0 Try the Demo

Environment Variables

Every environment variable Arcane reads, and which settings you can override from the environment.

This page lists the environment variables Arcane reads at startup. Most settings can also be changed in the Settings UI; use these when you configure Arcane from your Compose file or need a value in place before first start.

74 of 74 variables

Variable Details
ADMIN_STATIC_API_KEY

Maps to the AdminStaticAPIKey config field.

Default —
AGENT_MODE

Maps to the AgentMode config field.

Default false
AGENT_TOKEN

Maps to the AgentToken config field.

Default —
ALLOW_CLI_MFA_RESET

Maps to the AllowCLIMFAReset config field.

Default false
ALLOW_CLI_PASSWORD_RESET

Maps to the AllowCLIPasswordReset config field.

Default false
ALLOW_DOWNGRADE

Maps to the AllowDowngrade config field.

Default false
ANALYTICS_DISABLED

Maps to the AnalyticsDisabled config field.

Default false
APNS_KEY_ALGORITHM

Maps to the ApnsKeyAlgorithm config field.

Default ed25519
APNS_RELAY_URL

Maps to the ApnsRelayUrl config field.

Default https://apns.getarcane.app
APP_URL

Maps to the AppUrl config field.

Default http://localhost:3552
ARCANE_BACKUP_VOLUME_NAME

Maps to the BackupVolumeName config field.

Default arcane-backups
AUTO_LOGIN_PASSWORD

Maps to the AutoLoginPassword config field.

Default arcane-admin
AUTO_LOGIN_USERNAME

Auto-login credentials (used only when built with the buildables tag + autologin feature flag).

Default arcane
DATABASE_URL

Maps to the DatabaseURL config field.

Default file:data/arcane.db?_pragma=journal_mode(WAL)&_pragma=busy_timeout(2500)&_txlock=immediate
DIR_PERM

Maps to the DirPerm config field.

Default 0755
DOCKER_CONFIG

Maps to the DockerConfig config field.

Default —
DOCKER_HOST

Maps to the DockerHost config field.

Default unix:///var/run/docker.sock
EDGE_AGENT

Maps to the EdgeAgent config field.

Default false
EDGE_MTLS_ASSETS_DIR

Maps to the EdgeMTLSAssetsDir config field.

Default —
EDGE_MTLS_CA_FILE

Maps to the EdgeMTLSCAFile config field.

Default —
EDGE_MTLS_CERT_FILE

Maps to the EdgeMTLSCertFile config field.

Default —
EDGE_MTLS_KEY_FILE

Maps to the EdgeMTLSKeyFile config field.

Default —
EDGE_MTLS_MODE

Maps to the EdgeMTLSMode config field.

Default disabled
EDGE_MTLS_SERVER_NAME

Maps to the EdgeMTLSServerName config field.

Default —
EDGE_RECONNECT_INTERVAL

seconds

Default 5
EDGE_TRANSPORT

Maps to the EdgeTransport config field.

Default auto
ENCRYPTION_KEY

Maps to the EncryptionKey config field.

Default arcane-dev-key-32-characters!!!
ENVIRONMENT

Maps to the Environment config field.

Default production
FILE_PERM

Maps to the FilePerm config field.

Default 0644
GIT_WORK_DIR

Maps to the GitWorkDir config field.

Default data/git
GPU_MONITORING_ENABLED

Maps to the GPUMonitoringEnabled config field.

Default false
GPU_TYPE

Maps to the GPUType config field.

Default auto
HTTPS_PROXY

Maps to the HTTPSProxy config field.

Default —
HTTP_CLIENT_TIMEOUT

Maps to the HTTPClientTimeout config field.

Default 0
HTTP_PROXY

HTTPProxy, HTTPSProxy and NoProxy are forwarded to temporary Trivy scan containers.

Default —
JWT_REFRESH_EXPIRY

Maps to the JWTRefreshExpiry config field.

Default 168h
JWT_SECRET

Maps to the JWTSecret config field.

Deprecated
Default —
LISTEN

Maps to the Listen config field.

Default —
LOG_JSON

Maps to the LogJson config field.

Default false
LOG_LEVEL

Maps to the LogLevel config field.

Default info
MANAGER_API_URL

Maps to the ManagerApiUrl config field.

