Skip to content

Environment Variables

Every environment variable Arcane reads, and which settings you can override from the environment.

This page lists the environment variables Arcane reads at startup. Most settings can also be changed in the Settings UI; use these when you configure Arcane from your Compose file or need a value in place before first start.

75 of 75 variables

VariableDetails
ACTOR_PORT

Maps to the ActorPort config field.

Default3551
ADMIN_STATIC_API_KEY

Maps to the AdminStaticAPIKey config field.

Default—
AGENT_MODE

Maps to the AgentMode config field.

Defaultfalse
AGENT_TOKEN

Maps to the AgentToken config field.

Default—
ALLOW_CLI_MFA_RESET

Maps to the AllowCLIMFAReset config field.

Defaultfalse
ALLOW_CLI_PASSWORD_RESET

Maps to the AllowCLIPasswordReset config field.

Defaultfalse
ALLOW_DOWNGRADE

Maps to the AllowDowngrade config field.

Defaultfalse
ANALYTICS_DISABLED

Maps to the AnalyticsDisabled config field.

Defaultfalse
APNS_KEY_ALGORITHM

Maps to the ApnsKeyAlgorithm config field.

Defaulted25519
APNS_RELAY_URL

Maps to the ApnsRelayUrl config field.

Defaulthttps://apns.getarcane.app
APP_URL

Maps to the AppUrl config field.

Defaulthttp://localhost:3552
ARCANE_BACKUP_VOLUME_NAME

Maps to the BackupVolumeName config field.

Defaultarcane-backups
AUTO_LOGIN_PASSWORD

Maps to the AutoLoginPassword config field.

Defaultarcane-admin
AUTO_LOGIN_USERNAME

Auto-login credentials (used only when built with the buildables tag + autologin feature flag).

Defaultarcane
DATABASE_URL

Maps to the DatabaseURL config field.

Defaultfile:data/arcane.db?_pragma=journal_mode(WAL)&_pragma=busy_timeout(2500)&_txlock=immediate
DIR_PERM

Maps to the DirPerm config field.

Default0755
DOCKER_CONFIG

Maps to the DockerConfig config field.

Default—
DOCKER_HOST

Maps to the DockerHost config field.

Defaultunix:///var/run/docker.sock
EDGE_AGENT

Maps to the EdgeAgent config field.

Defaultfalse
EDGE_MTLS_ASSETS_DIR

Maps to the EdgeMTLSAssetsDir config field.

Default—
EDGE_MTLS_CA_FILE

Maps to the EdgeMTLSCAFile config field.

Default—
EDGE_MTLS_CERT_FILE

Maps to the EdgeMTLSCertFile config field.

Default—
EDGE_MTLS_KEY_FILE

Maps to the EdgeMTLSKeyFile config field.

Default—
EDGE_MTLS_MODE

Maps to the EdgeMTLSMode config field.

Defaultdisabled
EDGE_MTLS_SERVER_NAME

Maps to the EdgeMTLSServerName config field.

Default—
EDGE_RECONNECT_INTERVAL

seconds

Default5
EDGE_TRANSPORT

Maps to the EdgeTransport config field.

Defaultauto
ENCRYPTION_KEY

Maps to the EncryptionKey config field.

Defaultarcane-dev-key-32-characters!!!
ENVIRONMENT

Maps to the Environment config field.

Defaultproduction
FILE_PERM

Maps to the FilePerm config field.

Default0644
GIT_WORK_DIR

Maps to the GitWorkDir config field.

Defaultdata/git
GPU_MONITORING_ENABLED

Maps to the GPUMonitoringEnabled config field.

Defaultfalse
GPU_TYPE

Maps to the GPUType config field.

Defaultauto
HTTPS_PROXY

Maps to the HTTPSProxy config field.

Default—
HTTP_CLIENT_TIMEOUT

Maps to the HTTPClientTimeout config field.

Default0
HTTP_PROXY

Maps to the HTTPProxy config field.

Default—
JWT_REFRESH_EXPIRY

Maps to the JWTRefreshExpiry config field.

Default168h
JWT_SECRET

Maps to the JWTSecret config field.

Deprecated
Default—
LISTEN

Maps to the Listen config field.

Default—
LOG_JSON

Maps to the LogJson config field.

Defaultfalse
LOG_LEVEL

Maps to the LogLevel config field.

