Environment Variables
Every environment variable Arcane reads, and which settings you can override from the environment.
This page lists the environment variables Arcane reads at startup. Most settings can also be changed in the Settings UI; use these when you configure Arcane from your Compose file or need a value in place before first start.
74 of 74 variables
| Variable | Details |
|---|---|
ADMIN_STATIC_API_KEY | Maps to the AdminStaticAPIKey config field. Default — |
AGENT_MODE | Maps to the AgentMode config field. Default false |
AGENT_TOKEN | Maps to the AgentToken config field. Default — |
ALLOW_CLI_MFA_RESET | Maps to the AllowCLIMFAReset config field. Default false |
ALLOW_CLI_PASSWORD_RESET | Maps to the AllowCLIPasswordReset config field. Default false |
ALLOW_DOWNGRADE | Maps to the AllowDowngrade config field. Default false |
ANALYTICS_DISABLED | Maps to the AnalyticsDisabled config field. Default false |
APNS_KEY_ALGORITHM | Maps to the ApnsKeyAlgorithm config field. Default ed25519 |
APNS_RELAY_URL | Maps to the ApnsRelayUrl config field. Default https://apns.getarcane.app |
APP_URL | Maps to the AppUrl config field. Default http://localhost:3552 |
ARCANE_BACKUP_VOLUME_NAME | Maps to the BackupVolumeName config field. Default arcane-backups |
AUTO_LOGIN_PASSWORD | Maps to the AutoLoginPassword config field. Default arcane-admin |
AUTO_LOGIN_USERNAME | Auto-login credentials (used only when built with the buildables tag + autologin feature flag). Default arcane |
DATABASE_URL | Maps to the DatabaseURL config field. Default file:data/arcane.db?_pragma=journal_mode(WAL)&_pragma=busy_timeout(2500)&_txlock=immediate |
DIR_PERM | Maps to the DirPerm config field. Default 0755 |
DOCKER_CONFIG | Maps to the DockerConfig config field. Default — |
DOCKER_HOST | Maps to the DockerHost config field. Default unix:///var/run/docker.sock |
EDGE_AGENT | Maps to the EdgeAgent config field. Default false |
EDGE_MTLS_ASSETS_DIR | Maps to the EdgeMTLSAssetsDir config field. Default — |
EDGE_MTLS_CA_FILE | Maps to the EdgeMTLSCAFile config field. Default — |
EDGE_MTLS_CERT_FILE | Maps to the EdgeMTLSCertFile config field. Default — |
EDGE_MTLS_KEY_FILE | Maps to the EdgeMTLSKeyFile config field. Default — |
EDGE_MTLS_MODE | Maps to the EdgeMTLSMode config field. Default disabled |
EDGE_MTLS_SERVER_NAME | Maps to the EdgeMTLSServerName config field. Default — |
EDGE_RECONNECT_INTERVAL | seconds Default 5 |
EDGE_TRANSPORT | Maps to the EdgeTransport config field. Default auto |
ENCRYPTION_KEY | Maps to the EncryptionKey config field. Default arcane-dev-key-32-characters!!! |
ENVIRONMENT | Maps to the Environment config field. Default production |
FILE_PERM | Maps to the FilePerm config field. Default 0644 |
GIT_WORK_DIR | Maps to the GitWorkDir config field. Default data/git |
GPU_MONITORING_ENABLED | Maps to the GPUMonitoringEnabled config field. Default false |
GPU_TYPE | Maps to the GPUType config field. Default auto |
HTTPS_PROXY | Maps to the HTTPSProxy config field. Default — |
HTTP_CLIENT_TIMEOUT | Maps to the HTTPClientTimeout config field. Default 0 |
HTTP_PROXY | HTTPProxy, HTTPSProxy and NoProxy are forwarded to temporary Trivy scan containers. Default — |
JWT_REFRESH_EXPIRY | Maps to the JWTRefreshExpiry config field. Default 168h |
JWT_SECRET | Maps to the JWTSecret config field. DeprecatedDefault — |
LISTEN | Maps to the Listen config field. Default — |
LOG_JSON | Maps to the LogJson config field. Default false |
LOG_LEVEL | Maps to the LogLevel config field. Default info |
