Environment variables

The DataMind Installer reads two different environment files, and confusing them is the most common configuration mistake. Keep them apart:

Important

Values in the installer's own .env are interpolated by Docker Compose before the containers start. To change any of them you edit the file and recreate the container — see Rotating values for which changes are safe.

Installer runtime variables

Every variable below is present in .env.example, injected by the compose file, or read directly by the backend. Default is the value shipped in .env.example or the fallback in code.

VariableTypeDefaultRequiredControlsEffect of changing
VERSIONstring (image tag)latestNoImage tag the installer runs as, and the tag the self-update helper pullsSwitching it and recreating changes the running build; the supported path is self-update, which pins the tag itself
DELAMAIN_IMAGEimage referenceinjected by compose as unistream.azurecr.io/delamain:${VERSION}; code fallback delamainNoImage used to spawn the self-update helper and the host-migration helperMust match the running image, or the helpers run the wrong build
DELAMAIN_CHANNELstringprod (compose); dev in the dev composeNoInstall channel; selects the published compose file to compare against and the self-update tag channelRepoints self-update at another channel — do not change after install
DELAMAIN_CONTAINER_NAMEstringdelamain-backend (code); delamain-backend-dev in dev composeNoName of the container the backend inspects to resolve its own running image and compose projectWrong value breaks version reporting and self-update
ACR_URLhost nameunistream.azurecr.io (code); unistreamdev.azurecr.io in dev composeNoContainer registry host pulled fromWrong host fails every image pull
BLOB_ARTIFACT_VARIANTenum: empty or devempty (production artifacts)NoSelects the published artifact pair: production schema + compose, or the dev pairNever set on a client host — it switches the installer onto dev artifacts
DOCKER_SOCKhost path/var/run/docker.sockNoHost path of the Docker socket bind-mounted into the backendMust point at the correct socket (rootful vs rootless); wrong value leaves the backend unable to drive Docker
NEST_PORTinteger8000NoPort the backend listens on, and the host port published by composeChanges both the listen port and the published port; a reverse proxy or client using the old port must be updated first
NEST_NODE_ENVenum: dev or prodprodNoLog verbosity and production cookie-domain behaviourdev raises log verbosity; production cookie handling depends on prod
SWAGGER_ENABLEDbooleanfalseNoServes the OpenAPI UI at /api/docsTurning it on exposes the API surface; turning it off removes the route
TZstringUTCNoContainer timezoneChanges the local timezone used by the container's clock
NEST_TYPEORM_LOGGINGbooleanfalseNoTypeORM query loggingTurning it on logs every SQL statement — verbose and not for production
NEST_ORIGINScomma-separated listhttp://localhost:8000NoCORS allowlistOnly relevant when the UI is served from a different origin; irrelevant in the default same-origin setup
POSTGRES_HOSTstringpostgres (injected by compose)NoDatabase hostPoints the backend at another database
POSTGRES_PORTinteger5432 (injected by compose)NoDatabase portPoints the backend at another database port
POSTGRES_USERstringpostgresNoDatabase userChanges the role the backend and the Postgres container use; must match the role in the data volume
POSTGRES_DATABASE_NAMEstringdelamainNoDatabase nameChanging it after first start points the backend at a database that was never created
JWT_ACCESS_EXPIRYduration string30mNoLifetime of an access tokenLonger tokens stay valid longer; applies to newly issued tokens
JWT_REFRESH_EXPIRYduration string7dNoLifetime of a refresh tokenLonger refresh windows mean longer-lived sessions
AZURE_TENANT_IDUUIDnone in code; set by composeYes (validated non-empty)Azure AD tenant used for registry and blob authenticationThe backend refuses to start if it is empty; changing it breaks registry blob and ACR authentication
AZURE_CLIENT_IDUUIDnone in code; set by composeYes (validated non-empty)Azure AD application (client) idThe backend refuses to start if it is empty; changing it breaks Azure authentication
AZURE_CLIENT_SECRETstringnoneNoAzure AD client secretNot an .env value — stored encrypted in the database and set through the UI (see Secrets)
MIGRATE_HOST_SCRIPT_PATHhost path/opt/delamain/migrate-host.shNoWhere the host-migration script is copied before it runsMust be a path the migration helper can execute inside the host's namespaces
MIGRATE_HOST_DIRhost path/opt/delamainNoHost directory bind-mounted into the backend at the identical pathUsed only by compose; must stay consistent with MIGRATE_HOST_SCRIPT_PATH
JENKINS_HOMEhost path/var/lib/jenkinsNoJenkins home bind-mounted read-only into the backendFeeds the migration-time config.xml import
SECRETS_DIRpath./secrets in code; /usr/src/app/secrets via the mounted volumeNoDirectory the generated secret files are read from and written toMust stay the mounted volume, or generated secrets are lost on recreate
DEPLOYMENT_DIRcontainer path/usr/src/app/deployment (compose)NoDirectory holding the deployed stack's downloaded compose file and generated .envMust stay the bind-mounted path that maps to the host ./deployment
TMPDIRpath/var/tmp/delamainNoTemp directory; also the parent of the self-update staging directoryMust be bind-mounted at the same path host and container, or the helper receives an empty staging directory
JWT_SECRETstringgenerated on first bootNoJWT signing secretSet from the jwt.secret file at runtime; overriding it would break existing sessions
NEST_ENCR_KEYbase64 stringgenerated on first bootNoAES-256-GCM key that encrypts stored secret valuesSet from the encr.key file at runtime; changing it makes stored secrets undecryptable
POSTGRES_PASSstringgenerated on first bootNoDatabase passwordRead from the pg.pass file; not set in .env
CURATO_SERVICE_TOKENstringgenerated on first bootNoShared secret the curato service presents to drive deploymentsRead from the curato.token file, and written into the deployed stack's .env

