Skip to content

Settings in .env

.env holds every setting the stack reads. make env (scripts/setup-env) creates it from .env.example, in the same order and with the same comments, and on every later run keeps the values already in .env and adds settings that are new (Security).

What make env writes for each kind of value in .env.example:

In .env.example In .env
A plain value The value, which you may change
generate:hex, generate:token, generate:uuid, optionally with a prefix (generate:token:sk-) A fresh random secret, made once and then kept
basic-auth:USER_KEY:PASSWORD_KEY base64 of the two settings' values joined by a colon, recomputed on every run
Empty Empty, for you to fill in, such as a provider's key

Settings in .env that .env.example doesn't have, such as keys you add, are kept at the end of the file.

The settings, as .env.example groups and describes them:

The stack as a whole

The host address published ports bind to. 127.0.0.1 keeps every service reachable from this machine only.

Setting In .env.example
STACKR_BIND 127.0.0.1

The deployment environment telemetry is labelled with (deployment.environment.name), when an application doesn't set its own.

Setting In .env.example
STACKR_ENVIRONMENT local

Observability

Grafana signs in as admin with this password.

Setting In .env.example
GRAFANA_ADMIN_PASSWORD Generated: 43 URL-safe characters

Published ports. Applications send OTLP to the Collector on 4317 (gRPC) or 4318 (HTTP), and profiles to Pyroscope on 4040.

Setting In .env.example
OTLP_GRPC_PORT 4317
OTLP_HTTP_PORT 4318
PYROSCOPE_PORT 4040
GRAFANA_PORT 3000
PROMETHEUS_PORT 9090
TEMPO_PORT 3200
LOKI_PORT 3100

Database: the PostgreSQL port

The PostgreSQL adapter the stack's services keep their databases on:

  • supabase: local Supabase, started by make up through its CLI (default)
  • postgres: plain PostgreSQL, the postgres profile

db-init creates a role and a database for each service on either.

Setting In .env.example
STACKR_DATABASE supabase

The plain PostgreSQL adapter's admin password and published port. Local Supabase's are fixed: postgres, on port 54322.

Setting In .env.example
POSTGRES_ADMIN_PASSWORD Generated: 64 hex characters
POSTGRES_PORT 55432

The Redis protocol, with Valkey

Setting In .env.example
REDIS_PASSWORD Generated: 64 hex characters

Object storage: the S3 port, with MinIO

Setting In .env.example
S3_ACCESS_KEY_ID stackr
S3_SECRET_ACCESS_KEY Generated: 64 hex characters
S3_REGION auto
MINIO_PORT 9000
MINIO_CONSOLE_PORT 9001

Langfuse

Setting In .env.example
LANGFUSE_PORT 3300
LANGFUSE_DB_PASSWORD Generated: 64 hex characters
CLICKHOUSE_PASSWORD Generated: 64 hex characters

SALT and ENCRYPTION_KEY must never change once Langfuse has data.

Setting In .env.example
LANGFUSE_SALT Generated: 43 URL-safe characters
LANGFUSE_ENCRYPTION_KEY Generated: 64 hex characters
LANGFUSE_NEXTAUTH_SECRET Generated: 43 URL-safe characters

Created on first start: an organisation and project, the project's API keys, and an admin user who signs in with this email and password.

Setting In .env.example
LANGFUSE_INIT_ORG_ID stackr
LANGFUSE_INIT_PROJECT_ID stackr
LANGFUSE_PUBLIC_KEY Generated: pk-lf- and a UUID
LANGFUSE_SECRET_KEY Generated: sk-lf- and a UUID
LANGFUSE_ADMIN_EMAIL admin@stackr.local
LANGFUSE_ADMIN_PASSWORD Generated: 43 URL-safe characters

The Collector's credentials for Langfuse's OTLP endpoint, derived from the project's keys.

Setting In .env.example
LANGFUSE_OTLP_AUTH Derived: base64 of LANGFUSE_PUBLIC_KEY:LANGFUSE_SECRET_KEY, for HTTP Basic

The LLM gateway: LiteLLM

Setting In .env.example
LITELLM_PORT 4400

The master key administers the proxy (teams, keys, the admin UI at /ui, as admin); applications use team keys from scripts/create-tenant instead.

Setting In .env.example
LITELLM_MASTER_KEY Generated: sk- and 43 URL-safe characters

Encrypts credentials the proxy stores; must never change.

Setting In .env.example
LITELLM_SALT_KEY Generated: 43 URL-safe characters
LITELLM_DB_PASSWORD Generated: 64 hex characters

Provider keys. A model whose key is empty fails; the others still work.