MANAGER_API_URL | Maps to the ManagerApiUrl config field. Default — |
NO_PROXY | Maps to the NoProxy config field. Default — |
OIDC_AUTO_REDIRECT_TO_PROVIDER | Maps to the OidcAutoRedirectToProvider config field. Default false |
OIDC_CLIENT_ID | Maps to the OidcClientID config field. Default — |
OIDC_CLIENT_SECRET | Maps to the OidcClientSecret config field. Default — |
OIDC_ENABLED | Maps to the OidcEnabled config field. Default false |
OIDC_GROUPS_CLAIM | Maps to the OidcGroupsClaim config field. Default groups |
OIDC_ISSUER_URL | Maps to the OidcIssuerURL config field. Default — |
OIDC_MOBILE_REDIRECT_URIS | Maps to the OidcMobileRedirectUris config field. Default arcane-mobile://oidc-callback |
OIDC_PROVIDER_LOGO_URL | Maps to the OidcProviderLogoUrl config field. Default — |
OIDC_PROVIDER_NAME | Maps to the OidcProviderName config field. Default — |
OIDC_ROLE_MAPPINGS | OidcRoleMappings declaratively defines OIDC group→role mappings as a JSON array of role.OidcRoleMappingSpec. Reconciled into source='env' rows on every boot; rows are read-only at runtime. Supports *_FILE for Docker secrets. Leave empty to manage mappings purely via the UI/API. Default — |
OIDC_SCOPES | Maps to the OidcScopes config field. Default openid email profile |
OIDC_SKIP_TLS_VERIFY | Maps to the OidcSkipTlsVerify config field. Default false |
PGID | Maps to the PGID config field. Default — |
PORT | Maps to the Port config field. Default 3552 |
PROJECTS_DIRECTORY | Maps to the ProjectsDirectory config field. Default /app/data/projects |
PROJECT_SCAN_MAX_DEPTH | Maps to the ProjectScanMaxDepth config field. Default 3 |
PROJECT_SCAN_SKIP_DIRS | Maps to the ProjectScanSkipDirs config field. Default .git,node_modules,vendor,.venv,venv,__pycache__,.cache,dist,build,target,.next,.nuxt,.svelte-kit |
PROJECT_WORKSPACE_MAX_DEPTH | Maps to the ProjectWorkspaceMaxDepth config field. Default 20 |
PROJECT_WORKSPACE_MAX_ENTRIES | Maps to the ProjectWorkspaceMaxEntries config field. Default 2000 |
PROJECT_WORKSPACE_MAX_FILE_SIZE_MB | Maps to the ProjectWorkspaceMaxFileSizeMB config field. Default 10 |
PUID | Maps to the PUID config field. Default — |
TEMPLATES_DIRECTORY | Maps to the TemplatesDirectory config field. Default /app/data/templates |
TLS_CERT_FILE | Maps to the TLSCertFile config field. Default — |
TLS_ENABLED | Maps to the TLSEnabled config field. Default false |
TLS_KEY_FILE | Maps to the TLSKeyFile config field. Default — |
TRUSTED_PROXIES | Maps to the TrustedProxies config field. Default — |
TZ | Timezone for cron job scheduling. Uses IANA timezone names (e.g., "America/New_York", "Europe/London"). "Local" uses the system's local timezone, "UTC" for Coordinated Universal Time. Default Local |
UI_CONFIGURATION_DISABLED | Maps to the UIConfigurationDisabled config field. Default false |
UPDATE_CHECK_DISABLED | Maps to the UpdateCheckDisabled config field. Default false |
VOLUME_WORKSPACE_MAX_DEPTH | Maps to the VolumeWorkspaceMaxDepth config field. Default 50 |
VOLUME_WORKSPACE_MAX_ENTRIES | Maps to the VolumeWorkspaceMaxEntries config field. Default 10000 |
VOLUME_WORKSPACE_MAX_FILE_SIZE_MB | Maps to the VolumeWorkspaceMaxFileSizeMB config field. Default 10 |
Arcane also accepts the lowercase proxy variables http_proxy, https_proxy, and no_proxy.
To use an external Postgres database through DATABASE_URL, see Installation, which has the connection string format.
Settings overrides
The overrides below only take effect when UI_CONFIGURATION_DISABLED=true or AGENT_MODE=true is set. Otherwise Arcane ignores them.
