Skip to content

Environment variables

Every configuration key can be set from the environment, so a container needs no configuration file for anything that is not a list of tables.

A key section.key is the variable GUARD_SECTION_KEY, in upper case: server.http_port is GUARD_SERVER_HTTP_PORT, and storage.pool_size is GUARD_STORAGE_POOL_SIZE. The full list is below.

  • Files. Any variable X also accepts X_FILE, the path of a file holding the value, so a secret can be a mounted file and never appear in kubectl describe, in /proc/<pid>/environ or in a crash dump. One trailing newline is dropped. Setting both X and X_FILE is an error that names both.
  • Types. Booleans are true or false (1 and 0 also work). Lists are comma-separated: GUARD_SERVER_TRUSTED_PROXIES=10.0.0.1,10.0.0.2.
  • Not settable. Lists of tables (events.invalid_login_bands, events.login_protection.block_schedule) and the per-event-type level map (events.origin_levels) have no flat name. Keep them in the file.
  • Precedence, lowest to highest: built-in defaults, the configuration file, the standard OTEL_* variables, then GUARD_*. The environment wins over the file.
  • Check before you roll out. idp-server config check loads the configuration exactly as serve would, environment included, validates it without touching the network, and exits non-zero with the reason. --print writes the effective values as TOML with secrets redacted. An unknown GUARD_* variable is an error there (a typo such as GUARD_SERVER_HTTP_PROT names the variable you meant); serve only warns, so a stray variable cannot stop a boot.

A Service named guard makes Kubernetes inject GUARD_SERVICE_HOST, GUARD_SERVICE_PORT and GUARD_PORT* into every pod in the namespace. They are ignored here, and the chart sets enableServiceLinks: false so they are not injected at all.

Telemetry is configured with the standard OpenTelemetry variables, which sit below the service’s own names in precedence.