Defaultinfo
MANAGER_API_URL

Maps to the ManagerApiUrl config field.

Default—
NO_PROXY

Maps to the NoProxy config field.

Default—
OIDC_AUTO_REDIRECT_TO_PROVIDER

Maps to the OidcAutoRedirectToProvider config field.

Defaultfalse
OIDC_CLIENT_ID

Maps to the OidcClientID config field.

Default—
OIDC_CLIENT_SECRET

Maps to the OidcClientSecret config field.

Default—
OIDC_ENABLED

Maps to the OidcEnabled config field.

Defaultfalse
OIDC_GROUPS_CLAIM

Maps to the OidcGroupsClaim config field.

Defaultgroups
OIDC_ISSUER_URL

Maps to the OidcIssuerURL config field.

Default—
OIDC_MOBILE_REDIRECT_URIS

Maps to the OidcMobileRedirectUris config field.

Defaultarcane-mobile://oidc-callback
OIDC_PROVIDER_LOGO_URL

Maps to the OidcProviderLogoUrl config field.

Default—
OIDC_PROVIDER_NAME

Maps to the OidcProviderName config field.

Default—
OIDC_ROLE_MAPPINGS

Maps to the OidcRoleMappings config field.

Default—
OIDC_SCOPES

Maps to the OidcScopes config field.

Defaultopenid email profile
OIDC_SKIP_TLS_VERIFY

Maps to the OidcSkipTlsVerify config field.

Defaultfalse
PGID

Maps to the PGID config field.

Default—
PORT

Maps to the Port config field.

Default3552
PROJECTS_DIRECTORY

Maps to the ProjectsDirectory config field.

Default/app/data/projects
PROJECT_SCAN_MAX_DEPTH

Maps to the ProjectScanMaxDepth config field.

Default3
PROJECT_SCAN_SKIP_DIRS

Maps to the ProjectScanSkipDirs config field.

Default.git,node_modules,vendor,.venv,venv,__pycache__,.cache,dist,build,target,.next,.nuxt,.svelte-kit
PROJECT_WORKSPACE_MAX_DEPTH

Maps to the ProjectWorkspaceMaxDepth config field.

Default20
PROJECT_WORKSPACE_MAX_ENTRIES

Maps to the ProjectWorkspaceMaxEntries config field.

Default2000
PROJECT_WORKSPACE_MAX_FILE_SIZE_MB

Maps to the ProjectWorkspaceMaxFileSizeMB config field.

Default10
PUID

Maps to the PUID config field.

Default—
TEMPLATES_DIRECTORY

Maps to the TemplatesDirectory config field.

Default/app/data/templates
TLS_CERT_FILE

Maps to the TLSCertFile config field.

Default—
TLS_ENABLED

Maps to the TLSEnabled config field.

Defaultfalse
TLS_KEY_FILE

Maps to the TLSKeyFile config field.

Default—
TRUSTED_PROXIES

Maps to the TrustedProxies config field.

Default—
TZ

Maps to the Timezone config field.

DefaultLocal
UI_CONFIGURATION_DISABLED

Maps to the UIConfigurationDisabled config field.

Defaultfalse
UPDATE_CHECK_DISABLED

Maps to the UpdateCheckDisabled config field.

Defaultfalse
VOLUME_WORKSPACE_MAX_DEPTH

Maps to the VolumeWorkspaceMaxDepth config field.

Default50
VOLUME_WORKSPACE_MAX_ENTRIES

Maps to the VolumeWorkspaceMaxEntries config field.

Default10000
VOLUME_WORKSPACE_MAX_FILE_SIZE_MB

Maps to the VolumeWorkspaceMaxFileSizeMB config field.

Default10

To use an external Postgres database through DATABASE_URL, see Installation, which has the connection string format.

The overrides below only take effect when UI_CONFIGURATION_DISABLED=true or AGENT_MODE=true is set. Otherwise Arcane ignores them.

112 of 112 setting overrides

Env VarDetails
AUTO_HEAL_INTERVAL
SettingautoHealInterval

How often to check container health (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.