110 of 110 setting overrides
| Env Var | Details |
|---|---|
AUTO_HEAL_INTERVAL | Setting autoHealIntervalHow often to check container health (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
ENVIRONMENT_HEALTH_INTERVAL | Setting environmentHealthIntervalHow often to check environment connectivity (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EVENT_CLEANUP_INTERVAL | Setting eventCleanupIntervalHow often to delete old events (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EXPIRED_SESSIONS_CLEANUP_INTERVAL | Setting expiredSessionsCleanupIntervalHow often to delete expired and old revoked sessions (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ACTIVITY_HISTORY_MAX_ENTRIES | Setting activityHistoryMaxEntriesMaximum completed Activity Center entries to keep per environment. Set 0 to disable count-based cleanup. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ACTIVITY_HISTORY_RETENTION_DAYS | Setting activityHistoryRetentionDaysDelete completed Activity Center entries older than this many days. Set 0 to disable age-based cleanup. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
MAX_CONCURRENT_ACTIVITIES | Setting maxConcurrentActivitiesMaximum long-running activities per environment before new ones queue. Set 0 for unlimited. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_LOCAL_ENABLED | Setting authLocalEnabledEnable local username/password authentication Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_PASSWORD_POLICY | Setting authPasswordPolicySet password strength requirements Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_SESSION_TIMEOUT | Setting authSessionTimeoutHow long user sessions remain active Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
OIDC_AUTHORIZATION_ENDPOINT | Setting oidcAuthorizationEndpointOverride OIDC authorization endpoint |
OIDC_AUTO_REDIRECT_TO_PROVIDER | Setting oidcAutoRedirectToProviderAutomatically redirect to OIDC provider on login page |
OIDC_CLIENT_ID | Setting oidcClientIdOIDC provider client ID |
OIDC_CLIENT_SECRET | Setting oidcClientSecretOIDC provider client secret Sensitive |
OIDC_DEVICE_AUTHORIZATION_ENDPOINT | Setting oidcDeviceAuthorizationEndpointOverride OIDC device authorization endpoint for CLI authentication |
OIDC_ENABLED | Setting oidcEnabledEnable OpenID Connect (OIDC) authentication |
OIDC_GROUPS_CLAIM | Setting oidcGroupsClaimClaim name to read group memberships from for role mapping (default: groups) |
OIDC_ISSUER_URL | Setting oidcIssuerUrlOIDC provider issuer URL |
OIDC_JWKS_ENDPOINT | Setting oidcJwksEndpointOverride OIDC JWKS endpoint |
OIDC_MERGE_ACCOUNTS | Setting oidcMergeAccountsAllow OIDC logins to merge with existing accounts by email |
OIDC_MOBILE_REDIRECT_URIS | Setting oidcMobileRedirectUrisComma-separated allowlist of native app redirect URIs (e.g., arcane-mobile://oidc-callback) |
OIDC_PROVIDER_LOGO_URL | Setting oidcProviderLogoUrlCustom logo URL for the OIDC provider |
OIDC_PROVIDER_NAME | Setting oidcProviderNameCustom name for the OIDC provider (e.g., Authentik, Keycloak) |
OIDC_SCOPES | Setting oidcScopesOIDC scopes to request |
OIDC_SKIP_TLS_VERIFY | Setting oidcSkipTlsVerifySkip TLS verification for OIDC provider |
OIDC_TOKEN_ENDPOINT | Setting oidcTokenEndpointOverride OIDC token endpoint |
OIDC_USERINFO_ENDPOINT | Setting oidcUserinfoEndpointOverride OIDC userinfo endpoint |
BUILDS_DIRECTORY | Setting buildsDirectoryRoot directory for manual build workspaces |
BUILD_PROVIDER | Setting buildProviderDefault build provider (local or depot) |
BUILD_TIMEOUT | Setting buildTimeoutTimeout for BuildKit builds in seconds (default: 1800 = 30 minutes) |
DEPOT_PROJECT_ID | Setting depotProjectIdDepot project identifier |
DEPOT_TOKEN | Setting depotTokenDepot API token Sensitive |
BASE_SERVER_URL | Setting baseServerUrlSet the base URL for the application Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DEFAULT_SHELL | Setting defaultShellDefault shell to use for commands Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DISK_USAGE_PATH | Setting diskUsagePathPath used for disk usage calculations Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EXPERIMENTAL_FEATURES_ENABLED | Setting experimentalFeaturesEnabledEnable experimental features that may change or be removed in future releases Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
