# Environment variable reference

Keep public build values separate from server and maintenance credentials.

Start with .env.example for development and .env.production.example for deployment. The ATLAS_ prefix remains in configuration for compatibility even though the product is named Ralti. An unset optional value is different from a fabricated placeholder credential. Supply real secrets only through private environment files or the deployment secret manager.

| Variable | Purpose |
| --- | --- |
| ATLAS_AUTH_PROVIDER | clerk for hosted identity; local only for isolated development |
| NEXT_PUBLIC_CLERK_PUBLISHABLE_KEY | Public web build key for the chosen Clerk application |
| CLERK_SECRET_KEY | Server-only identity credential |
| ATLAS_PUBLIC_ORIGIN | Exact browser-facing application origin |
| CLERK_AUTHORIZED_PARTIES | Comma-separated exact allowed browser origins |
| ATLAS_SECURE_COOKIES | Enable secure cookies for HTTPS deployment |
| DATABASE_URL | Restricted PostgreSQL runtime connection; unset selects SQLite |
| DATABASE_POOL_SIZE | Connection pool size per runtime process |
| ATLAS_DATA_DIR | Private persistent file root; local default .atlas |
| ATLAS_WORKER_MODE | external delegates background work to supervised workers |
| OPENAI_API_KEY | Server credential for AI and semantic indexing |
| OPENAI_MODEL | Provider model for AI requests |
| ATLAS_SEMANTIC_SEARCH | false disables semantic queries and indexing, retaining keyword search |
| ATLAS_EMAIL_ENCRYPTION_KEY | Stable base64-encoded 32-byte email credential encryption key |
| MICROSOFT_CLIENT_ID / MICROSOFT_CLIENT_SECRET | Microsoft confidential OAuth application credentials |
| MICROSOFT_TENANT_ID | Microsoft tenant selection; defaults to common |
| MICROSOFT_REDIRECT_URI | Exact Microsoft callback URI |
| GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET | Google OAuth Web client credentials |
| GOOGLE_REDIRECT_URI | Exact Google callback URI |
| RALTI_DATABASE_ADMIN_URL | Maintenance only: migrations, provisioning, import, backup |
| RALTI_DATA_PATH | Compose host path for persistent private data |
| RALTI_IMAGE_TAG / RALTI_HTTP_PORT | Compose release image tag and loopback host port |

ATLAS_DISABLE_WORKER, ATLAS_DISABLE_AI_WORKER, ATLAS_DISABLE_EMAIL_WORKER, and ATLAS_DISABLE_SEARCH_WORKER control embedded worker startup for tests or maintenance. External worker processes must be stopped or started with only the intended roles. Review both modes before release: a working web process can still leave jobs queued. RALTI_WORKER_POOL_SIZE configures the installed macOS worker service pool; include it in the total connection budget.

## Native configuration

ATLAS_API_URL selects the reachable application origin for the iOS shell and earlier Android Flutter client. iOS loads the website’s identity configuration and session; CLERK_PUBLISHABLE_KEY remains a public Dart build input for the earlier Android interface. These are client build inputs, not aliases for server environment variables. Never bundle a Clerk secret, database URL, provider API key, or email encryption key.

> **Operational handling** Rebuild when changing public compiled values. Preserve the stable encryption key when moving encrypted mailbox data. Avoid printing fully expanded Compose configuration or environment files in logs; config --quiet validates configuration without displaying its secret values.