Setting In .env.example
ANTHROPIC_API_KEY Empty
OPENAI_API_KEY Empty
GEMINI_API_KEY Empty
OPENROUTER_API_KEY Empty

Local model servers on this machine, as the gateway's container sees them.

Setting In .env.example
LM_STUDIO_API_BASE http://host.docker.internal:1234/v1
OMLX_API_BASE http://host.docker.internal:4243/v1

The file

The whole file: .env.example
# stackr's local settings.
#
# `make env` (scripts/setup-env) copies this file to `.env` and replaces every
# `generate:...` value with a fresh secret. Running it again keeps the values
# already in `.env` and adds keys that are new here. Never commit `.env`.
#
# Everything here is for local development and single hosts.

# The host address published ports bind to. 127.0.0.1 keeps every service
# reachable from this machine only.
STACKR_BIND=127.0.0.1

# The deployment environment telemetry is labelled with
# (deployment.environment.name), when an application doesn't set its own.
STACKR_ENVIRONMENT=local

# --- observability ---------------------------------------------------------

# Grafana signs in as `admin` with this password.
GRAFANA_ADMIN_PASSWORD=generate:token

# Published ports. Applications send OTLP to the Collector on 4317 (gRPC) or
# 4318 (HTTP), and profiles to Pyroscope on 4040.
OTLP_GRPC_PORT=4317
OTLP_HTTP_PORT=4318
PYROSCOPE_PORT=4040
GRAFANA_PORT=3000
PROMETHEUS_PORT=9090
TEMPO_PORT=3200
LOKI_PORT=3100

# --- database: the PostgreSQL port -------------------------------------------

# The PostgreSQL adapter the stack's services keep their databases on:
#   supabase  local Supabase, started by `make up` through its CLI (default)
#   postgres  plain PostgreSQL, the `postgres` profile
# db-init creates a role and a database for each service on either.
STACKR_DATABASE=supabase
# The plain PostgreSQL adapter's admin password and published port. Local
# Supabase's are fixed: `postgres`, on port 54322.
POSTGRES_ADMIN_PASSWORD=generate:hex
POSTGRES_PORT=55432

# --- the Redis protocol, with Valkey -----------------------------------------

REDIS_PASSWORD=generate:hex

# --- object storage: the S3 port, with MinIO ---------------------------------

S3_ACCESS_KEY_ID=stackr
S3_SECRET_ACCESS_KEY=generate:hex
S3_REGION=auto
MINIO_PORT=9000
MINIO_CONSOLE_PORT=9001

# --- langfuse ----------------------------------------------------------------

LANGFUSE_PORT=3300
LANGFUSE_DB_PASSWORD=generate:hex
CLICKHOUSE_PASSWORD=generate:hex
# SALT and ENCRYPTION_KEY must never change once Langfuse has data.
LANGFUSE_SALT=generate:token
LANGFUSE_ENCRYPTION_KEY=generate:hex
LANGFUSE_NEXTAUTH_SECRET=generate:token

# Created on first start: an organisation and project, the project's API keys,
# and an admin user who signs in with this email and password.
LANGFUSE_INIT_ORG_ID=stackr
LANGFUSE_INIT_PROJECT_ID=stackr
LANGFUSE_PUBLIC_KEY=generate:uuid:pk-lf-
LANGFUSE_SECRET_KEY=generate:uuid:sk-lf-
LANGFUSE_ADMIN_EMAIL=admin@stackr.local
LANGFUSE_ADMIN_PASSWORD=generate:token

# The Collector's credentials for Langfuse's OTLP endpoint, derived from the
# project's keys.
LANGFUSE_OTLP_AUTH=basic-auth:LANGFUSE_PUBLIC_KEY:LANGFUSE_SECRET_KEY

# --- the LLM gateway: LiteLLM ------------------------------------------------

LITELLM_PORT=4400
# The master key administers the proxy (teams, keys, the admin UI at /ui, as
# `admin`); applications use team keys from scripts/create-tenant instead.
LITELLM_MASTER_KEY=generate:token:sk-
# Encrypts credentials the proxy stores; must never change.
LITELLM_SALT_KEY=generate:token
LITELLM_DB_PASSWORD=generate:hex

# Provider keys. A model whose key is empty fails; the others still work.
ANTHROPIC_API_KEY=
OPENAI_API_KEY=
GEMINI_API_KEY=
OPENROUTER_API_KEY=

# Local model servers on this machine, as the gateway's container sees them.
LM_STUDIO_API_BASE=http://host.docker.internal:1234/v1
OMLX_API_BASE=http://host.docker.internal:4243/v1