ENVIRONMENT_HEALTH_INTERVAL
SettingenvironmentHealthInterval

How often to check environment connectivity (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

EVENT_CLEANUP_INTERVAL
SettingeventCleanupInterval

How often to delete old events (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

EXPIRED_SESSIONS_CLEANUP_INTERVAL
SettingexpiredSessionsCleanupInterval

How often to delete expired and old revoked sessions (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

ACTIVITY_HISTORY_MAX_ENTRIES
SettingactivityHistoryMaxEntries

Maximum completed Activity Center entries to keep per environment. Set 0 to disable count-based cleanup.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

ACTIVITY_HISTORY_RETENTION_DAYS
SettingactivityHistoryRetentionDays

Delete completed Activity Center entries older than this many days. Set 0 to disable age-based cleanup.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

MAX_CONCURRENT_ACTIVITIES
SettingmaxConcurrentActivities

Maximum long-running activities per environment before new ones queue. Set 0 for unlimited.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

UPGRADE_LOG_RETENTION_DAYS
SettingupgradeLogRetentionDays

Delete upgrade log files older than this many days. Cleanup runs hourly. Default: 3 days. Set 0 to keep logs indefinitely.

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTH_LOCAL_ENABLED
SettingauthLocalEnabled

Enable local username/password authentication

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTH_PASSWORD_POLICY
SettingauthPasswordPolicy

Set password strength requirements

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTH_SESSION_TIMEOUT
SettingauthSessionTimeout

How long user sessions remain active

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

OIDC_AUTHORIZATION_ENDPOINT
SettingoidcAuthorizationEndpoint

Override OIDC authorization endpoint

OIDC_AUTO_REDIRECT_TO_PROVIDER
SettingoidcAutoRedirectToProvider

Automatically redirect to OIDC provider on login page

OIDC_CLIENT_ID
SettingoidcClientId

OIDC provider client ID

OIDC_CLIENT_SECRET
SettingoidcClientSecret

OIDC provider client secret

Sensitive
OIDC_DEVICE_AUTHORIZATION_ENDPOINT
SettingoidcDeviceAuthorizationEndpoint

Override OIDC device authorization endpoint for CLI authentication

OIDC_ENABLED
SettingoidcEnabled

Enable OpenID Connect (OIDC) authentication

OIDC_GROUPS_CLAIM
SettingoidcGroupsClaim

Claim name to read group memberships from for role mapping (default: groups)

OIDC_ISSUER_URL
SettingoidcIssuerUrl

OIDC provider issuer URL

OIDC_JWKS_ENDPOINT
SettingoidcJwksEndpoint

Override OIDC JWKS endpoint

OIDC_MERGE_ACCOUNTS
SettingoidcMergeAccounts

Allow OIDC logins to merge with existing accounts by email

OIDC_MOBILE_REDIRECT_URIS
SettingoidcMobileRedirectUris

Comma-separated allowlist of native app redirect URIs (e.g., arcane-mobile://oidc-callback)

OIDC_PROVIDER_LOGO_URL
SettingoidcProviderLogoUrl

Custom logo URL for the OIDC provider

OIDC_PROVIDER_NAME
SettingoidcProviderName

Custom name for the OIDC provider (e.g., Authentik, Keycloak)

OIDC_SCOPES
SettingoidcScopes

OIDC scopes to request

OIDC_SKIP_TLS_VERIFY
SettingoidcSkipTlsVerify

Skip TLS verification for OIDC provider

OIDC_TOKEN_ENDPOINT
SettingoidcTokenEndpoint

Override OIDC token endpoint

OIDC_USERINFO_ENDPOINT
SettingoidcUserinfoEndpoint

Override OIDC userinfo endpoint

BUILDS_DIRECTORY
SettingbuildsDirectory

Root directory for manual build workspaces

BUILD_PROVIDER
SettingbuildProvider

Default build provider (local or depot)

BUILD_TIMEOUT
SettingbuildTimeout

Timeout for BuildKit builds in seconds (default: 1800 = 30 minutes)

DEPOT_PROJECT_ID
SettingdepotProjectId

Depot project identifier

DEPOT_TOKEN
SettingdepotToken

Depot API token

Sensitive
BASE_SERVER_URL
SettingbaseServerUrl

Set the base URL for the application

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

DEFAULT_SHELL
SettingdefaultShell

Default shell to use for commands

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

DISK_USAGE_PATH
SettingdiskUsagePath

Path used for disk usage calculations

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

EXPERIMENTAL_FEATURES_ENABLED
SettingexperimentalFeaturesEnabled

Enable experimental features that may change or be removed in future releases

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

FEATURE_SWARM_ENABLED
SettingfeatureSwarmEnabled

Show Docker Swarm for this environment. An active swarm cluster keeps it enabled

An active swarm cluster keeps Swarm enabled regardless of this value.

