Environment variables
The environment variables that the Open Source edition of Stategraph Orchestration, the ghcr.io/terrateamio/terrat-oss container, reads. You set them in .env with Docker Compose, as Secrets and values with the Helm chart, or as Secrets Manager secrets and extra_environment with the ECS module.
For the Enterprise server, ghcr.io/stategraph/stategraph-server, see Environment variables. Its Orchestration section lists the other TERRAT_* settings, such as telemetry and tuning, which the Open Source container reads too.
Required variables
Database
| Variable | Description | Example |
|---|---|---|
DB_HOST |
Database host | localhost, db.example.com |
DB_NAME |
Database name | terrateam |
DB_USER |
Database user | terrateam |
DB_PASS |
Database password | secure_password_123 |
DB_PORT |
Database port | 5432 |
GitHub App
Required with GitHub:
| Variable | Description | Example |
|---|---|---|
GITHUB_APP_ID |
GitHub App ID | 123456 |
GITHUB_APP_CLIENT_ID |
GitHub App client ID | Iv1.8ea942184ee41c0b |
GITHUB_APP_CLIENT_SECRET |
GitHub App client secret | 8dab6d1de78a2cdbc9o014dubcf4a55ca44a3c81 |
GITHUB_APP_PEM |
GitHub App private key, in PEM format | -----BEGIN RSA PRIVATE KEY-----\nMIIE... |
GITHUB_WEBHOOK_SECRET |
GitHub webhook secret | 02d87878a0ac61d75d25cz8fec1d1af509f9a6d9 |
GitLab application
Required with GitLab:
| Variable | Description | Example |
|---|---|---|
GITLAB_APP_ID |
GitLab application ID | abc123def456 |
GITLAB_APP_SECRET |
GitLab application secret | gloas-1234567890abcdef |
GITLAB_ACCESS_TOKEN |
Personal access token of the bot account | glpat-xxxxxxxxxxxxxxxxxxxx |
Server URLs
| Variable | Description | Example |
|---|---|---|
TERRAT_API_BASE |
Public API base URL, with /api |
https://stategraph.example.com/api |
TERRAT_WEB_BASE_URL |
Public web base URL. The base of the run links in comments and commit checks for a repository whose brand has no base of its own | https://stategraph.example.com |
TERRAT_UI_BASE |
Public console base URL, required for the console. The base of the run links of a terrateam-brand repository |
https://stategraph.example.com |
The setup wizard writes TERRAT_UI_BASE and TERRAT_WEB_BASE_URL. With the Docker Compose tunnel, the server derives TERRAT_API_BASE from the tunnel when it is unset; with your own URL, set it.
Optional variables
GitHub Enterprise Server
| Variable | Description | Default | Example |
|---|---|---|---|
GITHUB_API_BASE_URL |
GitHub API base URL | https://api.github.com |
https://github.example.com/api/v3 |
GITHUB_WEB_BASE_URL |
GitHub web base URL | https://github.com |
https://github.example.com |
Self-managed GitLab
| Variable | Description | Default | Example |
|---|---|---|---|
GITLAB_API_BASE_URL |
Root URL of the instance, without /api/v4 |
https://gitlab.com |
https://gitlab.example.com |
GITLAB_WEB_BASE_URL |
Root URL of the instance | https://gitlab.com |
https://gitlab.example.com |
Proxy
For a network that requires an HTTP proxy:
| Variable | Description | Example |
|---|---|---|
HTTP_PROXY |
URL of the HTTP proxy | https://proxy.local:8080 |
HTTPS_PROXY |
URL of the HTTPS proxy | https://proxy.local:8080 |
NO_PROXY |
Comma-separated hosts that bypass the proxy | localhost,127.0.0.1,internal.com |
For a proxy with authentication, put the credentials in the URL:
HTTP_PROXY=https://username:password@proxy.local:8080
HTTPS_PROXY=https://username:password@proxy.local:8080
Custom CA certificates
For a private certificate authority, such as a TLS-inspecting corporate proxy, a GitHub Enterprise Server with an internal CA, or a private artifact registry, the container installs additional trusted CA certificates into its trust store at start.
| Variable | Description | Example |
|---|---|---|
CUSTOM_CA_CERT |
One or more PEM-encoded CA certificates to install into the system trust store of the container | -----BEGIN CERTIFICATE-----\nMIID...\n-----END CERTIFICATE----- |
When CUSTOM_CA_CERT is set, the container parses every -----BEGIN CERTIFICATE----- / -----END CERTIFICATE----- block from the value, writes each one to /usr/local/share/ca-certificates/, and runs update-ca-certificates, so the certificates are trusted system-wide inside the container. It removes the custom certificates of a previous start first, so the variable always holds the full set of custom CAs that you want trusted.
When CUSTOM_CA_CERT is unset, the container installs nothing and trusts only the certificates of the image.
A single certificate:
CUSTOM_CA_CERT="-----BEGIN CERTIFICATE-----
MIIDdz...long base64 body...
-----END CERTIFICATE-----"
Several certificates, as concatenated PEM blocks. The container splits them:
CUSTOM_CA_CERT="-----BEGIN CERTIFICATE-----
MIID...root CA...
-----END CERTIFICATE-----
-----BEGIN CERTIFICATE-----
MIIE...intermediate CA...
-----END CERTIFICATE-----"
With Docker Compose, load the certificate from a file on the host:
services:
server:
image: ghcr.io/terrateamio/terrat-oss:latest
environment:
CUSTOM_CA_CERT: ${CUSTOM_CA_CERT}
export CUSTOM_CA_CERT="$(cat /path/to/your-ca-bundle.pem)"
docker compose up -d
Only PEM certificates are supported. Convert a DER certificate first:
openssl x509 -inform DER -in your-ca.der -out your-ca.pem
Next steps
- Observability and metrics: when a configuration change has no effect, check
terrat_errors_totaland the other server metrics first. - Support: if the metrics do not explain it, contact support with your server logs and your version.
- Open Source: the deployment paths of the open-source edition.