Variable Sets Notes
OTEL_EXPORTER_OTLP_ENDPOINT observability.endpoint Naming a collector turns telemetry on, unless OTEL_SDK_DISABLED=true.
OTEL_SDK_DISABLED observability.enabled true turns it off.
OTEL_EXPORTER_OTLP_PROTOCOL observability.protocol Only http/protobuf is supported; another value is a configuration error.
OTEL_SERVICE_NAME observability.service_name
OTEL_RESOURCE_ATTRIBUTES observability.resource_attributes k=v,k=v
OTEL_TRACES_SAMPLER, OTEL_TRACES_SAMPLER_ARG observability.sample_ratio, observability.parent_based always_on, always_off, traceidratio (with the argument), each optionally parentbased_.
OTEL_TRACES_EXPORTER, OTEL_LOGS_EXPORTER observability.traces, observability.logs none turns that signal off.
Variable Key Type Example
GUARD_CLIENTS_ALLOWED_CUSTOM_ORIGIN_SCHEMES clients.allowed_custom_origin_schemes list (comma-separated) []
GUARD_CLIENTS_CLEANUP_INTERVAL_SECONDS clients.cleanup_interval_seconds integer 3600
GUARD_CLIENTS_CLEANUP_NEVER_USED_GRACE_SECONDS clients.cleanup_never_used_grace_seconds integer 3600
GUARD_CLIENTS_CLEANUP_UNUSED_DAYS clients.cleanup_unused_days integer 0
GUARD_CLIENTS_DANGER_ALLOW_EPHEMERAL_RESOURCES_WITHOUT_LIST clients.danger_allow_ephemeral_resources_without_list boolean false
GUARD_CLIENTS_DANGER_ALLOW_LOOPBACK_PORT_REDIRECTS clients.danger_allow_loopback_port_redirects boolean false
GUARD_CLIENTS_DANGER_STRIP_UNSUPPORTED_EPHEMERAL_GRANTS clients.danger_strip_unsupported_ephemeral_grants boolean false
GUARD_CLIENTS_DYNAMIC_ACCESS_TOKEN_LIFETIME_SECONDS clients.dynamic_access_token_lifetime_seconds integer 1800
GUARD_CLIENTS_DYNAMIC_ALLOWED_SCOPES clients.dynamic_allowed_scopes list (comma-separated) ["openid", "profile", "email", "offline_access", "groups"]
GUARD_CLIENTS_DYNAMIC_AUTO_ROTATE_REGISTRATION_TOKEN clients.dynamic_auto_rotate_registration_token boolean true
GUARD_CLIENTS_DYNAMIC_DEFAULT_SCOPES clients.dynamic_default_scopes list (comma-separated) ["openid", "profile"]
GUARD_CLIENTS_DYNAMIC_REGISTRATION_ENABLED clients.dynamic_registration_enabled boolean false
GUARD_CLIENTS_DYNAMIC_REGISTRATION_RATE_LIMIT_SECONDS clients.dynamic_registration_rate_limit_seconds integer 60
GUARD_CLIENTS_DYNAMIC_REGISTRATION_TOKEN clients.dynamic_registration_token string "operator-issued-registration-token"
GUARD_CLIENTS_EPHEMERAL_CACHE_TTL_SECONDS clients.ephemeral_cache_ttl_seconds integer 3600
GUARD_CLIENTS_EPHEMERAL_CLIENTS_ENABLED clients.ephemeral_clients_enabled boolean false
GUARD_CLIENTS_EPHEMERAL_FORCE_MFA clients.ephemeral_force_mfa boolean false
GUARD_CLIENTS_EPHEMERAL_GRANT_TYPES clients.ephemeral_grant_types list (comma-separated) ["authorization_code"]
Variable Key Type Example
GUARD_CLUSTER_NODE_NAME cluster.node_name string "node-1"
Variable Key Type Example
GUARD_DEVICE_GRANT_CODE_LIFETIME_SECS device_grant.code_lifetime_secs integer 300
GUARD_DEVICE_GRANT_POLL_INTERVAL_SECS device_grant.poll_interval_secs integer 5
GUARD_DEVICE_GRANT_RATE_LIMIT_SECS device_grant.rate_limit_secs integer 1
GUARD_DEVICE_GRANT_REFRESH_LIFETIME_HOURS device_grant.refresh_lifetime_hours integer 72
GUARD_DEVICE_GRANT_USER_CODE_LENGTH device_grant.user_code_length integer 8
Variable Key Type Example
GUARD_ENCRYPTION_KEK_ADDRESS encryption.kek_address string "https://vault.internal:8200"
GUARD_ENCRYPTION_KEK_MANAGER encryption.kek_manager string "vault"
GUARD_ENCRYPTION_KEK_MOUNT encryption.kek_mount string "secret"
GUARD_ENCRYPTION_KEK_NAMESPACE encryption.kek_namespace string "operations"
GUARD_ENCRYPTION_KEK_PATH encryption.kek_path string "tinyguard/platform/kek"
GUARD_ENCRYPTION_KEK_TOKEN_ENV encryption.kek_token_env string "GUARD_KEK_TOKEN"
GUARD_ENCRYPTION_WRAPPED_DEK encryption.wrapped_dek string "./wrapped_dek.toml"
Variable Key Type Example
GUARD_EVENTS_DISABLE_RELEASE_CHECK events.disable_release_check boolean false
GUARD_EVENTS_EMAIL_JOBS_BATCH_DELAY_MS events.email_jobs.batch_delay_ms integer 2000
GUARD_EVENTS_EMAIL_JOBS_BATCH_SIZE events.email_jobs.batch_size integer 3
GUARD_EVENTS_EMAIL_JOBS_INFO_RATE_LIMIT_SECONDS events.email_jobs.info_rate_limit_seconds integer 3600
