Reference
Environment variables
Reference the production settings exposed by Citadel's Docker Compose environment template.
Citadel uses environment variable names with double underscores between
sections. The .env downloaded in the installation guide
contains the settings needed to start Citadel. Add optional settings from this
reference as needed. The defaults are for local HTTP; configure TLS before
sharing an installation.
| Setting | Required when | Purpose |
|---|---|---|
CITADEL_IMAGE | Optional | Blank or unset uses ghcr.io/citadel-p/citadel:latest; set a complete image address to override |
CITADEL_BIND_ADDRESS | Optional | Host bind address; defaults to 127.0.0.1 |
CITADEL_HTTP_PORT, CITADEL_EDGE_PORT | Optional | Host ports; default to 18000 and 18001 |
PG_HOST | External or renamed PostgreSQL | PostgreSQL hostname; Compose defaults to pg_db |
PG_USER, PG_PASSWORD, PG_DATABASE | Always | PostgreSQL credentials and database |
Transport__Mode | Always | ReverseProxy, Direct, or development-only Disabled |
Transport__PublicUrl | Always | Canonical browser and API origin |
EdgeAgent__PublicGrpcUrl | Edge Agent use | Public Edge gRPC address |
AllowedHosts | Always | Hostnames accepted by Core |
Transport__ForwardedHeaders__KnownProxies | Reverse proxy | Immediate trusted proxy address |
Transport__ForwardedHeaders__KnownNetworks | Reverse proxy alternative | Immediate trusted proxy network |
Transport__Certificate__Path | Direct TLS | PEM certificate chain inside Core |
Transport__Certificate__PrivateKeyPath | Direct TLS | PEM private key inside Core |
Jwt__Issuer, Jwt__Audience | Optional override | Token validation identities; otherwise derived from the public URL |
Jwt__Key | Optional | Explicit signing key; otherwise persisted in citadel_data |
Secrets__EncryptionKey | Optional | Explicit 32-byte base64 key; otherwise persisted in citadel_data |
Mfa__Policy | Optional | Optional, RequiredForAdministrators, or RequiredForAllUsers |
Passwords__MinimumLength | Optional | Minimum password length, default 15; accepts 8–128, with a fixed maximum password length of 128 |
EnableSwagger | Optional | Exposes Swagger and the full/public OpenAPI documents; false by default |
See Docker Compose configuration for defaults, bootstrap settings, automation, monitoring intervals, and safe key handling.