Default —
NO_PROXY

Maps to the NoProxy config field.

Default —
OIDC_AUTO_REDIRECT_TO_PROVIDER

Maps to the OidcAutoRedirectToProvider config field.

Default false
OIDC_CLIENT_ID

Maps to the OidcClientID config field.

Default —
OIDC_CLIENT_SECRET

Maps to the OidcClientSecret config field.

Default —
OIDC_ENABLED

Maps to the OidcEnabled config field.

Default false
OIDC_GROUPS_CLAIM

Maps to the OidcGroupsClaim config field.

Default groups
OIDC_ISSUER_URL

Maps to the OidcIssuerURL config field.

Default —
OIDC_MOBILE_REDIRECT_URIS

Maps to the OidcMobileRedirectUris config field.

Default arcane-mobile://oidc-callback
OIDC_PROVIDER_LOGO_URL

Maps to the OidcProviderLogoUrl config field.

Default —
OIDC_PROVIDER_NAME

Maps to the OidcProviderName config field.

Default —
OIDC_ROLE_MAPPINGS

OidcRoleMappings declaratively defines OIDC group→role mappings as a JSON array of role.OidcRoleMappingSpec. Reconciled into source='env' rows on every boot; rows are read-only at runtime. Supports *_FILE for Docker secrets. Leave empty to manage mappings purely via the UI/API.

Default —
OIDC_SCOPES

Maps to the OidcScopes config field.

Default openid email profile
OIDC_SKIP_TLS_VERIFY

Maps to the OidcSkipTlsVerify config field.

Default false
PGID

Maps to the PGID config field.

Default —
PORT

Maps to the Port config field.

Default 3552
PROJECTS_DIRECTORY

Maps to the ProjectsDirectory config field.

Default /app/data/projects
PROJECT_SCAN_MAX_DEPTH

Maps to the ProjectScanMaxDepth config field.

Default 3
PROJECT_SCAN_SKIP_DIRS

Maps to the ProjectScanSkipDirs config field.

Default .git,node_modules,vendor,.venv,venv,__pycache__,.cache,dist,build,target,.next,.nuxt,.svelte-kit
PROJECT_WORKSPACE_MAX_DEPTH

Maps to the ProjectWorkspaceMaxDepth config field.

Default 20
PROJECT_WORKSPACE_MAX_ENTRIES

Maps to the ProjectWorkspaceMaxEntries config field.

Default 2000
PROJECT_WORKSPACE_MAX_FILE_SIZE_MB

Maps to the ProjectWorkspaceMaxFileSizeMB config field.

Default 10
PUID

Maps to the PUID config field.

Default —
TEMPLATES_DIRECTORY

Maps to the TemplatesDirectory config field.

Default /app/data/templates
TLS_CERT_FILE

Maps to the TLSCertFile config field.

Default —
TLS_ENABLED

Maps to the TLSEnabled config field.

Default false
TLS_KEY_FILE

Maps to the TLSKeyFile config field.

Default —
TRUSTED_PROXIES

Maps to the TrustedProxies config field.

Default —
TZ

Timezone for cron job scheduling. Uses IANA timezone names (e.g., "America/New_York", "Europe/London"). "Local" uses the system's local timezone, "UTC" for Coordinated Universal Time.

Default Local
UI_CONFIGURATION_DISABLED

Maps to the UIConfigurationDisabled config field.

Default false
UPDATE_CHECK_DISABLED

Maps to the UpdateCheckDisabled config field.

Default false
VOLUME_WORKSPACE_MAX_DEPTH

Maps to the VolumeWorkspaceMaxDepth config field.

Default 50
VOLUME_WORKSPACE_MAX_ENTRIES

Maps to the VolumeWorkspaceMaxEntries config field.

Default 10000
VOLUME_WORKSPACE_MAX_FILE_SIZE_MB

Maps to the VolumeWorkspaceMaxFileSizeMB config field.

Default 10
Note

Arcane also accepts the lowercase proxy variables http_proxy, https_proxy, and no_proxy.

To use an external Postgres database through DATABASE_URL, see Installation, which has the connection string format.

Settings overrides

The overrides below only take effect when UI_CONFIGURATION_DISABLED=true or AGENT_MODE=true is set. Otherwise Arcane ignores them.