FEATURE_VULNERABILITY_MANAGEMENT_ENABLED | Setting featureVulnerabilityManagementEnabledEnable vulnerability management for this environment. Disabling retains reports and configuration and leaves standalone image patching available Disabling retains existing reports and scanner settings, allows active work to finish, and leaves standalone image patching available. |
FOLLOW_PROJECT_SYMLINKS | Setting followProjectSymlinksTreat symlinked child directories inside the projects directory as Docker Compose projects |
GIT_SYNC_MAX_BINARY_SIZE_MB | Setting gitSyncMaxBinarySizeMbMaximum size in MB for a single binary file copied during a Git sync. Set 0 to disable the environment cap (default: 10) |
GIT_SYNC_MAX_FILES | Setting gitSyncMaxFilesMaximum number of repository files copied during a Git sync. Set 0 to disable the environment cap (default: 500) |
GIT_SYNC_MAX_TOTAL_SIZE_MB | Setting gitSyncMaxTotalSizeMbMaximum combined size in MB for files copied during a Git sync. Set 0 to disable the environment cap (default: 50) |
AUTO_HEAL_ENABLED | Setting autoHealEnabledAutomatically restart containers that become unhealthy Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_HEAL_EXCLUDED_CONTAINERS | Setting autoHealExcludedContainersComma-separated list of containers to exclude from auto-heal Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_HEAL_MAX_RESTARTS | Setting autoHealMaxRestartsMaximum auto-heal restarts per container within the restart window (default: 5) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_HEAL_RESTART_WINDOW | Setting autoHealRestartWindowTime window in minutes for counting auto-heal restarts (default: 30) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_INJECT_ENV | Setting autoInjectEnvAutomatically inject project .env variables into all containers (default: false) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE | Setting autoUpdateAutomatically update containers when new images are available Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE_EXCLUDED_CONTAINERS | Setting autoUpdateExcludedContainersComma-separated list of containers to exclude from auto-update Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE_INTERVAL | Setting autoUpdateIntervalHow often to check for automatic updates (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_UPDATE=true to have effect at runtime. |
DEFAULT_DEPLOY_PULL_POLICY | Setting defaultDeployPullPolicyDefault image pull policy when deploying projects Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DOCKER_CLIENT_REFRESH_INTERVAL | Setting dockerClientRefreshIntervalHow often to refresh the cached Docker client API version (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DOCKER_HOST | Setting dockerHostURI for Docker daemon |
IMAGE_EVENT_WATCHER_ENABLED | Setting imageEventWatcherEnabledCheck image registries immediately after Docker image events Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
MAX_IMAGE_UPLOAD_SIZE | Setting maxImageUploadSizeMaximum size in MB for image archive uploads (default: 500) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
POLLING_ENABLED | Setting pollingEnabledEnable automatic checking for image updates Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
POLLING_INTERVAL | Setting pollingIntervalHow often to check for image updates (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
PROJECTS_DIRECTORY | Setting projectsDirectoryConfigure where project files are stored |
PRUNE_BUILD_CACHE_MODE | Setting pruneBuildCacheModeSelect how build cache should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_BUILD_CACHE_UNTIL | Setting pruneBuildCacheUntilDuration threshold for scheduled build cache prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_BUILD_CACHE_MODE=olderThan to have effect at runtime. |
PRUNE_CONTAINER_MODE | Setting pruneContainerModeSelect how containers should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_CONTAINER_UNTIL | Setting pruneContainerUntilDuration threshold for scheduled container prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_CONTAINER_MODE=olderThan to have effect at runtime. |
PRUNE_IMAGE_MODE | Setting pruneImageModeSelect how images should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_IMAGE_UNTIL | Setting pruneImageUntilDuration threshold for scheduled image prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_IMAGE_MODE=olderThan to have effect at runtime. |
