Citadel
Reference

Environment variables

Reference the production settings exposed by Citadel's Docker Compose environment template.

Citadel uses environment variable names with double underscores between sections. The .env downloaded in the installation guide contains the settings needed to start Citadel. Add optional settings from this reference as needed. The defaults are for local HTTP; configure TLS before sharing an installation.

SettingRequired whenPurpose
CITADEL_IMAGEOptionalBlank or unset uses ghcr.io/citadel-p/citadel:latest; set a complete image address to override
CITADEL_BIND_ADDRESSOptionalHost bind address; defaults to 127.0.0.1
CITADEL_HTTP_PORT, CITADEL_EDGE_PORTOptionalHost ports; default to 18000 and 18001
PG_HOSTExternal or renamed PostgreSQLPostgreSQL hostname; Compose defaults to pg_db
PG_USER, PG_PASSWORD, PG_DATABASEAlwaysPostgreSQL credentials and database
Transport__ModeAlwaysReverseProxy, Direct, or development-only Disabled
Transport__PublicUrlAlwaysCanonical browser and API origin
EdgeAgent__PublicGrpcUrlEdge Agent usePublic Edge gRPC address
AllowedHostsAlwaysHostnames accepted by Core
Transport__ForwardedHeaders__KnownProxiesReverse proxyImmediate trusted proxy address
Transport__ForwardedHeaders__KnownNetworksReverse proxy alternativeImmediate trusted proxy network
Transport__Certificate__PathDirect TLSPEM certificate chain inside Core
Transport__Certificate__PrivateKeyPathDirect TLSPEM private key inside Core
Jwt__Issuer, Jwt__AudienceOptional overrideToken validation identities; otherwise derived from the public URL
Jwt__KeyOptionalExplicit signing key; otherwise persisted in citadel_data
Secrets__EncryptionKeyOptionalExplicit 32-byte base64 key; otherwise persisted in citadel_data
Mfa__PolicyOptionalOptional, RequiredForAdministrators, or RequiredForAllUsers
Passwords__MinimumLengthOptionalMinimum password length, default 15; accepts 8–128, with a fixed maximum password length of 128
EnableSwaggerOptionalExposes Swagger and the full/public OpenAPI documents; false by default

See Docker Compose configuration for defaults, bootstrap settings, automation, monitoring intervals, and safe key handling.