Environment variables
Every configuration key can be set from the environment, so a container needs no configuration file for anything that is not a list of tables.
Naming
Section titled “Naming”A key section.key is the variable GUARD_SECTION_KEY, in upper case:
server.http_port is GUARD_SERVER_HTTP_PORT, and storage.pool_size is
GUARD_STORAGE_POOL_SIZE. The full list is below.
- Files. Any variable
Xalso acceptsX_FILE, the path of a file holding the value, so a secret can be a mounted file and never appear inkubectl describe, in/proc/<pid>/environor in a crash dump. One trailing newline is dropped. Setting bothXandX_FILEis an error that names both. - Types. Booleans are
trueorfalse(1and0also work). Lists are comma-separated:GUARD_SERVER_TRUSTED_PROXIES=10.0.0.1,10.0.0.2. - Not settable. Lists of tables (
events.invalid_login_bands,events.login_protection.block_schedule) and the per-event-type level map (events.origin_levels) have no flat name. Keep them in the file. - Precedence, lowest to highest: built-in defaults, the configuration
file, the standard
OTEL_*variables, thenGUARD_*. The environment wins over the file. - Check before you roll out.
idp-server config checkloads the configuration exactly asservewould, environment included, validates it without touching the network, and exits non-zero with the reason.--printwrites the effective values as TOML with secrets redacted. An unknownGUARD_*variable is an error there (a typo such asGUARD_SERVER_HTTP_PROTnames the variable you meant);serveonly warns, so a stray variable cannot stop a boot.
In Kubernetes
Section titled “In Kubernetes”A Service named guard makes Kubernetes inject GUARD_SERVICE_HOST,
GUARD_SERVICE_PORT and GUARD_PORT* into every pod in the namespace. They are
ignored here, and the chart sets enableServiceLinks: false so they are not
injected at all.
Telemetry
Section titled “Telemetry”Telemetry is configured with the standard OpenTelemetry variables, which sit below the service’s own names in precedence.
| Variable | Sets | Notes |
|---|---|---|
OTEL_EXPORTER_OTLP_ENDPOINT |
observability.endpoint |
Naming a collector turns telemetry on, unless OTEL_SDK_DISABLED=true. |
OTEL_SDK_DISABLED |
observability.enabled |
true turns it off. |
OTEL_EXPORTER_OTLP_PROTOCOL |
observability.protocol |
Only http/protobuf is supported; another value is a configuration error. |
OTEL_SERVICE_NAME |
observability.service_name |
|
OTEL_RESOURCE_ATTRIBUTES |
observability.resource_attributes |
k=v,k=v |
OTEL_TRACES_SAMPLER, OTEL_TRACES_SAMPLER_ARG |
observability.sample_ratio, observability.parent_based |
always_on, always_off, traceidratio (with the argument), each optionally parentbased_. |
OTEL_TRACES_EXPORTER, OTEL_LOGS_EXPORTER |
observability.traces, observability.logs |
none turns that signal off. |
Configuration keys
Section titled “Configuration keys”[clients]
Section titled “[clients]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_CLIENTS_ALLOWED_CUSTOM_ORIGIN_SCHEMES |
clients.allowed_custom_origin_schemes |
list (comma-separated) | [] |
GUARD_CLIENTS_CLEANUP_INTERVAL_SECONDS |
clients.cleanup_interval_seconds |
integer | 3600 |
GUARD_CLIENTS_CLEANUP_NEVER_USED_GRACE_SECONDS |
clients.cleanup_never_used_grace_seconds |
integer | 3600 |
GUARD_CLIENTS_CLEANUP_UNUSED_DAYS |
clients.cleanup_unused_days |
integer | 0 |
GUARD_CLIENTS_DANGER_ALLOW_EPHEMERAL_RESOURCES_WITHOUT_LIST |
