Skip to content

Configuration Reference

Telmoni uses environment variables for all configuration. When deployed via Docker Compose or Kubernetes, these variables are passed to the container runtimes via .env files or Secret/ConfigMap resources.

These variables configure the Rust backend service (telmoni serve).

Variable Default Description
PORT 8082 HTTP listen port for the backend server.
APP_URL http://localhost:3000 The public origin of the web console. Used to format invitation links, password reset emails, and OAuth callback URLs.
SERVICE_SECRET Required A cryptographically secure secret shared between the web console and the core server. Used to sign and authenticate internal service calls.
SERVICE_SECRET_NEXT Optional A secondary service secret accepted alongside SERVICE_SECRET. Used for zero-downtime secret rotation.
DATABASE_CA_CERT Optional PEM-encoded certificate authority used to verify TLS connections to managed PostgreSQL instances.
ALLOW_TEST_SESSION false When true, exposes the POST /test/session route for end-to-end testing. Refused at boot in Kubernetes production environments.
DELETION_TAIL_BUDGET_MS 8000 Wall-clock time budget in milliseconds for inline deletion sagas before returning an HTTP 202 Accepted to the caller and handing off the remaining purges to the background sweep task.

These variables configure the web console container (telmoni/web).

Variable Default Description
PORT 3000 HTTP listen port for the Next.js console.
SERVER_URL Required The internal URL of the core backend server (e.g., http://server:8082).
AUTH_SECRET Required A secret key of at least 32 bytes (generate with openssl rand -hex 32) used to seal, encrypt, and decrypt browser session cookies.
AUTH_URL Required The public URL of the application. In production, must begin with https:// (or loopback http://localhost).
NEXT_PUBLIC_APP_URL Required The public origin of the console, exposed to browser clients for client-side routing.
REDIS_URL Required Connection string for Redis (e.g., redis://redis:6379). Used for rate limiting and fast session checks.
REDIS_CA_CERT Optional PEM-encoded CA certificate for validating TLS connections to Redis (rediss://).
COMPANY_NAME Optional Custom organization name displayed in the console footer and notification emails.
SUPPORT_EMAIL Optional Contact address displayed on error pages and system transactional emails.
LEGAL_URL Optional External URL hosting custom Terms of Service and Privacy Policy documents.

Database connection pools (Multi-role architecture)

Section titled “Database connection pools (Multi-role architecture)”

In simple deployments, all database variables can point to the same PostgreSQL connection string. In hardened production environments, each module connects as its own least-privilege PostgreSQL role:

Variable Default Description
AUTH_DATABASE_URL Required PostgreSQL DSN for identity, accounts, organizations, projects, and RBAC tables (role: auth).
NOTIFICATIONS_DATABASE_URL Required PostgreSQL DSN for notification feeds, delivery queues, and webhook subscriptions (role: notifications).
AGENT_DATABASE_URL Optional PostgreSQL DSN for document embeddings, vector chunks, and search indexing (role: agent). Required if the AI agent is enabled.
MIGRATOR_DATABASE_URL Required for migrations PostgreSQL DSN for applying DDL migrations and role hardening (role: migrator or superuser).

Variable Default Description
ALLOW_SIGN_UP false When false, public self-registration is disabled; new users can only join by accepting an email invitation from an existing Organization Admin or Owner.
VERIFY_EMAIL false When true, newly registered users must verify their email address via a confirmation link before accessing the console. Requires SMTP_URL.
DISABLE_LOGIN_FORM false Disables username and password authentication, forcing all users to sign in via OpenID Connect (SSO).
ADMIN_EMAIL Optional Seeds the primary Organization Owner account on the first migration run.
ADMIN_PASSWORD Optional Password for the initial administrator account.

Telmoni supports enterprise Identity Providers (Okta, Keycloak, Microsoft Entra ID, Google Workspace, Authentik) using standard OpenID Connect:

Variable Default Description
OIDC_ISSUER Optional The base discovery URL of your OIDC provider (must serve /.well-known/openid-configuration).
OIDC_CLIENT_ID Optional The registered OAuth2 client identifier.
OIDC_CLIENT_SECRET Optional The registered OAuth2 client secret.
OIDC_REDIRECT_URI http://localhost:3000/auth/callback The callback URL registered with your identity provider.
OIDC_NAME "SSO" The label displayed on the login button (e.g., "Continue with Okta").
OIDC_ALLOW_SIGN_UP true Allows first-time OIDC sign-ins to automatically provision a user account.
OIDC_ALLOW_INSECURE_EMAIL_LOOKUP false When true, links an OIDC identity to an existing account if the email matches, even if the account was created with a password.

Variable Default Description
SMTP_URL Optional SMTP connection URI (e.g., smtp://user:pass@smtp.mailgun.org:587). If unset, emails are written to standard output logs instead of being sent.
MAIL_FROM Telmoni <no-reply@localhost> RFC 5322 From: address for invitations, verifications, and alert notifications.
SUPPORT_EMAIL Optional Address referenced when recipients require administrative assistance.

Variable Default Description
CONNECTOR_KEK Required for connectors The Key Encryption Key used to seal integration credentials and secrets at rest. Format: local:<64-hex-characters> or a Google Cloud KMS key resource identifier.
SLACK_CLIENT_ID Optional Client ID for the Telmoni Slack application.
SLACK_CLIENT_SECRET Optional Client Secret for the Slack application.
SLACK_SIGNING_SECRET Optional Secret used to verify HMAC signatures of inbound Slack event webhooks.
DISCORD_CLIENT_ID Optional Application ID for the Telmoni Discord bot.
DISCORD_CLIENT_SECRET Optional Client Secret for Discord OAuth handshakes.

The embedded AI assistant uses 768-dimensional embeddings to query project metadata, audit histories, and documentation.

Variable Default Description
AGENT_MODEL_PROVIDER Optional Model provider protocol: anthropic or openai. (OpenAI protocol supports OpenAI, Gemini compatible endpoints, Ollama, and vLLM).
AGENT_MODEL_URL Optional Base API URL (e.g., http://ollama:11434/v1 or https://api.openai.com/v1).
AGENT_MODEL claude-sonnet-5 (Anthropic) The LLM model identifier (e.g., claude-3-5-sonnet-latest, gpt-4o, llama3.2).
AGENT_MODEL_API_KEY Optional Bearer API token for hosted model providers.
EMBEDDINGS_URL http://ollama:11434/v1 URL for the OpenAI-compatible vector embedding endpoint.
EMBEDDINGS_MODEL nomic-embed-text Embedding model identifier. Vector columns are fixed at 768 dimensions.
EMBEDDINGS_API_KEY Optional API token for the embeddings provider.
DOCS_CORPUS_URL https://docs.telmoni.com/llms-full.txt Remote documentation corpus ingested for the agent’s contextual knowledge base. Set to off to disable documentation indexing.