110 of 110 setting overrides

Env Var Details
AUTO_HEAL_INTERVAL
Setting autoHealInterval

How often to check container health (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.
ENVIRONMENT_HEALTH_INTERVAL
Setting environmentHealthInterval

How often to check environment connectivity (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
EVENT_CLEANUP_INTERVAL
Setting eventCleanupInterval

How often to delete old events (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
EXPIRED_SESSIONS_CLEANUP_INTERVAL
Setting expiredSessionsCleanupInterval

How often to delete expired and old revoked sessions (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
ACTIVITY_HISTORY_MAX_ENTRIES
Setting activityHistoryMaxEntries

Maximum completed Activity Center entries to keep per environment. Set 0 to disable count-based cleanup.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
ACTIVITY_HISTORY_RETENTION_DAYS
Setting activityHistoryRetentionDays

Delete completed Activity Center entries older than this many days. Set 0 to disable age-based cleanup.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
MAX_CONCURRENT_ACTIVITIES
Setting maxConcurrentActivities

Maximum long-running activities per environment before new ones queue. Set 0 for unlimited.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTH_LOCAL_ENABLED
Setting authLocalEnabled

Enable local username/password authentication

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTH_PASSWORD_POLICY
Setting authPasswordPolicy

Set password strength requirements

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTH_SESSION_TIMEOUT
Setting authSessionTimeout

How long user sessions remain active

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
OIDC_AUTHORIZATION_ENDPOINT
Setting oidcAuthorizationEndpoint

Override OIDC authorization endpoint

OIDC_AUTO_REDIRECT_TO_PROVIDER
Setting oidcAutoRedirectToProvider

Automatically redirect to OIDC provider on login page

OIDC_CLIENT_ID
Setting oidcClientId

OIDC provider client ID

OIDC_CLIENT_SECRET
Setting oidcClientSecret

OIDC provider client secret

Sensitive
OIDC_DEVICE_AUTHORIZATION_ENDPOINT
Setting oidcDeviceAuthorizationEndpoint

Override OIDC device authorization endpoint for CLI authentication

OIDC_ENABLED
Setting oidcEnabled

Enable OpenID Connect (OIDC) authentication

OIDC_GROUPS_CLAIM
Setting oidcGroupsClaim

Claim name to read group memberships from for role mapping (default: groups)

OIDC_ISSUER_URL
Setting oidcIssuerUrl

OIDC provider issuer URL

OIDC_JWKS_ENDPOINT
Setting oidcJwksEndpoint

Override OIDC JWKS endpoint

OIDC_MERGE_ACCOUNTS
Setting oidcMergeAccounts

Allow OIDC logins to merge with existing accounts by email

OIDC_MOBILE_REDIRECT_URIS
Setting oidcMobileRedirectUris

Comma-separated allowlist of native app redirect URIs (e.g., arcane-mobile://oidc-callback)

OIDC_PROVIDER_LOGO_URL
Setting oidcProviderLogoUrl

Custom logo URL for the OIDC provider

OIDC_PROVIDER_NAME
Setting oidcProviderName

Custom name for the OIDC provider (e.g., Authentik, Keycloak)

OIDC_SCOPES
Setting oidcScopes

OIDC scopes to request

OIDC_SKIP_TLS_VERIFY
Setting oidcSkipTlsVerify

Skip TLS verification for OIDC provider

OIDC_TOKEN_ENDPOINT
Setting oidcTokenEndpoint

Override OIDC token endpoint

OIDC_USERINFO_ENDPOINT
Setting oidcUserinfoEndpoint

Override OIDC userinfo endpoint

BUILDS_DIRECTORY
Setting buildsDirectory

Root directory for manual build workspaces

BUILD_PROVIDER
Setting buildProvider

Default build provider (local or depot)

BUILD_TIMEOUT
Setting buildTimeout

Timeout for BuildKit builds in seconds (default: 1800 = 30 minutes)

DEPOT_PROJECT_ID
Setting depotProjectId

Depot project identifier

DEPOT_TOKEN
Setting depotToken

Depot API token

Sensitive
BASE_SERVER_URL
Setting baseServerUrl

Set the base URL for the application

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
DEFAULT_SHELL
Setting defaultShell

Default shell to use for commands

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
DISK_USAGE_PATH
Setting diskUsagePath

