Environment variables
App image
Section titled “App image”| Variable | Default (in container) | Description |
|---|---|---|
GALENE_DATA_DIR |
/app/data |
Directory for the database file. Must be a mounted volume. |
GALENE_DB_PATH |
$GALENE_DATA_DIR/galene.db |
Full path to the SQLite database. |
PORT |
3000 |
HTTP port the app listens on (UI, REST, and MCP /mcp when enabled). |
NODE_ENV |
production (baked into the image) |
Affects the session cookie’s Secure flag by default. |
GALENE_COOKIE_SECURE |
unset → follows NODE_ENV |
1/true/yes/on sets the Secure flag; 0/false/no/off clears it. |
PROTOCOL_HEADER |
unset | Bun adapter: name of the header that carries the public scheme behind a TLS proxy. Set to x-forwarded-proto when TLS terminates upstream. |
HOST_HEADER |
unset → request Host |
Bun adapter: header for the public hostname (host or x-forwarded-host). |
PORT_HEADER |
unset | Optional Bun adapter: header for a non-default public port. |
ADDRESS_HEADER |
unset | Optional Bun adapter: client IP header (e.g. x-forwarded-for) for logging / rate limits. |
XFF_DEPTH |
1 |
Optional Bun adapter: which hop from the end of X-Forwarded-For is the client when ADDRESS_HEADER=x-forwarded-for. |
GALENE_ALLOW_EPHEMERAL_DATA |
unset | 1 disables the startup volume check. Only for throwaway/test containers. |
GALENE_OIDC_ENABLED |
unset | 1/0 overrides Settings → Security single sign-on on/off. Unset uses the saved toggle (default off). |
GALENE_OIDC_MODE |
unset | optional (default) or required. Overrides the Settings mode when set. |
GALENE_OIDC_ISSUER |
unset | Issuer URL. Overrides the Settings issuer when non-empty. |
GALENE_OIDC_CLIENT_ID |
unset | OIDC client id. Overrides Settings when non-empty. |
GALENE_OIDC_CLIENT_SECRET |
unset | OIDC client secret. Overrides Settings when non-empty and is not shown back in the form. |
GALENE_OIDC_SCOPES |
unset | Space-separated scopes. Overrides Settings when non-empty. Default in Settings is openid profile email. |
GALENE_ENABLE_MCP |
unset | 1/0 overrides Settings → API MCP HTTP on/off. Unset uses the saved toggle (default off). When off, /mcp is not live. When on, MCP shares the app PORT (no separate MCP port). |
GALENE_THEME_GALLERY_URL |
https://themes.galene.finance/api/themes |
Where Settings → Appearance → Publish sends signed theme packs. Must be https (plain http only for localhost / 127.0.0.1). See Appearance. |
MCP bundle (stdio from the app image)
Section titled “MCP bundle (stdio from the app image)”mcp-bundle.js ships inside the app image. There is no separate :mcp-* image. Prefer enabling MCP on the app (Settings → API → /mcp on the app port) for HTTP; for stdio, launch the bundle from the app image or from source.
| Variable | Default | Description |
|---|---|---|
GALENE_API_URL |
http://localhost:3000 |
Base URL of the Galene instance the MCP stdio process calls. |
GALENE_API_TOKEN |
— | API token from Settings → API. Required for stdio. Do not set it on the app when using Settings-managed HTTP MCP. |
GALENE_MCP_PORT |
unset | Optional when launching the bundle alone for a local HTTP process. Unset keeps stdio. Prefer app /mcp instead. |
GALENE_MCP_HOST |
0.0.0.0 |
Bind address when GALENE_MCP_PORT is set on a locally launched bundle. |
When to set GALENE_COOKIE_SECURE and the adapter proxy headers (PROTOCOL_HEADER, HOST_HEADER, …): Reverse proxy. A non-empty GALENE_OIDC_* / GALENE_ENABLE_MCP variable overrides the matching Settings field; see Single sign-on (OIDC) and API & MCP. Outside the container the default GALENE_DATA_DIR is ./data — see From source.