Image and version

VERSION is the single knob for which build of the DataMind Installer runs. The compose file defaults it to prod-latest when unset, while .env.example ships latest; pin a concrete tag for production hosts so a restart cannot silently move the running build.

DELAMAIN_IMAGE is derived from the same tag and is used whenever the installer has to start a sibling container: the self-update helper (a detached container built from the new image) and the host-migration helper. DELAMAIN_CONTAINER_NAME must match the container the installer actually runs in, because version reporting and self-update resolve the running build by inspecting that container, not by reading the tag.

BLOB_ARTIFACT_VARIANT selects which published artifact pair the installer downloads — the production schema and compose, or the dev pair. It is deliberately independent of NEST_NODE_ENV, so raising log verbosity can never switch a host onto dev artifacts. Leave it empty on any client host.

Docker access

DOCKER_SOCK is the host path of the Docker socket bind-mounted into the backend. The deploy engine drives docker compose through this socket, so access to it is equivalent to host root. Standard (rootful) Docker uses /var/run/docker.sock. For rootless Docker, point it at the rootless socket, for example /run/user/1000/docker.sock (find the UID with id -u).

Server and API

NEST_PORT controls the port the backend listens on and the host port compose publishes; both come from the same variable, so changing it moves the UI and API together. In the default setup the installer serves the SPA and the API from the same origin, which is why NEST_ORIGINS is described as irrelevant unless you repoint the UI at the backend from a different origin.

NEST_NODE_ENV selects log verbosity: prod restricts the logger to error, warn, log and fatal; dev adds debug and verbose. It also gates production cookie behaviour. SWAGGER_ENABLED serves the OpenAPI UI at /api/docs.

Database

POSTGRES_HOST and POSTGRES_PORT are injected by the compose file (the postgres service name on the compose network) rather than set in .env, because the backend and the init job must reach the database over the compose network. POSTGRES_USER and POSTGRES_DATABASE_NAME are interpolated into both the Postgres container and the backend, so the two stay in step. The password is never in .env — see Secrets.

Sessions

JWT_ACCESS_EXPIRY and JWT_REFRESH_EXPIRY set token lifetimes. Both are read once when the auth service starts, so a change applies to tokens issued after the next restart. JWT_SECRET is not an .env value: it is generated into the secrets volume on first boot and loaded at runtime.

Azure integration

AZURE_TENANT_ID and AZURE_CLIENT_ID are the only two variables the backend validates as mandatory: the application throws on startup if either is empty. They identify the Azure AD application used to authenticate to the container registry and blob storage. The matching client secret is stored encrypted in the database, not in .env.

Deployment paths and mounts

DEPLOYMENT_DIR is the container path of the directory that holds the deployed stack's compose file and generated .env; compose bind-mounts the host ./deployment there, so the files survive a container recreate. TMPDIR must be bind-mounted at the same path host and container — the self-update helper deliberately relies on that identity to receive staged files. MIGRATE_HOST_DIR and MIGRATE_HOST_SCRIPT_PATH locate the host-migration script, and JENKINS_HOME exposes the existing Jenkins configuration read-only for the migration-time import.

Variables the installer generates

These four values never appear in .env. They are generated on first boot and stored in the delamain_secrets volume:

Their creation, storage and rotation are covered in Secrets and Rotating values.

The deployed stack's environment file

The installer generates a second environment file for the DataMind OS services it deploys. It is written from the rows stored in the installer's own database, which are seeded from a published schema template (.env.unified.template, downloaded from blob storage). The concrete variable names in that file — PLATFORM_URL, the per-service memory and port variables, and the rest — are defined by that published schema and are not enumerated in this repository. This page therefore does not list them. Behaviour that is defined in this repository:

For the service names and groups these rows attach to, see Service catalog.

Note

The installer's own .env is separate from this generated file. Editing values in the UI changes the deployed stack, not the installer.