Environment Variables
Every environment variable Arcane reads, and which settings you can override from the environment.
This page lists the environment variables Arcane reads at startup. Most settings can also be changed in the Settings UI; use these when you configure Arcane from your Compose file or need a value in place before first start.
75 of 75 variables
| Variable | Details |
|---|---|
ACTOR_PORT | Maps to the ActorPort config field. |
ADMIN_STATIC_API_KEY | Maps to the AdminStaticAPIKey config field. |
AGENT_MODE | Maps to the AgentMode config field. |
AGENT_TOKEN | Maps to the AgentToken config field. |
ALLOW_CLI_MFA_RESET | Maps to the AllowCLIMFAReset config field. |
ALLOW_CLI_PASSWORD_RESET | Maps to the AllowCLIPasswordReset config field. |
ALLOW_DOWNGRADE | Maps to the AllowDowngrade config field. |
ANALYTICS_DISABLED | Maps to the AnalyticsDisabled config field. |
APNS_KEY_ALGORITHM | Maps to the ApnsKeyAlgorithm config field. |
APNS_RELAY_URL | Maps to the ApnsRelayUrl config field. |
APP_URL | Maps to the AppUrl config field. |
ARCANE_BACKUP_VOLUME_NAME | Maps to the BackupVolumeName config field. |
AUTO_LOGIN_PASSWORD | Maps to the AutoLoginPassword config field. |
AUTO_LOGIN_USERNAME | Auto-login credentials (used only when built with the buildables tag + autologin feature flag). |
DATABASE_URL | Maps to the DatabaseURL config field. |
DIR_PERM | Maps to the DirPerm config field. |
DOCKER_CONFIG | Maps to the DockerConfig config field. |
DOCKER_HOST | Maps to the DockerHost config field. |
EDGE_AGENT | Maps to the EdgeAgent config field. |
EDGE_MTLS_ASSETS_DIR | Maps to the EdgeMTLSAssetsDir config field. |
EDGE_MTLS_CA_FILE | Maps to the EdgeMTLSCAFile config field. |
EDGE_MTLS_CERT_FILE | Maps to the EdgeMTLSCertFile config field. |
EDGE_MTLS_KEY_FILE | Maps to the EdgeMTLSKeyFile config field. |
EDGE_MTLS_MODE | Maps to the EdgeMTLSMode config field. |
EDGE_MTLS_SERVER_NAME | Maps to the EdgeMTLSServerName config field. |
EDGE_RECONNECT_INTERVAL | seconds |
EDGE_TRANSPORT | Maps to the EdgeTransport config field. |
ENCRYPTION_KEY | Maps to the EncryptionKey config field. |
ENVIRONMENT | Maps to the Environment config field. |
FILE_PERM | Maps to the FilePerm config field. |
GIT_WORK_DIR | Maps to the GitWorkDir config field. |
GPU_MONITORING_ENABLED | Maps to the GPUMonitoringEnabled config field. |
GPU_TYPE | Maps to the GPUType config field. |
HTTPS_PROXY | Maps to the HTTPSProxy config field. |
HTTP_CLIENT_TIMEOUT | Maps to the HTTPClientTimeout config field. |
HTTP_PROXY | Maps to the HTTPProxy config field. |
JWT_REFRESH_EXPIRY | Maps to the JWTRefreshExpiry config field. |
JWT_SECRET | Maps to the JWTSecret config field. Deprecated |
LISTEN | Maps to the Listen config field. |
LOG_JSON | Maps to the LogJson config field. |
LOG_LEVEL | Maps to the LogLevel config field. |
MANAGER_API_URL | Maps to the ManagerApiUrl config field. |
NO_PROXY | Maps to the NoProxy config field. |
OIDC_AUTO_REDIRECT_TO_PROVIDER | Maps to the OidcAutoRedirectToProvider config field. |
OIDC_CLIENT_ID | Maps to the OidcClientID config field. |
OIDC_CLIENT_SECRET | Maps to the OidcClientSecret config field. |
OIDC_ENABLED | Maps to the OidcEnabled config field. |
OIDC_GROUPS_CLAIM | Maps to the OidcGroupsClaim config field. |
OIDC_ISSUER_URL | Maps to the OidcIssuerURL config field. |
OIDC_MOBILE_REDIRECT_URIS | Maps to the OidcMobileRedirectUris config field. |
OIDC_PROVIDER_LOGO_URL | Maps to the OidcProviderLogoUrl config field. |
OIDC_PROVIDER_NAME | Maps to the OidcProviderName config field. |
OIDC_ROLE_MAPPINGS | Maps to the OidcRoleMappings config field. |
OIDC_SCOPES | Maps to the OidcScopes config field. |
OIDC_SKIP_TLS_VERIFY | Maps to the OidcSkipTlsVerify config field. |
PGID | Maps to the PGID config field. |
PORT | Maps to the Port config field. |
PROJECTS_DIRECTORY | Maps to the ProjectsDirectory config field. |
PROJECT_SCAN_MAX_DEPTH | Maps to the ProjectScanMaxDepth config field. |
PROJECT_SCAN_SKIP_DIRS | Maps to the ProjectScanSkipDirs config field. |
PROJECT_WORKSPACE_MAX_DEPTH | Maps to the ProjectWorkspaceMaxDepth config field. |
