Skip to content

Variables

Define reusable key/value pairs and secrets available to all your projects.

Use Customization → Variables for values shared by Compose projects, such as a domain name, timezone, or database password.

Arcane syncs variables from its database to each environment’s .env.global. Projects reference them like any Compose variable, for example ${DOMAIN}. On first sync, Arcane imports the remote environment’s existing variables before managing the file.

Compose resolves a ${VAR} in your project from three places, in increasing order of precedence:

  1. A short allowlist of Arcane’s own process environment — TZ, LANG, LANGUAGE, and LC_ALL, and nothing else.
  2. .env.global, which is what the Variables page writes.
  3. The project’s own .env.
  1. Go to Customization → Variables.
  2. Select Add Variable.
  3. Enter a Key and a Value.
  4. Choose the scope — all environments, or specific ones.
  5. Mark it as a secret if the value is sensitive.
  6. Save.

Keys must be valid POSIX environment names: letters, digits, and underscores, not starting with a digit. DB_PASSWORD and _INTERNAL are fine; db-password and 2FAST are rejected.

Choose all environments or specific environments. The same key can have different values in staging and production; each row shows its scope.

Mark a value as a Secret to encrypt it in the database. Arcane masks it in the table, excludes it from search, and never returns it to the browser.

Secrets are encrypted in the database and in transit, but written as plaintext in .env.global for Compose. Protect that directory on the destination host.

  • Projects — how Compose files and per-project .env files are managed.
  • Templates — variables pair well with templates for parameterized deployments.