clients.danger_allow_ephemeral_resources_without_list |
boolean | false |
GUARD_CLIENTS_DANGER_ALLOW_LOOPBACK_PORT_REDIRECTS |
clients.danger_allow_loopback_port_redirects |
boolean | false |
GUARD_CLIENTS_DANGER_STRIP_UNSUPPORTED_EPHEMERAL_GRANTS |
clients.danger_strip_unsupported_ephemeral_grants |
boolean | false |
GUARD_CLIENTS_DYNAMIC_ACCESS_TOKEN_LIFETIME_SECONDS |
clients.dynamic_access_token_lifetime_seconds |
integer | 1800 |
GUARD_CLIENTS_DYNAMIC_ALLOWED_SCOPES |
clients.dynamic_allowed_scopes |
list (comma-separated) | ["openid", "profile", "email", "offline_access", "groups"] |
GUARD_CLIENTS_DYNAMIC_AUTO_ROTATE_REGISTRATION_TOKEN |
clients.dynamic_auto_rotate_registration_token |
boolean | true |
GUARD_CLIENTS_DYNAMIC_DEFAULT_SCOPES |
clients.dynamic_default_scopes |
list (comma-separated) | ["openid", "profile"] |
GUARD_CLIENTS_DYNAMIC_REGISTRATION_ENABLED |
clients.dynamic_registration_enabled |
boolean | false |
GUARD_CLIENTS_DYNAMIC_REGISTRATION_RATE_LIMIT_SECONDS |
clients.dynamic_registration_rate_limit_seconds |
integer | 60 |
GUARD_CLIENTS_DYNAMIC_REGISTRATION_TOKEN |
clients.dynamic_registration_token |
string | "operator-issued-registration-token" |
GUARD_CLIENTS_EPHEMERAL_CACHE_TTL_SECONDS |
clients.ephemeral_cache_ttl_seconds |
integer | 3600 |
GUARD_CLIENTS_EPHEMERAL_CLIENTS_ENABLED |
clients.ephemeral_clients_enabled |
boolean | false |
GUARD_CLIENTS_EPHEMERAL_FORCE_MFA |
clients.ephemeral_force_mfa |
boolean | false |
GUARD_CLIENTS_EPHEMERAL_GRANT_TYPES |
clients.ephemeral_grant_types |
list (comma-separated) | ["authorization_code"] |
[cluster]
Section titled “[cluster]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_CLUSTER_NODE_NAME |
cluster.node_name |
string | "node-1" |
[device_grant]
Section titled “[device_grant]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_DEVICE_GRANT_CODE_LIFETIME_SECS |
device_grant.code_lifetime_secs |
integer | 300 |
GUARD_DEVICE_GRANT_POLL_INTERVAL_SECS |
device_grant.poll_interval_secs |
integer | 5 |
GUARD_DEVICE_GRANT_RATE_LIMIT_SECS |
device_grant.rate_limit_secs |
integer | 1 |
GUARD_DEVICE_GRANT_REFRESH_LIFETIME_HOURS |
device_grant.refresh_lifetime_hours |
integer | 72 |
GUARD_DEVICE_GRANT_USER_CODE_LENGTH |
device_grant.user_code_length |
integer | 8 |
[encryption]
Section titled “[encryption]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_ENCRYPTION_KEK_ADDRESS |
encryption.kek_address |
string | "https://vault.internal:8200" |
GUARD_ENCRYPTION_KEK_MANAGER |
encryption.kek_manager |
string | "vault" |
GUARD_ENCRYPTION_KEK_MOUNT |
encryption.kek_mount |
string | "secret" |
GUARD_ENCRYPTION_KEK_NAMESPACE |
encryption.kek_namespace |
string | "operations" |
GUARD_ENCRYPTION_KEK_PATH |
encryption.kek_path |
string | "tinyguard/platform/kek" |
GUARD_ENCRYPTION_KEK_TOKEN_ENV |
encryption.kek_token_env |
string | "GUARD_KEK_TOKEN" |
GUARD_ENCRYPTION_WRAPPED_DEK |
encryption.wrapped_dek |
string | "./wrapped_dek.toml" |
[events]
Section titled “[events]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_EVENTS_DISABLE_RELEASE_CHECK |
events.disable_release_check |
boolean | false |
GUARD_EVENTS_EMAIL_JOBS_BATCH_DELAY_MS |
events.email_jobs.batch_delay_ms |
integer | 2000 |
GUARD_EVENTS_EMAIL_JOBS_BATCH_SIZE |
events.email_jobs.batch_size |
integer | 3 |
GUARD_EVENTS_EMAIL_JOBS_INFO_RATE_LIMIT_SECONDS |
events.email_jobs.info_rate_limit_seconds |
integer | 3600 |
