Skip to main content

Configuration

Orbit is configured entirely through environment variables, validated on startup — the process refuses to start with a clear error if a required variable is missing or malformed.

VariableRequiredDefaultNotes
OIDC_ISSUER_URLyes—OIDC provider issuer URL (discovery document at <issuer>/.well-known/openid-configuration)
OIDC_CLIENT_IDyes—OIDC client ID
OIDC_CLIENT_SECRETyes—OIDC client secret
OIDC_REDIRECT_URIyes—Must exactly match what's registered with the provider; always <origin>/auth/callback
ENCRYPTION_KEYyes—32-byte key, hex (64 chars) or base64, for encrypting stored profile secrets
DATABASE_URLnounset (uses SQLite)PostgreSQL connection string; when set, Postgres is used instead of SQLite
SQLITE_PATHno./data/app.dbSQLite file path, used only when DATABASE_URL is unset
OIDC_SCOPESnoopenid profile emailSpace-separated OAuth2 scopes requested at authorization. openid must always be present. Only change this if your provider needs different scopes — see OIDC setup.
PORTno3000HTTP port the server listens on
SESSION_TTLno28800 (8h)Session cookie sliding expiry, in seconds
WEB_DISTno../web/dist relative to the server packagePath to the built frontend to serve as static files; the Docker image sets this to /app/web/dist
OIDC_ALLOW_INSECURE_HTTPnofalseDevelopment only. Set to true to permit an http:// OIDC issuer, so the app can run against a local mock IdP. Never enable it in production — the authorization code and tokens would travel in clear text.
AWS_KEYLESS_ENABLEDnofalseAllows connection profiles with authMode: 'aws-iam', which authenticate as the server's own AWS identity instead of a stored access key. Must be set to exactly true to enable — any other value (including unset, empty, or 1) is treated as off. See Keyless AWS IAM — off by default because every signed-in user of the deployment would share that identity.

See also​

  • OIDC setup for worked provider examples and the redirect URI rule.
  • Security for what ENCRYPTION_KEY protects and the consequences of rotating or losing it.
  • Kubernetes for how the Helm chart maps these to values.yaml.