Start with .env.example for development and .env.production.example for deployment. The ATLAS_ prefix remains in configuration for compatibility even though the product is named Ralti. An unset optional value is different from a fabricated placeholder credential. Supply real secrets only through private environment files or the deployment secret manager.

VariablePurpose
ATLAS_AUTH_PROVIDERclerk for hosted identity; local only for isolated development
NEXT_PUBLIC_CLERK_PUBLISHABLE_KEYPublic web build key for the chosen Clerk application
CLERK_SECRET_KEYServer-only identity credential
ATLAS_PUBLIC_ORIGINExact browser-facing application origin
CLERK_AUTHORIZED_PARTIESComma-separated exact allowed browser origins
ATLAS_SECURE_COOKIESEnable secure cookies for HTTPS deployment
DATABASE_URLRestricted PostgreSQL runtime connection; unset selects SQLite
DATABASE_POOL_SIZEConnection pool size per runtime process
ATLAS_DATA_DIRPrivate persistent file root; local default .atlas
ATLAS_WORKER_MODEexternal delegates background work to supervised workers
OPENAI_API_KEYServer credential for AI and semantic indexing
OPENAI_MODELProvider model for AI requests
ATLAS_SEMANTIC_SEARCHfalse disables semantic queries and indexing, retaining keyword search
ATLAS_EMAIL_ENCRYPTION_KEYStable base64-encoded 32-byte email credential encryption key
MICROSOFT_CLIENT_ID / MICROSOFT_CLIENT_SECRETMicrosoft confidential OAuth application credentials
MICROSOFT_TENANT_IDMicrosoft tenant selection; defaults to common
MICROSOFT_REDIRECT_URIExact Microsoft callback URI
GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRETGoogle OAuth Web client credentials
GOOGLE_REDIRECT_URIExact Google callback URI
RALTI_DATABASE_ADMIN_URLMaintenance only: migrations, provisioning, import, backup
RALTI_DATA_PATHCompose host path for persistent private data
RALTI_IMAGE_TAG / RALTI_HTTP_PORTCompose release image tag and loopback host port

ATLAS_DISABLE_WORKER, ATLAS_DISABLE_AI_WORKER, ATLAS_DISABLE_EMAIL_WORKER, and ATLAS_DISABLE_SEARCH_WORKER control embedded worker startup for tests or maintenance. External worker processes must be stopped or started with only the intended roles. Review both modes before release: a working web process can still leave jobs queued. RALTI_WORKER_POOL_SIZE configures the installed macOS worker service pool; include it in the total connection budget.

Native configuration#

ATLAS_API_URL selects the reachable application origin for the iOS shell and earlier Android Flutter client. iOS loads the website’s identity configuration and session; CLERK_PUBLISHABLE_KEY remains a public Dart build input for the earlier Android interface. These are client build inputs, not aliases for server environment variables. Never bundle a Clerk secret, database URL, provider API key, or email encryption key.