PROJECT_WORKSPACE_MAX_ENTRIES | Maps to the ProjectWorkspaceMaxEntries config field. |
PROJECT_WORKSPACE_MAX_FILE_SIZE_MB | Maps to the ProjectWorkspaceMaxFileSizeMB config field. |
PUID | Maps to the PUID config field. |
TEMPLATES_DIRECTORY | Maps to the TemplatesDirectory config field. |
TLS_CERT_FILE | Maps to the TLSCertFile config field. |
TLS_ENABLED | Maps to the TLSEnabled config field. |
TLS_KEY_FILE | Maps to the TLSKeyFile config field. |
TRUSTED_PROXIES | Maps to the TrustedProxies config field. |
TZ | Maps to the Timezone config field. |
UI_CONFIGURATION_DISABLED | Maps to the UIConfigurationDisabled config field. |
UPDATE_CHECK_DISABLED | Maps to the UpdateCheckDisabled config field. |
VOLUME_WORKSPACE_MAX_DEPTH | Maps to the VolumeWorkspaceMaxDepth config field. |
VOLUME_WORKSPACE_MAX_ENTRIES | Maps to the VolumeWorkspaceMaxEntries config field. |
VOLUME_WORKSPACE_MAX_FILE_SIZE_MB | Maps to the VolumeWorkspaceMaxFileSizeMB config field. |
No variables match. Try a shorter name or clear the search.
To use an external Postgres database through DATABASE_URL, see Installation, which has the connection string format.
Settings overrides
Section titled “Settings overrides”The overrides below only take effect when UI_CONFIGURATION_DISABLED=true or AGENT_MODE=true is set. Otherwise Arcane ignores them.
112 of 112 setting overrides
| Env Var | Details |
|---|---|
AUTO_HEAL_INTERVAL | How often to check container health (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
ENVIRONMENT_HEALTH_INTERVAL | How often to check environment connectivity (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EVENT_CLEANUP_INTERVAL | How often to delete old events (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EXPIRED_SESSIONS_CLEANUP_INTERVAL | How often to delete expired and old revoked sessions (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ACTIVITY_HISTORY_MAX_ENTRIES | Maximum completed Activity Center entries to keep per environment. Set 0 to disable count-based cleanup. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ACTIVITY_HISTORY_RETENTION_DAYS | Delete completed Activity Center entries older than this many days. Set 0 to disable age-based cleanup. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
MAX_CONCURRENT_ACTIVITIES | Maximum long-running activities per environment before new ones queue. Set 0 for unlimited. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
UPGRADE_LOG_RETENTION_DAYS | Delete upgrade log files older than this many days. Cleanup runs hourly. Default: 3 days. Set 0 to keep logs indefinitely. Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_LOCAL_ENABLED | Enable local username/password authentication Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_PASSWORD_POLICY | Set password strength requirements Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTH_SESSION_TIMEOUT | How long user sessions remain active Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
OIDC_AUTHORIZATION_ENDPOINT | Override OIDC authorization endpoint |
OIDC_AUTO_REDIRECT_TO_PROVIDER | Automatically redirect to OIDC provider on login page |
OIDC_CLIENT_ID | OIDC provider client ID |
OIDC_CLIENT_SECRET | OIDC provider client secret Sensitive |
OIDC_DEVICE_AUTHORIZATION_ENDPOINT | Override OIDC device authorization endpoint for CLI authentication |
OIDC_ENABLED | Enable OpenID Connect (OIDC) authentication |
OIDC_GROUPS_CLAIM | Claim name to read group memberships from for role mapping (default: groups) |
OIDC_ISSUER_URL | OIDC provider issuer URL |
OIDC_JWKS_ENDPOINT | Override OIDC JWKS endpoint |
OIDC_MERGE_ACCOUNTS | Allow OIDC logins to merge with existing accounts by email |
OIDC_MOBILE_REDIRECT_URIS | Comma-separated allowlist of native app redirect URIs (e.g., arcane-mobile://oidc-callback) |
OIDC_PROVIDER_LOGO_URL | Custom logo URL for the OIDC provider |
OIDC_PROVIDER_NAME | Custom name for the OIDC provider (e.g., Authentik, Keycloak) |
OIDC_SCOPES | OIDC scopes to request |
OIDC_SKIP_TLS_VERIFY | Skip TLS verification for OIDC provider |
OIDC_TOKEN_ENDPOINT | Override OIDC token endpoint |
OIDC_USERINFO_ENDPOINT | Override OIDC userinfo endpoint |