PRUNE_NETWORK_MODE | Setting pruneNetworkModeSelect how networks should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_NETWORK_UNTIL | Setting pruneNetworkUntilDuration threshold for scheduled network prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_NETWORK_MODE=olderThan to have effect at runtime. |
PRUNE_VOLUME_MODE | Setting pruneVolumeModeSelect how volumes should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
SCHEDULED_PRUNE_ENABLED | Setting scheduledPruneEnabledEnable scheduled pruning of unused Docker resources Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
SCHEDULED_PRUNE_INTERVAL | Setting scheduledPruneIntervalHow often to run scheduled prunes (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
SWARM_STACK_SOURCES_DIRECTORY | Setting swarmStackSourcesDirectoryConfigure where swarm stack source files are stored |
TEMPLATES_DIRECTORY | Setting templatesDirectoryConfigure where local compose template folders are discovered |
TOOLS_IMAGE_REGISTRY | Setting toolsImageRegistryContainer registry used to pull the Arcane tools helper image |
UPDATE_CHECK_REGISTRY | Setting updateCheckRegistryRegistry queried when checking whether the Arcane image has a newer digest |
VOLUME_HELPER_IDLE_TIMEOUT | Setting volumeHelperIdleTimeoutMinutes a volume helper container may sit idle before automatic removal (default: 10 Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
APNS_ENABLED | Setting apnsEnabledLet users receive native push notifications in the Arcane mobile app Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_AUTO_PATCH_ENABLED | Setting imageAutoPatchEnabledAutomatically patch images whose latest vulnerability scan found fixable OS package vulnerabilities Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_AUTO_PATCH_INTERVAL | Setting imageAutoPatchIntervalHow often to run scheduled image patching (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_ALL_PLATFORMS | Setting imagePatchAllPlatformsPatch every platform in a multi-platform image instead of only the platform this server runs on Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_SUFFIX | Setting imagePatchSuffixSuffix appended to the source tag when patching an image (default: patched) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_TIMEOUT_SEC | Setting imagePatchTimeoutSecTimeout for a single image patch operation in seconds (default: 600) |
LIFECYCLE_DEFAULT_RUNNER_IMAGE | Setting lifecycleDefaultRunnerImageDefault container image used to run GitOps pre-deploy lifecycle scripts when a sync does not override it |
LIFECYCLE_ENABLED | Setting lifecycleEnabledAllow GitOps syncs to configure pre-deploy lifecycle scripts. Disabled by default because scripts are repo-trusted code that runs on every deploy |
LIFECYCLE_MAX_TIMEOUT_SEC | Setting lifecycleMaxTimeoutSecMaximum allowed timeout for lifecycle scripts in seconds (default: 300) |
TRIVY_CONCURRENT_SCAN_CONTAINERS | Setting trivyConcurrentScanContainersMaximum number of concurrent Trivy scan containers for manual and scheduled scans. Minimum 1 |
TRIVY_CONFIG | Setting trivyConfigTrivy configuration file content in YAML format Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
TRIVY_CPU_LIMIT | Setting trivyCpuLimitMaximum CPU cores for Trivy scan containers (supports decimals, e.g. 1.5). Set 0 to disable CPU limit |
TRIVY_DB_REGISTRY | Setting trivyDbRegistryContainer registry used to pull the Trivy vulnerability database artifacts |
TRIVY_IGNORE | Setting trivyIgnoreTrivy ignore file content - one vulnerability ID per line Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
TRIVY_IGNORE_UNFIXED | Setting trivyIgnoreUnfixedOnly report vulnerabilities that have a known fix available. Reduces noise from vulnerabilities you cannot act on. |
TRIVY_MEMORY_LIMIT_MB | Setting trivyMemoryLimitMbMaximum memory for Trivy scan containers in MB. Set 0 to disable memory limit |
TRIVY_NETWORK | Setting trivyNetworkDocker network mode/network name used for Trivy scan containers. Leave empty to inherit Arcane's network automatically. |
TRIVY_PRIVILEGED | Setting trivyPrivilegedRun Trivy scan containers in privileged mode when required by the host security policy |
TRIVY_RESOURCE_LIMITS_ENABLED | Setting trivyResourceLimitsEnabledEnable CPU and memory limits for Trivy scan containers |
