Configuration

The Configuration screen opens the editor titled Advanced configuration. It holds every setting DataMind OS runs with. The first install uses the same editor to review the values before anything is deployed.

A host has two environment files:

File in the install directoryRead byWritten by
.envThe DataMind InstallerYou, by hand. See What lives on the host
deployment/.envDataMind OSThe Installer, from this screen

The editor

The sidebar lists General, then the groups from the configuration schema DataMind publishes with each release, then System secrets. General holds the rows that belong to no group.

Each row is labelled with its environment key. An icon shows where its value comes from:

Icon tooltipThe value comes from
User-provided valueYou
Constant — fixed valueThe published schema
Auto-generated valueThe Installer, drawn at random once
Computed from host resourcesThe host's memory, recalculated on every generation

Admins edit. Everyone else sees Read-only — an admin account is required to edit configuration, with secret rows masked. System secrets holds AZURE_CLIENT_SECRET, the Azure client secret. It shows Configured or Not set, and a warning icon when Azure rejects it. Its value is never shown.

Required rows

A red * after a key marks a required row. Required if <KEY> is set means the row becomes required once that other key has a value.

How each row reaches deployment/.env:

The rowWritten as
Has a valueKEY=value
Was cleared and savedKEY=
Has no value, source User, not requiredLeft out, so the service uses its built-in default
Has no value, any other source or requiredKEY=

A cleared row is saved as empty (KEY=) and passes the required check. Never clear a required row: enter a new value instead.

The Installer rewrites deployment/.env on every save, install and update. A hand edit to the file is lost at the next rewrite. CURATO_SERVICE_TOKEN is not a row: the Installer writes it from its secrets volume.

Apply a saved change

A save stores the value and rewrites deployment/.env. Running services keep the old value until they are recreated.

  1. Change the values and click Save changes.
  2. Check the services the Configuration updated prompt lists. When a critical service is among them, expect a brief outage while it is recreated.
  3. Click Apply changes. The Installer recreates the services in waves, in dependency order, and shows Wave <n>: <services> — <x>/<y> healthy.

Apply changes never recreates one-shot services. Some rows are read by every service: applying one of them recreates the whole deployment.

Check it worked. The toast Configuration applied appears, and the warning icon beside the key is gone.

Rows saved but not applied

While the Installer is open in a browser, every 60 seconds it checks which rows you saved after each service was last recreated. Such a row shows a warning icon beside the key, with the tooltip Saved but not yet live in: <services> — use “Apply changes” to recreate these services.

If you dismiss the prompt, nothing is applied. It returns after your next save and lists every service still on old values. Restart on Service status does not apply them.

Rows that need care

Secret rows, auto-generated rows and the Azure client secret are stored encrypted in the Installer's database. The key is in its secrets volume: see What lives on the host.

Questions, answered

How do I change a setting?

Save, then apply. Change the value, click Save changes, then Apply changes in the prompt.

I dismissed the Apply changes prompt. How do I apply later?

Save another change. The prompt returns and lists every service still running old values.

How do I tell that a saved change is not live yet?

See Rows saved but not applied.