GUARD_EVENTS_EMAIL_JOBS_RECOVERY_INTERVAL_SECONDS |
events.email_jobs.recovery_interval_seconds |
integer | 300 |
GUARD_EVENTS_EMAIL_JOBS_SEND_RETRY_BASE_MS |
events.email_jobs.send_retry_base_ms |
integer | 10 |
GUARD_EVENTS_EMAIL_JOBS_STALENESS_SECONDS |
events.email_jobs.staleness_seconds |
integer | 300 |
GUARD_EVENTS_EMAIL_JOBS_USER_DELAY_MS |
events.email_jobs.user_delay_ms |
integer | 10 |
GUARD_EVENTS_GENERATE_TOKEN_ISSUED |
events.generate_token_issued |
boolean | true |
GUARD_EVENTS_KEEP_ALIVE_SECONDS |
events.keep_alive_seconds |
integer | 30 |
GUARD_EVENTS_LEVEL |
events.level |
string | "info" |
GUARD_EVENTS_LEVEL_JWKS_ROTATE |
events.level_jwks_rotate |
string | "notice" |
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_BLACKLIST_SECS |
events.login_protection.stuffing_blacklist_secs |
integer | 86400 |
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_THRESHOLD |
events.login_protection.stuffing_threshold |
integer | 15 |
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_WINDOW_SECS |
events.login_protection.stuffing_window_secs |
integer | 10800 |
GUARD_EVENTS_NOTIFY_EMAIL_FROM_ADDRESS |
events.notify.email.from_address |
string | "idp@example.com" |
GUARD_EVENTS_NOTIFY_EMAIL_RECIPIENT_ADDRESS |
events.notify.email.recipient_address |
string | "ops@example.com" |
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_HOST |
events.notify.email.smtp_host |
string | "relay.example" |
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_PASSWORD |
events.notify.email.smtp_password |
string | "relay-password" |
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_PORT |
events.notify.email.smtp_port |
integer | 587 |
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_USERNAME |
events.notify.email.smtp_username |
string | "relay-user" |
GUARD_EVENTS_NOTIFY_EMAIL_THEME |
events.notify.email.theme |
string | "light" |
GUARD_EVENTS_NOTIFY_MATRIX_ACCESS_TOKEN |
events.notify.matrix.access_token |
string | "syt-..." |
GUARD_EVENTS_NOTIFY_MATRIX_HOMESERVER_URL |
events.notify.matrix.homeserver_url |
string | "https://matrix.example" |
GUARD_EVENTS_NOTIFY_MATRIX_PASSWORD |
events.notify.matrix.password |
string | "svc-password" |
GUARD_EVENTS_NOTIFY_MATRIX_ROOM_ID |
events.notify.matrix.room_id |
string | "!room:example.org" |
GUARD_EVENTS_NOTIFY_MATRIX_USERNAME |
events.notify.matrix.username |
string | "svc-user" |
GUARD_EVENTS_NOTIFY_NOTIFY_EMAIL_ENABLED |
events.notify.notify_email_enabled |
boolean | false |
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_EMAIL |
events.notify.notify_level_email |
string | "warning" |
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_MATRIX |
events.notify.notify_level_matrix |
string | "notice" |
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_SLACK |
events.notify.notify_level_slack |
string | "notice" |
GUARD_EVENTS_NOTIFY_NOTIFY_MATRIX_ENABLED |
events.notify.notify_matrix_enabled |
boolean | false |
GUARD_EVENTS_NOTIFY_NOTIFY_SLACK_ENABLED |
events.notify.notify_slack_enabled |
boolean | false |
GUARD_EVENTS_NOTIFY_NOTIFY_SUBJECT_PREFIX |
events.notify.notify_subject_prefix |
string | "[idp]" |
GUARD_EVENTS_NOTIFY_OUTBOUND_ALLOWED_PRIVATE_NETWORKS |
events.notify.outbound.allowed_private_networks |
list (comma-separated) | ["10.20.0.0/16"] |
GUARD_EVENTS_NOTIFY_OUTBOUND_CUSTOM_CA_PATH |
events.notify.outbound.custom_ca_path |
string | "/etc/ca.pem" |