FEATURE_VULNERABILITY_MANAGEMENT_ENABLED
SettingfeatureVulnerabilityManagementEnabled

Enable vulnerability management for this environment. Disabling retains reports and configuration and leaves standalone image patching available

Disabling retains existing reports and scanner settings, allows active work to finish, and leaves standalone image patching available.

FOLLOW_PROJECT_SYMLINKS
SettingfollowProjectSymlinks

Treat symlinked child directories inside the projects directory as Docker Compose projects

GIT_SYNC_MAX_BINARY_SIZE_MB
SettinggitSyncMaxBinarySizeMb

Maximum size in MB for a single binary file copied during a Git sync. Set 0 to disable the environment cap (default: 10)

GIT_SYNC_MAX_FILES
SettinggitSyncMaxFiles

Maximum number of repository files copied during a Git sync. Set 0 to disable the environment cap (default: 500)

GIT_SYNC_MAX_TOTAL_SIZE_MB
SettinggitSyncMaxTotalSizeMb

Maximum combined size in MB for files copied during a Git sync. Set 0 to disable the environment cap (default: 50)

AUTO_HEAL_ENABLED
SettingautoHealEnabled

Automatically restart containers that become unhealthy

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTO_HEAL_EXCLUDED_CONTAINERS
SettingautoHealExcludedContainers

Comma-separated list of containers to exclude from auto-heal

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.

AUTO_HEAL_MAX_RESTARTS
SettingautoHealMaxRestarts

Maximum auto-heal restarts per container within the restart window (default: 5)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.

AUTO_HEAL_RESTART_WINDOW
SettingautoHealRestartWindow

Time window in minutes for counting auto-heal restarts (default: 30)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime.

AUTO_INJECT_ENV
SettingautoInjectEnv

Automatically inject project .env variables into all containers (default: false)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTO_UPDATE
SettingautoUpdate

Automatically update containers when new images are available

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTO_UPDATE_EXCLUDED_CONTAINERS
SettingautoUpdateExcludedContainers

Comma-separated list of containers to exclude from auto-update

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

AUTO_UPDATE_INTERVAL
SettingautoUpdateInterval

How often to check for automatic updates (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_UPDATE=true to have effect at runtime.

DEFAULT_DEPLOY_PULL_POLICY
SettingdefaultDeployPullPolicy

Default image pull policy when deploying projects

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

DOCKER_CLIENT_REFRESH_INTERVAL
SettingdockerClientRefreshInterval

How often to refresh the cached Docker client API version (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

DOCKER_HOST
SettingdockerHost

URI for Docker daemon

IMAGE_EVENT_WATCHER_ENABLED
SettingimageEventWatcherEnabled

Check image registries immediately after Docker image events

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

MAX_IMAGE_UPLOAD_SIZE
SettingmaxImageUploadSize

Maximum size in MB for image archive uploads (default: 500)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

POLLING_ENABLED
SettingpollingEnabled

Enable automatic checking for image updates

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

POLLING_INTERVAL
SettingpollingInterval

How often to check for image updates (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

PROJECTS_DIRECTORY
SettingprojectsDirectory

Configure where project files are stored

PRUNE_BUILD_CACHE_MODE
SettingpruneBuildCacheMode

Select how build cache should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

PRUNE_BUILD_CACHE_UNTIL
SettingpruneBuildCacheUntil

Duration threshold for scheduled build cache prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_BUILD_CACHE_MODE=olderThan to have effect at runtime.

PRUNE_CONTAINER_MODE
SettingpruneContainerMode

Select how containers should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

PRUNE_CONTAINER_UNTIL
SettingpruneContainerUntil

Duration threshold for scheduled container prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_CONTAINER_MODE=olderThan to have effect at runtime.

PRUNE_IMAGE_MODE
SettingpruneImageMode

Select how images should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

PRUNE_IMAGE_UNTIL
SettingpruneImageUntil

Duration threshold for scheduled image prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_IMAGE_MODE=olderThan to have effect at runtime.

