Variables
Define reusable key/value pairs and secrets available to all your projects.
Use Customization → Variables for values shared by Compose projects, such as a domain name, timezone, or database password.
How variables reach your projects
Section titled “How variables reach your projects”Arcane syncs variables from its database to each environment’s .env.global. Projects reference them like any Compose variable, for example ${DOMAIN}. On first sync, Arcane imports the remote environment’s existing variables before managing the file.
What Compose can and cannot see
Section titled “What Compose can and cannot see”Compose resolves a ${VAR} in your project from three places, in increasing order of precedence:
- A short allowlist of Arcane’s own process environment —
TZ,LANG,LANGUAGE, andLC_ALL, and nothing else. .env.global, which is what the Variables page writes.- The project’s own
.env.
Add a variable
Section titled “Add a variable”- Go to Customization → Variables.
- Select Add Variable.
- Enter a Key and a Value.
- Choose the scope — all environments, or specific ones.
- Mark it as a secret if the value is sensitive.
- Save.
Keys must be valid POSIX environment names: letters, digits, and underscores, not starting with a digit. DB_PASSWORD and _INTERNAL are fine; db-password and 2FAST are rejected.
Environment scoping
Section titled “Environment scoping”Choose all environments or specific environments. The same key can have different values in staging and production; each row shows its scope.
Secrets
Section titled “Secrets”Mark a value as a Secret to encrypt it in the database. Arcane masks it in the table, excludes it from search, and never returns it to the browser.
Secrets are encrypted in the database and in transit, but written as plaintext in .env.global for Compose. Protect that directory on the destination host.