Path used for disk usage calculations

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
EXPERIMENTAL_FEATURES_ENABLED
Setting experimentalFeaturesEnabled

Enable experimental features that may change or be removed in future releases

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
FEATURE_VULNERABILITY_MANAGEMENT_ENABLED
Setting featureVulnerabilityManagementEnabled

Enable vulnerability management for this environment. Disabling retains reports and configuration and leaves standalone image patching available

Disabling retains existing reports and scanner settings, allows active work to finish, and leaves standalone image patching available.
FOLLOW_PROJECT_SYMLINKS
Setting followProjectSymlinks

Treat symlinked child directories inside the projects directory as Docker Compose projects

GIT_SYNC_MAX_BINARY_SIZE_MB
Setting gitSyncMaxBinarySizeMb

Maximum size in MB for a single binary file copied during a Git sync. Set 0 to disable the environment cap (default: 10)

GIT_SYNC_MAX_FILES
Setting gitSyncMaxFiles

Maximum number of repository files copied during a Git sync. Set 0 to disable the environment cap (default: 500)

GIT_SYNC_MAX_TOTAL_SIZE_MB
Setting gitSyncMaxTotalSizeMb

Maximum combined size in MB for files copied during a Git sync. Set 0 to disable the environment cap (default: 50)

AUTO_HEAL_ENABLED
Setting autoHealEnabled

Automatically restart containers that become unhealthy

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTO_HEAL_EXCLUDED_CONTAINERS
Setting autoHealExcludedContainers

Comma-separated list of containers to exclude from auto-heal

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.
AUTO_HEAL_MAX_RESTARTS
Setting autoHealMaxRestarts

Maximum auto-heal restarts per container within the restart window (default: 5)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.
AUTO_HEAL_RESTART_WINDOW
Setting autoHealRestartWindow

Time window in minutes for counting auto-heal restarts (default: 30)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.
AUTO_INJECT_ENV
Setting autoInjectEnv

Automatically inject project .env variables into all containers (default: false)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTO_UPDATE
Setting autoUpdate

Automatically update containers when new images are available

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTO_UPDATE_EXCLUDED_CONTAINERS
Setting autoUpdateExcludedContainers

Comma-separated list of containers to exclude from auto-update

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
AUTO_UPDATE_INTERVAL
Setting autoUpdateInterval

How often to check for automatic updates (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_UPDATE=true to have effect at runtime.
DEFAULT_DEPLOY_PULL_POLICY
Setting defaultDeployPullPolicy

Default image pull policy when deploying projects

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
DOCKER_CLIENT_REFRESH_INTERVAL
Setting dockerClientRefreshInterval

How often to refresh the cached Docker client API version (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
DOCKER_HOST
Setting dockerHost

URI for Docker daemon

IMAGE_EVENT_WATCHER_ENABLED
Setting imageEventWatcherEnabled

Check image registries immediately after Docker image events

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
MAX_IMAGE_UPLOAD_SIZE
Setting maxImageUploadSize

Maximum size in MB for image archive uploads (default: 500)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
POLLING_ENABLED
Setting pollingEnabled

Enable automatic checking for image updates

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
POLLING_INTERVAL
Setting pollingInterval

How often to check for image updates (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
PROJECTS_DIRECTORY
Setting projectsDirectory

Configure where project files are stored

PRUNE_BUILD_CACHE_MODE
Setting pruneBuildCacheMode

Select how build cache should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
PRUNE_BUILD_CACHE_UNTIL
Setting pruneBuildCacheUntil

Duration threshold for scheduled build cache prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_BUILD_CACHE_MODE=olderThan to have effect at runtime.
PRUNE_CONTAINER_MODE
Setting pruneContainerMode

Select how containers should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
PRUNE_CONTAINER_UNTIL
Setting pruneContainerUntil

Duration threshold for scheduled container prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_CONTAINER_MODE=olderThan to have effect at runtime.
PRUNE_IMAGE_MODE
Setting pruneImageMode

Select how images should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
PRUNE_IMAGE_UNTIL
Setting pruneImageUntil

Duration threshold for scheduled image prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_IMAGE_MODE=olderThan to have effect at runtime.
PRUNE_NETWORK_MODE
Setting pruneNetworkMode

Select how networks should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
PRUNE_NETWORK_UNTIL
Setting pruneNetworkUntil

