Skip to content

Environment variables

Variable Default (in container) Description
GALENE_DATA_DIR /app/data Directory for the database file. Must be a mounted volume.
GALENE_DB_PATH $GALENE_DATA_DIR/galene.db Full path to the SQLite database.
PORT 3000 HTTP port the app listens on (UI, REST, and MCP /mcp when enabled).
NODE_ENV production (baked into the image) Affects the session cookie’s Secure flag by default.
GALENE_COOKIE_SECURE unset → follows NODE_ENV 1/true/yes/on sets the Secure flag; 0/false/no/off clears it.
PROTOCOL_HEADER unset Bun adapter: name of the header that carries the public scheme behind a TLS proxy. Set to x-forwarded-proto when TLS terminates upstream.
HOST_HEADER unset → request Host Bun adapter: header for the public hostname (host or x-forwarded-host).
PORT_HEADER unset Optional Bun adapter: header for a non-default public port.
ADDRESS_HEADER unset Optional Bun adapter: client IP header (e.g. x-forwarded-for) for logging / rate limits.
XFF_DEPTH 1 Optional Bun adapter: which hop from the end of X-Forwarded-For is the client when ADDRESS_HEADER=x-forwarded-for.
GALENE_ALLOW_EPHEMERAL_DATA unset 1 disables the startup volume check. Only for throwaway/test containers.
GALENE_OIDC_ENABLED unset 1/0 overrides Settings → Security single sign-on on/off. Unset uses the saved toggle (default off).
GALENE_OIDC_MODE unset optional (default) or required. Overrides the Settings mode when set.
GALENE_OIDC_ISSUER unset Issuer URL. Overrides the Settings issuer when non-empty.
GALENE_OIDC_CLIENT_ID unset OIDC client id. Overrides Settings when non-empty.
GALENE_OIDC_CLIENT_SECRET unset OIDC client secret. Overrides Settings when non-empty and is not shown back in the form.
GALENE_OIDC_SCOPES unset Space-separated scopes. Overrides Settings when non-empty. Default in Settings is openid profile email.
GALENE_ENABLE_MCP unset 1/0 overrides Settings → API MCP HTTP on/off. Unset uses the saved toggle (default off). When off, /mcp is not live. When on, MCP shares the app PORT (no separate MCP port).
GALENE_THEME_GALLERY_URL https://themes.galene.finance/api/themes Where Settings → Appearance → Publish sends signed theme packs. Must be https (plain http only for localhost / 127.0.0.1). See Appearance.

mcp-bundle.js ships inside the app image. There is no separate :mcp-* image. Prefer enabling MCP on the app (Settings → API → /mcp on the app port) for HTTP; for stdio, launch the bundle from the app image or from source.

Variable Default Description
GALENE_API_URL http://localhost:3000 Base URL of the Galene instance the MCP stdio process calls.
GALENE_API_TOKEN — API token from Settings → API. Required for stdio. Do not set it on the app when using Settings-managed HTTP MCP.
GALENE_MCP_PORT unset Optional when launching the bundle alone for a local HTTP process. Unset keeps stdio. Prefer app /mcp instead.
GALENE_MCP_HOST 0.0.0.0 Bind address when GALENE_MCP_PORT is set on a locally launched bundle.

When to set GALENE_COOKIE_SECURE and the adapter proxy headers (PROTOCOL_HEADER, HOST_HEADER, …): Reverse proxy. A non-empty GALENE_OIDC_* / GALENE_ENABLE_MCP variable overrides the matching Settings field; see Single sign-on (OIDC) and API & MCP. Outside the container the default GALENE_DATA_DIR is ./data — see From source.