TRIVY_SECURITY_OPTS | Setting trivySecurityOptsDocker security options applied to Trivy scan containers. Use commas or new lines to separate entries (for example: label=disable) |
TRIVY_SERVER_ENABLED | Setting trivyServerEnabledScan against a remote Trivy server instead of downloading the vulnerability database locally. Recommended for 32-bit hosts (arm/v7) where the local DB cannot be memory-mapped. |
TRIVY_SERVER_TOKEN | Setting trivyServerTokenOptional authentication token sent to the remote Trivy server. Leave empty if the server requires no token. Sensitive |
TRIVY_SERVER_URL | Setting trivyServerUrlURL of the remote Trivy server (e.g. http://trivy.example.com:4954). Used when client/server mode is enabled. |
VULNERABILITY_SCAN_ENABLED | Setting vulnerabilityScanEnabledEnable scheduled vulnerability scanning of all Docker images Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
VULNERABILITY_SCAN_INTERVAL | Setting vulnerabilityScanIntervalHow often to run scheduled vulnerability scans (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true and VULNERABILITY_SCAN_ENABLED=true to have effect at runtime. |
VULNERABILITY_THREAT_INTEL_ENABLED | Setting vulnerabilityThreatIntelEnabledFetch the CISA KEV catalog and FIRST EPSS scores to prioritize exploited vulnerabilities. Disable for air-gapped installs. Requires: FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true to have effect at runtime. |
DEPLOY_WAIT_TIMEOUT | Setting deployWaitTimeoutTimeout waiting for services to become healthy or complete during a deploy in seconds (default: 600 = 10 minutes) |
DOCKER_API_TIMEOUT | Setting dockerApiTimeoutTimeout for Docker list operations in seconds (default: 30) |
DOCKER_IMAGE_PULL_TIMEOUT | Setting dockerImagePullTimeoutTimeout for Docker image pulls in seconds (default: 600 = 10 minutes) |
GIT_OPERATION_TIMEOUT | Setting gitOperationTimeoutTimeout for Git clone/fetch operations in seconds (default: 300 = 5 minutes) |
HTTP_CLIENT_TIMEOUT | Setting httpClientTimeoutDefault timeout for HTTP requests in seconds (default: 30) |
PROXY_REQUEST_TIMEOUT | Setting proxyRequestTimeoutTimeout for proxied requests in seconds (default: 60) |
REGISTRY_TAG_TIMEOUT | Setting registryTagTimeoutTimeout for listing every tag in a repository during version update checks in seconds (default: 120) |
REGISTRY_TIMEOUT | Setting registryTimeoutTimeout for container registry operations in seconds (default: 30) |
TRIVY_SCAN_TIMEOUT | Setting trivyScanTimeoutTimeout for Trivy image scans in seconds (default: 900 = 15 minutes) |
AVATAR_MAX_UPLOAD_SIZE_MB | Setting avatarMaxUploadSizeMbMaximum size in MB for profile picture uploads (default: 2) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ENABLE_GRAVATAR | Setting enableGravatarEnable Gravatar profile pictures for users Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
Container runtime user
When Arcane runs inside a container, it drops to the built-in non-root user (65532:65532) unless PUID and PGID are set. Arcane treats itself as containerized when ARCANE_IN_CONTAINER=true (set by the official images), when the container variable is non-empty, or when /.dockerenv or /run/.containerenv exists. Outside a container, the process keeps the user it was started as.
Set PUID and PGID if mounted files should belong to a specific host user and group. If you point DOCKER_HOST at a custom Unix socket, Arcane uses that socket path when it adds the runtime user to the socket’s group.
Timezone and scheduled jobs
Arcane’s recurring jobs (image update checks, auto-updates, vulnerability scans, scheduled pruning, GitOps sync, and environment health checks) run on cron-style schedules evaluated in the timezone set by TZ. Set it to an IANA timezone name so jobs run at the local times you expect:
If TZ is unset, Arcane uses the container’s local time, which is UTC on the official images. Job intervals and cron expressions are set in the Settings UI, or through the environment when settings overrides are enabled.
Admin API key bootstrap
Set ADMIN_STATIC_API_KEY when automation needs a known API key from the first start. At startup, Arcane creates or updates a protected admin API key with this value, so you don’t have to create it in the UI. See the API Reference for usage and webhook examples.