Configuration
{/* GENERATED FILE — do not edit. Produced by docs/scripts/generate-reference.mjs from src/lib/config.ts. */}
All tunable behaviour is environment-driven and centralized in
src/lib/config.ts.
This table is generated from that file, so it cannot drift from the code.
Every variable below and in the next table is validated at server startup;
Startup validation lists which are required
in production and what npm run config:check reports.
| Variable | Type | Default | Purpose |
|---|---|---|---|
DEFAULT_REFRESH_INTERVAL_MS |
number | 15000 |
Default dashboard refresh cadence. A dashboard may override this per its own IR, but new dashboards start from this value. Documented default: 15s. |
MIN_REFRESH_INTERVAL_MS |
number | 2000 |
Minimum refresh cadence enforced server-side to protect the metrics store. |
DEFAULT_TIME_FROM |
string | now-24h |
Default relative time range applied to new dashboards. Documented default: last 24 hours (“now-24h” .. “now”). |
DEFAULT_TIME_TO |
string | now |
Upper bound of the default range. now keeps new dashboards live. |
MAX_QUERY_ROWS |
number | 5000 |
Hard cap on rows returned by any query executed against the metrics store. |
MAX_RESULT_BYTES |
number | 4 * 1024 * 1024 |
Hard cap on the serialized size (bytes of JSON) of any query result. Rows are a poor proxy for memory; a result over this fails with a 400 naming the limit before it is fully buffered. Default 4 MiB. |
MAX_WINDOW_POINTS |
number | 720 |
Max points retained per series in the browser rolling window. |
QUERY_TIMEOUT_SECONDS |
number | 20 |
Statement timeout (seconds) applied to every metrics query. |
CATALOG_STALE_AFTER_DAYS |
number | 30 |
How long a source’s catalog may go without being checked against the live database before it is reported as stale. Stale is a warning, not a refusal — a catalog nobody has refreshed at all is what blocks generation. 0 disables the age check entirely. Documented default: 30 days. |
SHUTDOWN_GRACE_MS |
number | 10000 |
How long the server may take to drain after SIGTERM: pollers stop, SSE subscribers are handed a reconnect hint, in-flight queries are awaited, and the pools are closed. Keep it below the orchestrator’s own kill timeout (terminationGracePeriodSeconds, stop_grace_period) or the process is killed mid-drain. Documented default: 10s. |
AI_MODEL |
string | — |
The AI model id used for generation, surfaced read-only to the UI so users can see which model produced their specs. Empty when unconfigured. This is a display label only — actual provider/model resolution lives in src/lib/ai/provider.ts. |
LLM_RATE_PER_MINUTE |
number | 20 |
Model requests per minute allowed per user in a workspace, on every LLM-backed route (generate, source draft, dashboard chat). A token bucket: this is both the sustained rate and the burst size. 0 disables the limit. Overridable per workspace in the workspace_limits table. |
LLM_DAILY_TOKEN_BUDGET |
number | 2000000 |
Input plus output tokens a workspace may spend per UTC day across every LLM-backed route. Requests over budget get a 429 until midnight UTC. 0 disables the limit. Overridable per workspace in workspace_limits. |
CHAT_HISTORY_MAX_MESSAGES |
number | 100 |
How many messages of one person’s chat history on one dashboard are kept and replayed. The cap is enforced on write and on read, so lowering it takes effect at once. Documented default: 100 messages. |
CHAT_HISTORY_RETENTION_DAYS |
number | 30 |
How long a stored chat message is kept. A conversation is a reader working something out, not a record anyone audits, so it expires. 0 disables the age check and leaves only the message cap. Documented default: 30 days. |
GENERATION_LOG_RETENTION_DAYS |
number | 30 |
How long a generation_log row – the redacted prompt, the spec the model returned, and what it cost – is kept. The sweep runs on write, so shortening this takes effect at the next generation in that workspace and immediately for anyone reading the log. 0 disables the age check and lets the log grow without bound, which is for an operator shipping the rows somewhere else. Documented default: 30 days. |
OIDC_ACCOUNT_URL |
string | — |
The identity provider’s self-service account page, e.g. Keycloak’s <issuer>/account. The account settings section links to it when set, so people can change the name, email and password the provider owns. Unset hides the link. |
SESSION_COOKIE_NAME |
string | holotable_session |
Cookie name used for the session JWT. |
CSP_REPORT_ONLY |
boolean | false |
Send the Content-Security-Policy as Content-Security-Policy-Report-Only, so the browser logs violations without blocking anything. For rolling the policy out against a deployment; leave false once the console is clean. |
Variables read outside config.ts
Section titled “Variables read outside config.ts”These are read directly from process.env at their point of use rather than
through the config module.
| Variable | Read by | Purpose |
|---|---|---|
DATABASE_URL |
src/lib/db/pg.ts |
Config-store connection string. Required. |
PG_POOL_MAX |
src/lib/db/pg.ts |
Config-store pool size. Defaults to 10. |
SESSION_SECRET |
src/lib/auth/session.ts |
HS256 signing key for first-party session tokens. Must be at least 32 characters in production. |
AI_PROVIDER |
src/lib/ai/provider.ts |
gateway or openai-compatible. |
OPENAI_BASE_URL, OPENAI_API_KEY, OPENAI_API |
src/lib/ai/provider.ts |
OpenAI-compatible endpoint selection. See AI provider. |
AI_GATEWAY_API_KEY |
AI SDK | Used when AI_PROVIDER=gateway. |
OIDC_ISSUER, OIDC_CLIENT_ID, OIDC_CLIENT_SECRET, OIDC_REDIRECT_URI, OIDC_SCOPE |
src/lib/auth/oidc.ts |
OIDC login flow. See Keycloak setup. |
OIDC_JWKS_URL, OIDC_AUDIENCE, OIDC_GROUPS_CLAIM |
src/lib/auth/session.ts |
Token verification and the group claim name. |
SOURCE_SECRET_REFS |
src/lib/secrets/credentials.ts |
Which workspaces may use which secret_ref: REF:ws1,ws2; OTHER:*. Unset grants nothing (an error in production). See Source secret references. |
SOURCE_SECRETS_DIR |
src/lib/secrets/credentials.ts |
Directory of <SECRET_REF>_USERNAME / <SECRET_REF>_PASSWORD files, read on every connection before the environment. Optional. |
<SECRET_REF>_USERNAME / <SECRET_REF>_PASSWORD |
src/lib/secrets/credentials.ts |
Per-source credentials resolved at execution time. See Source secret references. |
APP_VERSION, GIT_COMMIT |
src/lib/version.ts |
Build identity reported by GET /api/health. Optional. See Health and readiness. |
METRICS_TOKEN, METRICS_ALLOWED_CIDRS |
src/lib/metrics-access.ts |
Who may scrape GET /api/metrics. Unset on both closes the endpoint. Read outside config.ts because that module reaches the browser bundle. See Prometheus metrics. |