PRUNE_NETWORK_MODE
SettingpruneNetworkMode

Select how networks should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

PRUNE_NETWORK_UNTIL
SettingpruneNetworkUntil

Duration threshold for scheduled network prune when mode is olderThan

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_NETWORK_MODE=olderThan to have effect at runtime.

PRUNE_VOLUME_MODE
SettingpruneVolumeMode

Select how volumes should be pruned when the scheduled prune job runs

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

SCHEDULED_PRUNE_ENABLED
SettingscheduledPruneEnabled

Enable scheduled pruning of unused Docker resources

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

SCHEDULED_PRUNE_INTERVAL
SettingscheduledPruneInterval

How often to run scheduled prunes (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime.

SWARM_STACK_SOURCES_DIRECTORY
SettingswarmStackSourcesDirectory

Configure where swarm stack source files are stored

TEMPLATES_DIRECTORY
SettingtemplatesDirectory

Configure where local compose template folders are discovered

TOOLS_IMAGE_REGISTRY
SettingtoolsImageRegistry

Container registry used to pull the Arcane tools helper image

UPDATE_CHECK_REGISTRY
SettingupdateCheckRegistry

Registry queried when checking whether the Arcane image has a newer digest

VOLUME_HELPER_IDLE_TIMEOUT
SettingvolumeHelperIdleTimeout

Minutes a volume helper container may sit idle before automatic removal (default: 10

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

APNS_ENABLED
SettingapnsEnabled

Let users receive native push notifications in the Arcane mobile app

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

IMAGE_AUTO_PATCH_ENABLED
SettingimageAutoPatchEnabled

Automatically patch images whose latest vulnerability scan found fixable OS package vulnerabilities

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

IMAGE_AUTO_PATCH_INTERVAL
SettingimageAutoPatchInterval

How often to run scheduled image patching (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

IMAGE_PATCH_ALL_PLATFORMS
SettingimagePatchAllPlatforms

Patch every platform in a multi-platform image instead of only the platform this server runs on

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

IMAGE_PATCH_SUFFIX
SettingimagePatchSuffix

Suffix appended to the source tag when patching an image (default: patched)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

IMAGE_PATCH_TIMEOUT_SEC
SettingimagePatchTimeoutSec

Timeout for a single image patch operation in seconds (default: 600)

LIFECYCLE_DEFAULT_RUNNER_IMAGE
SettinglifecycleDefaultRunnerImage

Default container image used to run GitOps pre-deploy lifecycle scripts when a sync does not override it

LIFECYCLE_ENABLED
SettinglifecycleEnabled

Allow GitOps syncs to configure pre-deploy lifecycle scripts. Disabled by default because scripts are repo-trusted code that runs on every deploy

LIFECYCLE_MAX_TIMEOUT_SEC
SettinglifecycleMaxTimeoutSec

Maximum allowed timeout for lifecycle scripts in seconds (default: 300)

TRIVY_CONCURRENT_SCAN_CONTAINERS
SettingtrivyConcurrentScanContainers

Maximum number of concurrent Trivy scan containers for manual and scheduled scans. Minimum 1

TRIVY_CONFIG
SettingtrivyConfig

Trivy configuration file content in YAML format

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

TRIVY_CPU_LIMIT
SettingtrivyCpuLimit

Maximum CPU cores for Trivy scan containers (supports decimals, e.g. 1.5). Set 0 to disable CPU limit

TRIVY_DB_REGISTRY
SettingtrivyDbRegistry

Container registry used to pull the Trivy vulnerability database artifacts

TRIVY_IGNORE
SettingtrivyIgnore

Trivy ignore file content - one vulnerability ID per line

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

TRIVY_IGNORE_UNFIXED
SettingtrivyIgnoreUnfixed

Only report vulnerabilities that have a known fix available. Reduces noise from vulnerabilities you cannot act on.

TRIVY_MEMORY_LIMIT_MB
SettingtrivyMemoryLimitMb

Maximum memory for Trivy scan containers in MB. Set 0 to disable memory limit

TRIVY_NETWORK
SettingtrivyNetwork

Docker network mode/network name used for Trivy scan containers. Leave empty to inherit Arcane's network automatically.

