Skip to content

Environment variables

These are the .env settings an operator sets or changes. The installer writes the required ones; everything else is configured in Jackdaw.

.env sits in the stack directory, next to docker-compose.yml. After you edit it, run docker compose up -d there so the changed containers restart. A change to MANTLE_SERVER_ORIGIN or MANTLE_CLIENT_IMAGE_TAG also needs the interface stack restarted, as in Update Mantle. Keep your own changes in .env: an edited docker-compose.yml stops receiving release changes.

Secrets (written once by the installer)

Variable What it is
MANTLE_MASTER_KEY Encrypts stored API keys, passwords and secrets. Never change it on a running brain. Lose it and that data is gone.
SESSION_SECRET Signs login sessions.
POSTGRES_PASSWORD Database password.
S3_ACCESS_KEY, S3_SECRET_KEY Object store credentials.
MANTLE_SETUP_CODE The code sign-up asks for until the first account exists. scripts/install.sh --setup-code prints it.

Address and network

Variable What it does
MANTLE_SITE_ADDRESS The hostname the front door serves, for example brain.example.com. A hostname gets HTTPS automatically.
MANTLE_PUBLIC_URL The full public address, for example https://brain.example.com. Used in share and email links.
MANTLE_SERVER_ORIGIN The address Jackdaw uses to reach the API. Usually the same as MANTLE_PUBLIC_URL.
MANTLE_BIND_ADDR Network interface for ports 80 and 443. 127.0.0.1 keeps the brain off the network. Default 0.0.0.0.
MANTLE_HTTP_PORT, MANTLE_HTTPS_PORT Host ports for the front door. Default 80 and 443. HTTPS certificates need the real 80 and 443.
MANTLE_WEB_DEBUG_PORT Loopback-only debug port. Default 3000. Change it if something else holds 3000.
MANTLE_TRUSTED_PROXIES Proxy hops in front of Mantle, for correct client addresses. Default 1. Raise it if you add a proxy before Caddy.
MANTLE_API_CORS_ORIGINS Extra origins allowed to call the API, comma separated. Empty means same origin only.

To change the domain, run scripts/install.sh --domain <host> instead of editing these by hand. See Add a domain and HTTPS.

Stack

Variable What it does
MANTLE_STACK_DIR Full path of the stack directory. The updater needs it.
MANTLE_DATA_DIR Where all state is stored. Default ./data.
MANTLE_IMAGE_TAG Server version. latest, or a release tag to stay on one version.
MANTLE_CLIENT_IMAGE_TAG Jackdaw interface version. The updater sets it.
MANTLE_CLIENT_ENABLED 0 runs no Jackdaw interface on the box (headless). Missing means on.
COMPOSE_PROFILES Optional services: sandboxes, media, local-embedder, helpers. Prefer Settings > Services.
COMPOSE_FILE Set by --core for the small core shape.
SANDBOXD_TOKEN, MEDIA_SIDECAR_TOKEN Tokens for the sandbox and media services. Written for you.

Updater

Variable What it does
MANTLE_PRE_ROLL_BACKUP 0 skips the backup before each update. Take your own then.
MANTLE_PRE_ROLL_KEEP How many pre-update backups to keep. Default 3.
MANTLE_IMAGE_PRUNE 0 keeps old images after an update. By default they are removed.

Next