The Configuration screen opens the editor titled Advanced configuration. It holds every setting DataMind OS runs with. The first install uses the same editor to review the values before anything is deployed.
A host has two environment files:
| File in the install directory | Read by | Written by |
|---|---|---|
. | The DataMind Installer | You, by hand. See What lives on the host |
deployment/ | DataMind OS | The Installer, from this screen |
The sidebar lists General, then the groups from the configuration schema DataMind publishes with each release, then System secrets. General holds the rows that belong to no group.
Each row is labelled with its environment key. An icon shows where its value comes from:
| Icon tooltip | The value comes from |
|---|---|
| User-provided value | You |
| Constant — fixed value | The published schema |
| Auto-generated value | The Installer, drawn at random once |
| Computed from host resources | The host's memory, recalculated on every generation |
Admins edit. Everyone else sees Read-only — an admin account is required to edit configuration,
with secret rows masked. System secrets holds AZURE_CLIENT_SECRET, the Azure client secret. It
shows Configured or Not set, and a warning icon when Azure rejects it. Its value is never
shown.
A red * after a key marks a required row. Required if <KEY> is set means the row becomes
required once that other key has a value.
How each row reaches deployment/:
| The row | Written as |
|---|---|
| Has a value | KEY=value |
| Was cleared and saved | KEY= |
| Has no value, source User, not required | Left out, so the service uses its built-in default |
| Has no value, any other source or required | KEY= |
A cleared row is saved as empty (KEY=) and passes the required check. Never clear a required row:
enter a new value instead.
The Installer rewrites deployment/ on every save, install and update. A hand edit to the file
is lost at the next rewrite. CURATO_SERVICE_TOKEN is not a row: the Installer writes it from its
secrets volume.
A save stores the value and rewrites deployment/. Running services keep the old value until
they are recreated.
Wave <n>: <services> — <x>/ <y> healthy.Apply changes never recreates one-shot services. Some rows are read by every service: applying one of them recreates the whole deployment.
Check it worked. The toast Configuration applied appears, and the warning icon beside the key is gone.
While the Installer is open in a browser, every 60 seconds it checks which rows you saved after each
service was last recreated. Such a row shows a warning icon beside the key, with the tooltip
Saved but not yet live in: <services> — use “Apply changes” to recreate these services.
If you dismiss the prompt, nothing is applied. It returns after your next save and lists every service still on old values. Restart on Service status does not apply them.
PLATFORM_URL. The root of every URL the services derive. It is checked on save. See
TLS and certificates.deployment/ . env holds per-service memory limits
and reservations. A row you edit keeps your value, and the block lists it on the line
# hand-edited, dependent rows recalculated from them:.Secret rows, auto-generated rows and the Azure client secret are stored encrypted in the Installer's database. The key is in its secrets volume: see What lives on the host.
Save, then apply. Change the value, click Save changes, then Apply changes in the prompt.
Save another change. The prompt returns and lists every service still running old values.