Duration threshold for scheduled network prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_NETWORK_MODE=olderThan to have effect at runtime.
PRUNE_VOLUME_MODE
Setting pruneVolumeMode

Select how volumes should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
SCHEDULED_PRUNE_ENABLED
Setting scheduledPruneEnabled

Enable scheduled pruning of unused Docker resources

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
SCHEDULED_PRUNE_INTERVAL
Setting scheduledPruneInterval

How often to run scheduled prunes (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.
SWARM_STACK_SOURCES_DIRECTORY
Setting swarmStackSourcesDirectory

Configure where swarm stack source files are stored

TEMPLATES_DIRECTORY
Setting templatesDirectory

Configure where local compose template folders are discovered

TOOLS_IMAGE_REGISTRY
Setting toolsImageRegistry

Container registry used to pull the Arcane tools helper image

UPDATE_CHECK_REGISTRY
Setting updateCheckRegistry

Registry queried when checking whether the Arcane image has a newer digest

VOLUME_HELPER_IDLE_TIMEOUT
Setting volumeHelperIdleTimeout

Minutes a volume helper container may sit idle before automatic removal (default: 10

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
APNS_ENABLED
Setting apnsEnabled

Let users receive native push notifications in the Arcane mobile app

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
IMAGE_AUTO_PATCH_ENABLED
Setting imageAutoPatchEnabled

Automatically patch images whose latest vulnerability scan found fixable OS package vulnerabilities

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
IMAGE_AUTO_PATCH_INTERVAL
Setting imageAutoPatchInterval

How often to run scheduled image patching (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
IMAGE_PATCH_ALL_PLATFORMS
Setting imagePatchAllPlatforms

Patch every platform in a multi-platform image instead of only the platform this server runs on

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
IMAGE_PATCH_SUFFIX
Setting imagePatchSuffix

Suffix appended to the source tag when patching an image (default: patched)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
IMAGE_PATCH_TIMEOUT_SEC
Setting imagePatchTimeoutSec

Timeout for a single image patch operation in seconds (default: 600)

LIFECYCLE_DEFAULT_RUNNER_IMAGE
Setting lifecycleDefaultRunnerImage

Default container image used to run GitOps pre-deploy lifecycle scripts when a sync does not override it

LIFECYCLE_ENABLED
Setting lifecycleEnabled

Allow GitOps syncs to configure pre-deploy lifecycle scripts. Disabled by default because scripts are repo-trusted code that runs on every deploy

LIFECYCLE_MAX_TIMEOUT_SEC
Setting lifecycleMaxTimeoutSec

Maximum allowed timeout for lifecycle scripts in seconds (default: 300)

TRIVY_CONCURRENT_SCAN_CONTAINERS
Setting trivyConcurrentScanContainers

Maximum number of concurrent Trivy scan containers for manual and scheduled scans. Minimum 1

TRIVY_CONFIG
Setting trivyConfig

Trivy configuration file content in YAML format

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
TRIVY_CPU_LIMIT
Setting trivyCpuLimit

Maximum CPU cores for Trivy scan containers (supports decimals, e.g. 1.5). Set 0 to disable CPU limit

TRIVY_DB_REGISTRY
Setting trivyDbRegistry

Container registry used to pull the Trivy vulnerability database artifacts

TRIVY_IGNORE
Setting trivyIgnore

Trivy ignore file content - one vulnerability ID per line

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
TRIVY_IGNORE_UNFIXED
Setting trivyIgnoreUnfixed

Only report vulnerabilities that have a known fix available. Reduces noise from vulnerabilities you cannot act on.

TRIVY_MEMORY_LIMIT_MB
Setting trivyMemoryLimitMb

Maximum memory for Trivy scan containers in MB. Set 0 to disable memory limit

TRIVY_NETWORK
Setting trivyNetwork

Docker network mode/network name used for Trivy scan containers. Leave empty to inherit Arcane's network automatically.