GUARD_EVENTS_NOTIFY_OUTBOUND_DANGER_ACCEPT_INVALID_CERTS |
events.notify.outbound.danger_accept_invalid_certs |
boolean | false |
GUARD_EVENTS_NOTIFY_SLACK_WEBHOOK_URL |
events.notify.slack.webhook_url |
string | "https://hooks.example/services/..." |
GUARD_EVENTS_RETAIN_DAYS |
events.retain_days |
integer | 31 |
GUARD_EVENTS_RETRY_SECONDS |
events.retry_seconds |
integer | 10 |
[fedcm]
Section titled “[fedcm]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_FEDCM_ENABLED |
fedcm.enabled |
boolean | false |
[federation]
Section titled “[federation]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_FEDERATION_ENABLED |
federation.enabled |
boolean | false |
[hashing]
Section titled “[hashing]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_HASHING_ARGON2_M_COST |
hashing.argon2_m_cost |
integer | 19456 |
GUARD_HASHING_ARGON2_P_COST |
hashing.argon2_p_cost |
integer | 1 |
GUARD_HASHING_ARGON2_T_COST |
hashing.argon2_t_cost |
integer | 2 |
GUARD_HASHING_MAX_HASH_THREADS |
hashing.max_hash_threads |
integer | 2 |
[health]
Section titled “[health]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_HEALTH_GRACE_WINDOW_SECONDS |
health.grace_window_seconds |
integer | 30 |
[lifetimes]
Section titled “[lifetimes]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_LIFETIMES_JWK_AUTOROTATE_CRON |
lifetimes.jwk_autorotate_cron |
string | "0 30 3 1 * * *" |
[logging]
Section titled “[logging]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_LOGGING_FORMAT |
logging.format |
string | "plain" |
GUARD_LOGGING_LEVEL |
logging.level |
string | "info" |
[observability]
Section titled “[observability]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_OBSERVABILITY_ALLOW_INSECURE_ENDPOINT |
observability.allow_insecure_endpoint |
boolean | false |
GUARD_OBSERVABILITY_BATCH_DELAY_MS |
observability.batch_delay_ms |
integer | 5000 |
GUARD_OBSERVABILITY_BATCH_EXPORT_SIZE |
observability.batch_export_size |
integer | 512 |
GUARD_OBSERVABILITY_BATCH_QUEUE_SIZE |
observability.batch_queue_size |
integer | 2048 |
GUARD_OBSERVABILITY_ENABLED |
observability.enabled |
boolean | false |
GUARD_OBSERVABILITY_ENDPOINT |
observability.endpoint |
string | "http://localhost:4318" |
GUARD_OBSERVABILITY_EXPORT_TIMEOUT_MS |
observability.export_timeout_ms |
integer | 10000 |
GUARD_OBSERVABILITY_LOGS |
observability.logs |
boolean | true |
GUARD_OBSERVABILITY_PARENT_BASED |
observability.parent_based |
boolean | true |
GUARD_OBSERVABILITY_PROTOCOL |
observability.protocol |
string | "http/protobuf" |
GUARD_OBSERVABILITY_RESOURCE_ATTRIBUTES |
observability.resource_attributes |
list (comma-separated) | ["deployment.environment=production"] |
GUARD_OBSERVABILITY_SAMPLE_RATIO |
observability.sample_ratio |
number | 1.0 |
GUARD_OBSERVABILITY_SERVICE_NAME |
observability.service_name |
string | "tinyguard" |
GUARD_OBSERVABILITY_TRACES |
observability.traces |
boolean | true |
[security]
Section titled “[security]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_SECURITY_BLACKLIST |
security.blacklist |
list (comma-separated) | [] |
GUARD_SECURITY_BLACKLIST_MINUTES |
security.blacklist_minutes |
integer | 5 |
GUARD_SECURITY_SCAN_TARGET_PATHS |
security.scan_target_paths |
list (comma-separated) | ["/wp-admin", "/.env"] |
[server]
Section titled “[server]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_SERVER_CONSOLE_STATIC_DIR |
server.console_static_dir |
string | "/app/console" |