BUILDS_DIRECTORY | Root directory for manual build workspaces |
BUILD_PROVIDER | Default build provider (local or depot) |
BUILD_TIMEOUT | Timeout for BuildKit builds in seconds (default: 1800 = 30 minutes) |
DEPOT_PROJECT_ID | Depot project identifier |
DEPOT_TOKEN | Depot API token Sensitive |
BASE_SERVER_URL | Set the base URL for the application Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DEFAULT_SHELL | Default shell to use for commands Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DISK_USAGE_PATH | Path used for disk usage calculations Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
EXPERIMENTAL_FEATURES_ENABLED | Enable experimental features that may change or be removed in future releases Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
FEATURE_SWARM_ENABLED | Show Docker Swarm for this environment. An active swarm cluster keeps it enabled An active swarm cluster keeps Swarm enabled regardless of this value. |
FEATURE_VULNERABILITY_MANAGEMENT_ENABLED | Enable vulnerability management for this environment. Disabling retains reports and configuration and leaves standalone image patching available Disabling retains existing reports and scanner settings, allows active work to finish, and leaves standalone image patching available. |
FOLLOW_PROJECT_SYMLINKS | Treat symlinked child directories inside the projects directory as Docker Compose projects |
GIT_SYNC_MAX_BINARY_SIZE_MB | Maximum size in MB for a single binary file copied during a Git sync. Set 0 to disable the environment cap (default: 10) |
GIT_SYNC_MAX_FILES | Maximum number of repository files copied during a Git sync. Set 0 to disable the environment cap (default: 500) |
GIT_SYNC_MAX_TOTAL_SIZE_MB | Maximum combined size in MB for files copied during a Git sync. Set 0 to disable the environment cap (default: 50) |
AUTO_HEAL_ENABLED | Automatically restart containers that become unhealthy Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_HEAL_EXCLUDED_CONTAINERS | Comma-separated list of containers to exclude from auto-heal Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_HEAL_MAX_RESTARTS | Maximum auto-heal restarts per container within the restart window (default: 5) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_HEAL_RESTART_WINDOW | Time window in minutes for counting auto-heal restarts (default: 30) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_HEAL_ENABLED=true to have effect at runtime. |
AUTO_INJECT_ENV | Automatically inject project .env variables into all containers (default: false) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE | Automatically update containers when new images are available Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE_EXCLUDED_CONTAINERS | Comma-separated list of containers to exclude from auto-update Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
AUTO_UPDATE_INTERVAL | How often to check for automatic updates (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. AUTO_UPDATE=true to have effect at runtime. |
DEFAULT_DEPLOY_PULL_POLICY | Default image pull policy when deploying projects Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DOCKER_CLIENT_REFRESH_INTERVAL | How often to refresh the cached Docker client API version (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
DOCKER_HOST | URI for Docker daemon |
IMAGE_EVENT_WATCHER_ENABLED | Check image registries immediately after Docker image events Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
MAX_IMAGE_UPLOAD_SIZE | Maximum size in MB for image archive uploads (default: 500) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
POLLING_ENABLED | Enable automatic checking for image updates Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
POLLING_INTERVAL | How often to check for image updates (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
PROJECTS_DIRECTORY | Configure where project files are stored |
PRUNE_BUILD_CACHE_MODE | Select how build cache should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_BUILD_CACHE_UNTIL | Duration threshold for scheduled build cache prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_BUILD_CACHE_MODE=olderThan to have effect at runtime. |
