE_DRIVER is {"override":true} | "s3"]
S3_ENDPOINTstring-The endpoint URL for the S3 service (for S3-compatible services) [optional] [when STORAGE_DRIVER is {"override":true} | "s3"]
S3_FORCE_PATH_STYLEboolean-Whether to force path-style URLs for S3 [optional] [when STORAGE_DRIVER is {"override":true} | "s3" → then default=false]

TLS​

KeyTypeAllowed valuesNotes
TLS_ENABLEDboolean-Enable built-in TLS termination (serve HTTPS directly). Requires TLS_CERT_PATH and TLS_KEY_PATH; startup fails if they are unset or unreadable [optional] (default: false)
TLS_CERT_PATHstring-Path to the TLS certificate file (PEM format) [optional]
TLS_KEY_PATHstring-Path to the TLS private key file (PEM format) [optional]
TLS_CA_PATHstring-Path to the intermediate CA certificate(s) of the server certificate (PEM format). They are sent to clients after the certificate in TLS_CERT_PATH so clients can build the chain. Not needed if TLS_CERT_PATH already contains the full chain (e.g. Let's Encrypt fullchain.pem). Does not enable client certificate authentication (mTLS) [optional]
TLS_KEY_PASSPHRASEstring-Passphrase for an encrypted TLS_KEY_PATH private key [optional] 🔒

Verifier​

KeyTypeAllowed valuesNotes
VP_REMOVE_TAboolean-If true, strip trusted_authorities from the DCQL query sent to wallets in OID4VP authorization requests. Use this as an escape hatch for wallets that do not yet handle trusted_authorities correctly. [optional] (default: false)

Webhook​

KeyTypeAllowed valuesNotes
OUTBOUND_URL_ALLOW_HTTPboolean-Allow HTTP (non-TLS) for outbound calls (webhooks, attribute providers, issuer and schema metadata imports, trust lists, status lists, federation entities, external authorization servers and the upstream provider of a chained authorization server). CRLs may always use HTTP. Enable it for local development against HTTP endpoints. [optional] (default: false)
OUTBOUND_URL_ALLOW_PRIVATE_NETWORKboolean-Allow outbound calls (webhooks, attribute providers, metadata imports, trust lists, status lists, federation entities, CRLs, external authorization servers and the upstream provider of a chained authorization server) to private, loopback, or link-local IP ranges, e.g. for services inside the same cluster or for local development. The address actually connected to is checked as well (DNS rebinding protection). EUDIPLO's own PUBLIC_URL and INTERNAL_URL are always reachable for trust lists, status lists and authorization server keys. [optional] (default: false)
OUTBOUND_URL_ALLOWED_HOSTSstring-Comma-separated hostname allowlist for outbound calls (webhooks, attribute providers, metadata imports, trust lists, status lists, federation entities, CRLs, external and upstream authorization servers; supports exact host and subdomains). When set, other hosts are rejected. Listed hosts still need HTTPS and public addresses unless OUTBOUND_URL_ALLOW_HTTP or OUTBOUND_URL_ALLOW_PRIVATE_NETWORK is set. [optional]