Skip to content
SupaCovedocs

04 / 13

Configuration

Every SB_* variable: defaults, semantics, risks

All configuration is via environment variables; there is no config file.

Core

VariableDefaultMeaning
SB_DATA_DIR./data (/app/data in image)master secret, SQLite, staging
SB_ADDR:8080HTTP listen address
SB_LOG_LEVELinfodebug / info / warn / error
SB_SECRET_FILE(inside data dir)override master secret path
SB_PUBLIC_ORIGINemptyexternal origin behind a proxy; Origins must match exactly when set
SB_TRUSTED_PROXIESemptyCIDRs allowed to supply X-Forwarded-For; empty trusts none

Sessions and bootstrap

VariableDefaultMeaning
SB_INSECURE_COOKIEfalseallow session cookies without Secure. Local plain-HTTP dev only
bootstrap token TTL15 minutesone-time token from the bootstrap subcommand
session TTL7 daysfixed

Backups and staging

VariableDefaultMeaning
SB_LOCAL_KEEP5staged ciphertext copies kept per database (newest success always protected)
SB_STAGING_QUOTA_BYTES0 (unlimited)staging hard budget; exceeding it fails new backups with the disk class. Even at 0, a 64 MiB filesystem free-space floor still applies
SB_JOB_TIMEOUT6hwall-clock budget per job (export+upload+read-back). During normal runs expiry fails the job as a network-class failure and notifies; a startup resume that exceeds it settles back to interrupted without notifying. 0 disables
SB_FAILED_ARTIFACT_TTL_HOURS72grace before failed/canceled/interrupted artifacts are reclaimed; 0 keeps forever

Restore verification (off by default)

VariableDefaultMeaning
SB_VERIFY_ENABLEDfalseenable embedded-PostgreSQL restore verification after every success
SB_VERIFY_IDENTITY_FILEemptyrequired when verification is on; must be a regular, non-symlink file readable by the runtime user with no group/other permissions (0600 or 0400)
SB_VERIFY_PGBINemptyoverride server binaries for the throwaway instance

Enabling verification hands the decryption identity to the running instance — a deliberate trust decision (ADR-004). While off, tasks show "not verified"; backup correctness is unaffected.

Heartbeat fallback

VariableDefaultMeaning
SB_HEARTBEAT_URLemptyserver-wide dead-man-switch fallback; databases without their own URL inherit it

Last updated

On this page