Configuration
Orbit is configured entirely through environment variables, validated on startup — the process refuses to start with a clear error if a required variable is missing or malformed.
| Variable | Required | Default | Notes |
|---|---|---|---|
OIDC_ISSUER_URL | yes | — | OIDC provider issuer URL (discovery document at <issuer>/.well-known/openid-configuration) |
OIDC_CLIENT_ID | yes | — | OIDC client ID |
OIDC_CLIENT_SECRET | yes | — | OIDC client secret |
OIDC_REDIRECT_URI | yes | — | Must exactly match what's registered with the provider; always <origin>/auth/callback |
ENCRYPTION_KEY | yes | — | 32-byte key, hex (64 chars) or base64, for encrypting stored profile secrets |
DATABASE_URL | no | unset (uses SQLite) | PostgreSQL connection string; when set, Postgres is used instead of SQLite |
SQLITE_PATH | no | ./data/app.db | SQLite file path, used only when DATABASE_URL is unset |
OIDC_SCOPES | no | openid profile email | Space-separated OAuth2 scopes requested at authorization. openid must always be present. Only change this if your provider needs different scopes — see OIDC setup. |
PORT | no | 3000 | HTTP port the server listens on |
SESSION_TTL | no | 28800 (8h) | Session cookie sliding expiry, in seconds |
WEB_DIST | no | ../web/dist relative to the server package | Path to the built frontend to serve as static files; the Docker image sets this to /app/web/dist |
OIDC_ALLOW_INSECURE_HTTP | no | false | Development only. Set to true to permit an http:// OIDC issuer, so the app can run against a local mock IdP. Never enable it in production — the authorization code and tokens would travel in clear text. |
AWS_KEYLESS_ENABLED | no | false | Allows connection profiles with authMode: 'aws-iam', which authenticate as the server's own AWS identity instead of a stored access key. Must be set to exactly true to enable — any other value (including unset, empty, or 1) is treated as off. See Keyless AWS IAM — off by default because every signed-in user of the deployment would share that identity. |
See also
- OIDC setup for worked provider examples and the redirect URI rule.
- Security for what
ENCRYPTION_KEYprotects and the consequences of rotating or losing it. - Kubernetes for how the Helm chart maps these to
values.yaml.