GUARD_SERVER_DOCS_ENABLED |
server.docs.enabled |
boolean | false |
GUARD_SERVER_DOCS_PUBLIC |
server.docs.public |
boolean | false |
GUARD_SERVER_GRACEFUL_SHUTDOWN_SECONDS |
server.graceful_shutdown_seconds |
integer | 10 |
GUARD_SERVER_HTTP_PORT |
server.http_port |
integer | 8080 |
GUARD_SERVER_HTTP_WORKERS |
server.http_workers |
integer | 0 |
GUARD_SERVER_HTTPS_PORT |
server.https_port |
integer | 8443 |
GUARD_SERVER_LISTEN_HOST |
server.listen_host |
string | "0.0.0.0" |
GUARD_SERVER_LISTEN_SCHEME |
server.listen_scheme |
string | "http" |
GUARD_SERVER_METRICS_ENABLED |
server.metrics.enabled |
boolean | false |
GUARD_SERVER_METRICS_LISTEN_HOST |
server.metrics.listen_host |
string | "0.0.0.0" |
GUARD_SERVER_METRICS_PORT |
server.metrics.port |
integer | 9090 |
GUARD_SERVER_PROXY_ENABLED |
server.proxy_enabled |
boolean | false |
GUARD_SERVER_PUBLIC_URL |
server.public_url |
string | "localhost:8080" |
GUARD_SERVER_TLS_CERT_PATH |
server.tls.cert_path |
string | "tls/tls.crt" |
GUARD_SERVER_TLS_KEY_PATH |
server.tls.key_path |
string | "tls/tls.key" |
GUARD_SERVER_TLS_SELF_SIGNED |
server.tls.self_signed |
boolean | false |
GUARD_SERVER_TLS_CERT_DIR |
server.tls_cert_dir |
string | "/app/tls-hostnames" |
GUARD_SERVER_TRUSTED_PROXIES |
server.trusted_proxies |
list (comma-separated) | ["10.0.0.0/8"] |
GUARD_SERVER_UNIX_SOCKET_PATH |
server.unix_socket_path |
string | "/run/idp/server.sock" |
GUARD_SERVER_WHOAMI_HEADERS |
server.whoami_headers |
boolean | false |
[storage]
Section titled “[storage]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_STORAGE_AUTO_MIGRATE |
storage.auto_migrate |
boolean | true |
GUARD_STORAGE_CA_FILE |
storage.ca_file |
string | "/etc/ssl/pg-ca.pem" |
GUARD_STORAGE_CONNECT_TIMEOUT_SECONDS |
storage.connect_timeout_seconds |
integer | 10 |
GUARD_STORAGE_DATA_DIRECTORY |
storage.data_directory |
string | "./data" |
GUARD_STORAGE_DB_NAME |
storage.db_name |
string | "idp" |
GUARD_STORAGE_HOST |
storage.host |
string | "localhost" |
GUARD_STORAGE_MODE |
storage.mode |
string | "embedded" |
GUARD_STORAGE_PASSWORD |
storage.password |
string | "$SECRETS.pg_password" |
GUARD_STORAGE_POOL_SIZE |
storage.pool_size |
integer | 10 |
GUARD_STORAGE_PORT |
storage.port |
integer | 5432 |
GUARD_STORAGE_SCHEMA |
storage.schema |
string | "tinyguard" |
GUARD_STORAGE_STATEMENT_TIMEOUT_SECONDS |
storage.statement_timeout_seconds |
integer | 30 |
GUARD_STORAGE_TLS_MODE |
storage.tls_mode |
string | "verify-full" |
GUARD_STORAGE_USER |
storage.user |
string | "idp" |
[tenants]
Section titled “[tenants]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_TENANTS_DNS_RESOLVERS |
tenants.dns_resolvers |
list (comma-separated) | ["1.1.1.1", "9.9.9.9:53"] |
GUARD_TENANTS_DOMAIN_CLAIM_DAYS |
tenants.domain_claim_days |
integer | 14 |
GUARD_TENANTS_DOMAIN_GRACE_DAYS |
tenants.domain_grace_days |
integer | 14 |
GUARD_TENANTS_DOMAIN_RECHECK_HOURS |
tenants.domain_recheck_hours |
integer | 24 |
GUARD_TENANTS_ENABLED |
tenants.enabled |
boolean | false |
GUARD_TENANTS_HOSTNAME_SUFFIX |
tenants.hostname_suffix |
string | "guard.example.com" |
GUARD_TENANTS_TENANT_HOSTNAMES |
tenants.tenant_hostnames |
boolean | false |
[users]
Section titled “[users]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_USERS_ACTION_LINK_LIFETIME_MINUTES |
users.action_link_lifetime_minutes |
integer | 30 |
GUARD_USERS_ALLOW_OPEN_REDIRECTS |