PRUNE_CONTAINER_MODE | Select how containers should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_CONTAINER_UNTIL | Duration threshold for scheduled container prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_CONTAINER_MODE=olderThan to have effect at runtime. |
PRUNE_IMAGE_MODE | Select how images should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_IMAGE_UNTIL | Duration threshold for scheduled image prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_IMAGE_MODE=olderThan to have effect at runtime. |
PRUNE_NETWORK_MODE | Select how networks should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
PRUNE_NETWORK_UNTIL | Duration threshold for scheduled network prune when mode is olderThan Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true and PRUNE_NETWORK_MODE=olderThan to have effect at runtime. |
PRUNE_VOLUME_MODE | Select how volumes should be pruned when the scheduled prune job runs Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
SCHEDULED_PRUNE_ENABLED | Enable scheduled pruning of unused Docker resources Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
SCHEDULED_PRUNE_INTERVAL | How often to run scheduled prunes (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. SCHEDULED_PRUNE_ENABLED=true to have effect at runtime. |
SWARM_STACK_SOURCES_DIRECTORY | Configure where swarm stack source files are stored |
TEMPLATES_DIRECTORY | Configure where local compose template folders are discovered |
TOOLS_IMAGE_REGISTRY | Container registry used to pull the Arcane tools helper image |
UPDATE_CHECK_REGISTRY | Registry queried when checking whether the Arcane image has a newer digest |
VOLUME_HELPER_IDLE_TIMEOUT | Minutes a volume helper container may sit idle before automatic removal (default: 10 Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
APNS_ENABLED | Let users receive native push notifications in the Arcane mobile app Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_AUTO_PATCH_ENABLED | Automatically patch images whose latest vulnerability scan found fixable OS package vulnerabilities Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_AUTO_PATCH_INTERVAL | How often to run scheduled image patching (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_ALL_PLATFORMS | Patch every platform in a multi-platform image instead of only the platform this server runs on Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_SUFFIX | Suffix appended to the source tag when patching an image (default: patched) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
IMAGE_PATCH_TIMEOUT_SEC | Timeout for a single image patch operation in seconds (default: 600) |
LIFECYCLE_DEFAULT_RUNNER_IMAGE | Default container image used to run GitOps pre-deploy lifecycle scripts when a sync does not override it |
LIFECYCLE_ENABLED | Allow GitOps syncs to configure pre-deploy lifecycle scripts. Disabled by default because scripts are repo-trusted code that runs on every deploy |
LIFECYCLE_MAX_TIMEOUT_SEC | Maximum allowed timeout for lifecycle scripts in seconds (default: 300) |
TRIVY_CONCURRENT_SCAN_CONTAINERS | Maximum number of concurrent Trivy scan containers for manual and scheduled scans. Minimum 1 |
TRIVY_CONFIG | Trivy configuration file content in YAML format Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
TRIVY_CPU_LIMIT | Maximum CPU cores for Trivy scan containers (supports decimals, e.g. 1.5). Set 0 to disable CPU limit |
TRIVY_DB_REGISTRY | Container registry used to pull the Trivy vulnerability database artifacts |
TRIVY_IGNORE | Trivy ignore file content - one vulnerability ID per line Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
TRIVY_IGNORE_UNFIXED | Only report vulnerabilities that have a known fix available. Reduces noise from vulnerabilities you cannot act on. |
TRIVY_MEMORY_LIMIT_MB | Maximum memory for Trivy scan containers in MB. Set 0 to disable memory limit |
TRIVY_NETWORK | Docker network mode/network name used for Trivy scan containers. Leave empty to inherit Arcane's network automatically. |
TRIVY_PRIVILEGED | Run Trivy scan containers in privileged mode when required by the host security policy |