TRIVY_PRIVILEGED
Setting trivyPrivileged

Run Trivy scan containers in privileged mode when required by the host security policy

TRIVY_RESOURCE_LIMITS_ENABLED
Setting trivyResourceLimitsEnabled

Enable CPU and memory limits for Trivy scan containers

TRIVY_SECURITY_OPTS
Setting trivySecurityOpts

Docker security options applied to Trivy scan containers. Use commas or new lines to separate entries (for example: label=disable)

TRIVY_SERVER_ENABLED
Setting trivyServerEnabled

Scan against a remote Trivy server instead of downloading the vulnerability database locally. Recommended for 32-bit hosts (arm/v7) where the local DB cannot be memory-mapped.

TRIVY_SERVER_TOKEN
Setting trivyServerToken

Optional authentication token sent to the remote Trivy server. Leave empty if the server requires no token.

Sensitive
TRIVY_SERVER_URL
Setting trivyServerUrl

URL of the remote Trivy server (e.g. http://trivy.example.com:4954). Used when client/server mode is enabled.

VULNERABILITY_SCAN_ENABLED
Setting vulnerabilityScanEnabled

Enable scheduled vulnerability scanning of all Docker images

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
VULNERABILITY_SCAN_INTERVAL
Setting vulnerabilityScanInterval

How often to run scheduled vulnerability scans (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true and VULNERABILITY_SCAN_ENABLED=true to have effect at runtime.
VULNERABILITY_THREAT_INTEL_ENABLED
Setting vulnerabilityThreatIntelEnabled

Fetch the CISA KEV catalog and FIRST EPSS scores to prioritize exploited vulnerabilities. Disable for air-gapped installs.

Requires: FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true to have effect at runtime.
DEPLOY_WAIT_TIMEOUT
Setting deployWaitTimeout

Timeout waiting for services to become healthy or complete during a deploy in seconds (default: 600 = 10 minutes)

DOCKER_API_TIMEOUT
Setting dockerApiTimeout

Timeout for Docker list operations in seconds (default: 30)

DOCKER_IMAGE_PULL_TIMEOUT
Setting dockerImagePullTimeout

Timeout for Docker image pulls in seconds (default: 600 = 10 minutes)

GIT_OPERATION_TIMEOUT
Setting gitOperationTimeout

Timeout for Git clone/fetch operations in seconds (default: 300 = 5 minutes)

HTTP_CLIENT_TIMEOUT
Setting httpClientTimeout

Default timeout for HTTP requests in seconds (default: 30)

PROXY_REQUEST_TIMEOUT
Setting proxyRequestTimeout

Timeout for proxied requests in seconds (default: 60)

REGISTRY_TAG_TIMEOUT
Setting registryTagTimeout

Timeout for listing every tag in a repository during version update checks in seconds (default: 120)

REGISTRY_TIMEOUT
Setting registryTimeout

Timeout for container registry operations in seconds (default: 30)

TRIVY_SCAN_TIMEOUT
Setting trivyScanTimeout

Timeout for Trivy image scans in seconds (default: 900 = 15 minutes)

AVATAR_MAX_UPLOAD_SIZE_MB
Setting avatarMaxUploadSizeMb

Maximum size in MB for profile picture uploads (default: 2)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.
ENABLE_GRAVATAR
Setting enableGravatar

Enable Gravatar profile pictures for users

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

Container runtime user

When Arcane runs inside a container, it drops to the built-in non-root user (65532:65532) unless PUID and PGID are set. Arcane treats itself as containerized when ARCANE_IN_CONTAINER=true (set by the official images), when the container variable is non-empty, or when /.dockerenv or /run/.containerenv exists. Outside a container, the process keeps the user it was started as.

Set PUID and PGID if mounted files should belong to a specific host user and group. If you point DOCKER_HOST at a custom Unix socket, Arcane uses that socket path when it adds the runtime user to the socket’s group.

Timezone and scheduled jobs

Arcane’s recurring jobs (image update checks, auto-updates, vulnerability scans, scheduled pruning, GitOps sync, and environment health checks) run on cron-style schedules evaluated in the timezone set by TZ. Set it to an IANA timezone name so jobs run at the local times you expect:

If TZ is unset, Arcane uses the container’s local time, which is UTC on the official images. Job intervals and cron expressions are set in the Settings UI, or through the environment when settings overrides are enabled.

Admin API key bootstrap

Set ADMIN_STATIC_API_KEY when automation needs a known API key from the first start. At startup, Arcane creates or updates a protected admin API key with this value, so you don’t have to create it in the UI. See the API Reference for usage and webhook examples.