users.allow_open_redirects |
boolean | false |
GUARD_USERS_FORCE_ADMIN_MFA |
users.force_admin_mfa |
boolean | false |
GUARD_USERS_LIST_MODE_THRESHOLD |
users.list_mode_threshold |
integer | 1000 |
GUARD_USERS_PICTURE_SIZE_LIMIT_BYTES |
users.picture_size_limit_bytes |
integer | 524288 |
GUARD_USERS_PICTURE_STORAGE |
users.picture_storage |
string | "disabled" |
GUARD_USERS_PREFERRED_USERNAME_BLACKLIST |
users.preferred_username_blacklist |
list (comma-separated) | ["admin", "root"] |
GUARD_USERS_PREFERRED_USERNAME_IMMUTABLE |
users.preferred_username_immutable |
boolean | false |
GUARD_USERS_PREFERRED_USERNAME_REQUIRED |
users.preferred_username_required |
boolean | false |
GUARD_USERS_REGISTRATION_ENABLED |
users.registration_enabled |
boolean | false |
GUARD_USERS_RELAX_RESET_BINDING |
users.relax_reset_binding |
boolean | false |
GUARD_USERS_SELF_DELETION_ENABLED |
users.self_deletion_enabled |
boolean | false |
[webauthn]
Section titled “[webauthn]”| Variable | Key | Type | Example |
|---|---|---|---|
GUARD_WEBAUTHN_CEREMONY_LIFETIME_SECS |
webauthn.ceremony_lifetime_secs |
integer | 90 |
GUARD_WEBAUTHN_CHALLENGE_EXPIRY_SECS |
webauthn.challenge_expiry_secs |
integer | 60 |
GUARD_WEBAUTHN_FORCE_USER_VERIFICATION |
webauthn.force_user_verification |
boolean | false |
GUARD_WEBAUTHN_MFA_COOKIE_HOURS |
webauthn.mfa_cookie_hours |
integer | 2160 |
GUARD_WEBAUTHN_NO_PASSWORD_EXPIRY_WITH_PASSKEY |
webauthn.no_password_expiry_with_passkey |
boolean | false |
GUARD_WEBAUTHN_RENEW_MFA_ON_SESSION_RENEW |
webauthn.renew_mfa_on_session_renew |
boolean | false |
Other variables
Section titled “Other variables”These are not configuration keys: the server or the loader reads them directly.
A variable marked secret also takes a _FILE form (one trailing newline is
dropped; both set is an error).
| Variable | Purpose |
|---|---|
GUARD_BOOTSTRAP_ADMIN_EMAIL |
The first administrator’s address (default admin@idp.local). Read on the first boot of an empty store. |
GUARD_BOOTSTRAP_ADMIN_PASSWORD_ARGON2ID (secret) |
The first administrator’s password as an Argon2id hash. Wins over the plain form. |
GUARD_BOOTSTRAP_ADMIN_PASSWORD_PLAIN (secret) |
The first administrator’s password in clear. Without either, one is generated and printed once. |
GUARD_BOOTSTRAP_PLATFORM_API_KEY (secret) |
A provisioning credential, <name>$<secret>, holding only the tenants grant. Created or rotated on every boot. See Tenants. |
GUARD_LOCAL_TEST |
true uses the bundled demo configuration with generated secrets. Never for production. |
GUARD_VAULT_CONFIG |
true fetches the whole configuration from a vault-style source, set by GUARD_VAULT_ADDR, GUARD_VAULT_MOUNT, GUARD_VAULT_CONFIG_PATH and GUARD_VAULT_TOKEN (secret). |
GUARD_KEK_TOKEN (secret) |
The key-encryption-key manager’s token, when [encryption] is used and encryption.kek_token_env is not changed. |
GUARD_DEPLOYMENT_MODE |
self_hosted selects the self-hosted policy for tenant secret managers. Anything else, including unset, is the hosted policy, which fails closed. |
GUARD_AWS_PLATFORM_ROLE_ARN, GUARD_AWS_PLATFORM_CREDENTIALS_FILE |
The platform’s AWS role and credentials file for cross-account tenant secret managers (hosted deployments). |
GUARD_TENANT_TOKENS_ROOT, GUARD_TENANT_SECRETS_ROOT |
Directories of per-tenant secret-manager tokens and mounted secrets (hosted deployments). GUARD_TENANT_<SLUG>_… names carry one tenant’s token. |