TRIVY_RESOURCE_LIMITS_ENABLED | Enable CPU and memory limits for Trivy scan containers |
TRIVY_SECURITY_OPTS | Docker security options applied to Trivy scan containers. Use commas or new lines to separate entries (for example: label=disable) |
TRIVY_SERVER_ENABLED | Scan against a remote Trivy server instead of downloading the vulnerability database locally. Recommended for 32-bit hosts (arm/v7) where the local DB cannot be memory-mapped. |
TRIVY_SERVER_TOKEN | Optional authentication token sent to the remote Trivy server. Leave empty if the server requires no token. Sensitive |
TRIVY_SERVER_URL | URL of the remote Trivy server (e.g. http://trivy.example.com:4954). Used when client/server mode is enabled. |
VULNERABILITY_SCAN_ENABLED | Enable scheduled vulnerability scanning of all Docker images Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
VULNERABILITY_SCAN_INTERVAL | How often to run scheduled vulnerability scans (cron expression) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true and VULNERABILITY_SCAN_ENABLED=true to have effect at runtime. |
VULNERABILITY_THREAT_INTEL_ENABLED | Fetch the CISA KEV catalog and FIRST EPSS scores to prioritize exploited vulnerabilities. Disable for air-gapped installs. Requires: FEATURE_VULNERABILITY_MANAGEMENT_ENABLED=true to have effect at runtime. |
DEPLOY_WAIT_TIMEOUT | Timeout waiting for services to become healthy or complete during a deploy in seconds (default: 600 = 10 minutes) |
DOCKER_API_TIMEOUT | Timeout for Docker list operations in seconds (default: 30) |
DOCKER_IMAGE_PULL_TIMEOUT | Timeout for Docker image pulls in seconds (default: 600 = 10 minutes) |
GIT_OPERATION_TIMEOUT | Timeout for Git clone/fetch operations in seconds (default: 300 = 5 minutes) |
HTTP_CLIENT_TIMEOUT | Default timeout for HTTP requests in seconds (default: 30) |
PROXY_REQUEST_TIMEOUT | Timeout for proxied requests in seconds (default: 60) |
REGISTRY_TAG_TIMEOUT | Timeout for listing every tag in a repository during version update checks in seconds (default: 120) |
REGISTRY_TIMEOUT | Timeout for container registry operations in seconds (default: 30) |
TRIVY_SCAN_TIMEOUT | Timeout for Trivy image scans in seconds (default: 900 = 15 minutes) |
AVATAR_MAX_UPLOAD_SIZE_MB | Maximum size in MB for profile picture uploads (default: 2) Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
ENABLE_GRAVATAR | Enable Gravatar profile pictures for users Requires: AGENT_MODE=true or UI_CONFIGURATION_DISABLED=true to manage this setting via env. |
No setting overrides match. Try a shorter name or clear the search.
Container runtime user
Section titled “Container runtime user”When Arcane runs inside a container, it drops to the built-in non-root user (65532:65532) unless PUID and PGID are set. Arcane treats itself as containerized when ARCANE_IN_CONTAINER=true (set by the official images), when the container variable is non-empty, or when /.dockerenv or /run/.containerenv exists. Outside a container, the process keeps the user it was started as.
Set PUID and PGID if mounted files should belong to a specific host user and group. If you point DOCKER_HOST at a custom Unix socket, Arcane uses that socket path when it adds the runtime user to the socket’s group.
Timezone and scheduled jobs
Section titled “Timezone and scheduled jobs”Arcane’s recurring jobs (image update checks, auto-updates, vulnerability scans, scheduled pruning, GitOps sync, and environment health checks) run on cron-style schedules evaluated in the timezone set by TZ. Set it to an IANA timezone name so jobs run at the local times you expect:
TZ=America/New_YorkIf TZ is unset, Arcane uses the container’s local time, which is UTC on the official images. Job intervals and cron expressions are set in the Settings UI, or through the environment when settings overrides are enabled.
Admin API key bootstrap
Section titled “Admin API key bootstrap”Set ADMIN_STATIC_API_KEY when automation needs a known API key from the first start. At startup, Arcane creates or updates a protected admin API key with this value, so you don’t have to create it in the UI. See the API Reference for usage and webhook examples.