TRIVY_PRIVILEGED
SettingtrivyPrivileged

Run Trivy scan containers in privileged mode when required by the host security policy

TRIVY_RESOURCE_LIMITS_ENABLED
SettingtrivyResourceLimitsEnabled

Enable CPU and memory limits for Trivy scan containers

TRIVY_SECURITY_OPTS
SettingtrivySecurityOpts

Docker security options applied to Trivy scan containers. Use commas or new lines to separate entries (for example: label=disable)

TRIVY_SERVER_ENABLED
SettingtrivyServerEnabled

Scan against a remote Trivy server instead of downloading the vulnerability database locally. Recommended for 32-bit hosts (arm/v7) where the local DB cannot be memory-mapped.

TRIVY_SERVER_TOKEN
SettingtrivyServerToken

Optional authentication token sent to the remote Trivy server. Leave empty if the server requires no token.

Sensitive
TRIVY_SERVER_URL
SettingtrivyServerUrl

URL of the remote Trivy server (e.g. http://trivy.example.com:4954). Used when client/server mode is enabled.

VULNERABILITY_SCAN_ENABLED
SettingvulnerabilityScanEnabled

Enable scheduled vulnerability scanning of all Docker images

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

VULNERABILITY_SCAN_INTERVAL
SettingvulnerabilityScanInterval

How often to run scheduled vulnerability scans (cron expression)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true and VULNERABILITY_SCAN_ENABLED=true to have effect at runtime.

VULNERABILITY_THREAT_INTEL_ENABLED
SettingvulnerabilityThreatIntelEnabled

Fetch the CISA KEV catalog and FIRST EPSS scores to prioritize exploited vulnerabilities. Disable for air-gapped installs.

Requires: FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true to have effect at runtime.

DEPLOY_WAIT_TIMEOUT
SettingdeployWaitTimeout

Timeout waiting for services to become healthy or complete during a deploy in seconds (default: 600 = 10 minutes)

DOCKER_API_TIMEOUT
SettingdockerApiTimeout

Timeout for Docker list operations in seconds (default: 30)

DOCKER_IMAGE_PULL_TIMEOUT
SettingdockerImagePullTimeout

Timeout for Docker image pulls in seconds (default: 600 = 10 minutes)

GIT_OPERATION_TIMEOUT
SettinggitOperationTimeout

Timeout for Git clone/fetch operations in seconds (default: 300 = 5 minutes)

HTTP_CLIENT_TIMEOUT
SettinghttpClientTimeout

Default timeout for HTTP requests in seconds (default: 30)

PROXY_REQUEST_TIMEOUT
SettingproxyRequestTimeout

Timeout for proxied requests in seconds (default: 60)

REGISTRY_TAG_TIMEOUT
SettingregistryTagTimeout

Timeout for listing every tag in a repository during version update checks in seconds (default: 120)

REGISTRY_TIMEOUT
SettingregistryTimeout

Timeout for container registry operations in seconds (default: 30)

TRIVY_SCAN_TIMEOUT
SettingtrivyScanTimeout

Timeout for Trivy image scans in seconds (default: 900 = 15 minutes)

AVATAR_MAX_UPLOAD_SIZE_MB
SettingavatarMaxUploadSizeMb

Maximum size in MB for profile picture uploads (default: 2)

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

ENABLE_GRAVATAR
SettingenableGravatar

Enable Gravatar profile pictures for users

Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env.

When Arcane runs inside a container, it drops to the built-in non-root user (65532:65532) unless PUID and PGID are set. Arcane treats itself as containerized when ARCANE_IN_CONTAINER=true (set by the official images), when the container variable is non-empty, or when /.dockerenv or /run/.containerenv exists. Outside a container, the process keeps the user it was started as.

Set PUID and PGID if mounted files should belong to a specific host user and group. If you point DOCKER_HOST at a custom Unix socket, Arcane uses that socket path when it adds the runtime user to the socket’s group.

Arcane’s recurring jobs (image update checks, auto-updates, vulnerability scans, scheduled pruning, GitOps sync, and environment health checks) run on cron-style schedules evaluated in the timezone set by TZ. Set it to an IANA timezone name so jobs run at the local times you expect:

Terminal window
TZ=America/New_York

If TZ is unset, Arcane uses the container’s local time, which is UTC on the official images. Job intervals and cron expressions are set in the Settings UI, or through the environment when settings overrides are enabled.

Set ADMIN_STATIC_API_KEY when automation needs a known API key from the first start. At startup, Arcane creates or updates a protected admin API key with this value, so you don’t have to create it in the UI. See the API Reference for usage and webhook examples.