GUARD_EVENTS_EMAIL_JOBS_RECOVERY_INTERVAL_SECONDS events.email_jobs.recovery_interval_seconds integer 300
GUARD_EVENTS_EMAIL_JOBS_SEND_RETRY_BASE_MS events.email_jobs.send_retry_base_ms integer 10
GUARD_EVENTS_EMAIL_JOBS_STALENESS_SECONDS events.email_jobs.staleness_seconds integer 300
GUARD_EVENTS_EMAIL_JOBS_USER_DELAY_MS events.email_jobs.user_delay_ms integer 10
GUARD_EVENTS_GENERATE_TOKEN_ISSUED events.generate_token_issued boolean true
GUARD_EVENTS_KEEP_ALIVE_SECONDS events.keep_alive_seconds integer 30
GUARD_EVENTS_LEVEL events.level string "info"
GUARD_EVENTS_LEVEL_JWKS_ROTATE events.level_jwks_rotate string "notice"
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_BLACKLIST_SECS events.login_protection.stuffing_blacklist_secs integer 86400
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_THRESHOLD events.login_protection.stuffing_threshold integer 15
GUARD_EVENTS_LOGIN_PROTECTION_STUFFING_WINDOW_SECS events.login_protection.stuffing_window_secs integer 10800
GUARD_EVENTS_NOTIFY_EMAIL_FROM_ADDRESS events.notify.email.from_address string "idp@example.com"
GUARD_EVENTS_NOTIFY_EMAIL_RECIPIENT_ADDRESS events.notify.email.recipient_address string "ops@example.com"
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_HOST events.notify.email.smtp_host string "relay.example"
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_PASSWORD events.notify.email.smtp_password string "relay-password"
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_PORT events.notify.email.smtp_port integer 587
GUARD_EVENTS_NOTIFY_EMAIL_SMTP_USERNAME events.notify.email.smtp_username string "relay-user"
GUARD_EVENTS_NOTIFY_EMAIL_THEME events.notify.email.theme string "light"
GUARD_EVENTS_NOTIFY_MATRIX_ACCESS_TOKEN events.notify.matrix.access_token string "syt-..."
GUARD_EVENTS_NOTIFY_MATRIX_HOMESERVER_URL events.notify.matrix.homeserver_url string "https://matrix.example"
GUARD_EVENTS_NOTIFY_MATRIX_PASSWORD events.notify.matrix.password string "svc-password"
GUARD_EVENTS_NOTIFY_MATRIX_ROOM_ID events.notify.matrix.room_id string "!room:example.org"
GUARD_EVENTS_NOTIFY_MATRIX_USERNAME events.notify.matrix.username string "svc-user"
GUARD_EVENTS_NOTIFY_NOTIFY_EMAIL_ENABLED events.notify.notify_email_enabled boolean false
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_EMAIL events.notify.notify_level_email string "warning"
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_MATRIX events.notify.notify_level_matrix string "notice"
GUARD_EVENTS_NOTIFY_NOTIFY_LEVEL_SLACK events.notify.notify_level_slack string "notice"
GUARD_EVENTS_NOTIFY_NOTIFY_MATRIX_ENABLED events.notify.notify_matrix_enabled boolean false
GUARD_EVENTS_NOTIFY_NOTIFY_SLACK_ENABLED events.notify.notify_slack_enabled boolean false
GUARD_EVENTS_NOTIFY_NOTIFY_SUBJECT_PREFIX events.notify.notify_subject_prefix string "[idp]"
GUARD_EVENTS_NOTIFY_OUTBOUND_ALLOWED_PRIVATE_NETWORKS events.notify.outbound.allowed_private_networks list (comma-separated) ["10.20.0.0/16"]
GUARD_EVENTS_NOTIFY_OUTBOUND_CUSTOM_CA_PATH events.notify.outbound.custom_ca_path string "/etc/ca.pem"
GUARD_EVENTS_NOTIFY_OUTBOUND_DANGER_ACCEPT_INVALID_CERTS events.notify.outbound.danger_accept_invalid_certs boolean false
GUARD_EVENTS_NOTIFY_SLACK_WEBHOOK_URL events.notify.slack.webhook_url string "https://hooks.example/services/..."
GUARD_EVENTS_RETAIN_DAYS events.retain_days integer 31
GUARD_EVENTS_RETRY_SECONDS events.retry_seconds integer 10
Variable Key Type Example
GUARD_FEDCM_ENABLED fedcm.enabled boolean false
Variable Key Type Example
GUARD_FEDERATION_ENABLED federation.enabled boolean false
Variable Key Type Example
GUARD_HASHING_ARGON2_M_COST hashing.argon2_m_cost integer 19456
GUARD_HASHING_ARGON2_P_COST hashing.argon2_p_cost integer 1
GUARD_HASHING_ARGON2_T_COST hashing.argon2_t_cost integer 2
GUARD_HASHING_MAX_HASH_THREADS hashing.max_hash_threads integer 2
Variable Key Type Example
GUARD_HEALTH_GRACE_WINDOW_SECONDS health.grace_window_seconds integer 30
Variable Key Type Example
GUARD_LIFETIMES_JWK_AUTOROTATE_CRON lifetimes.jwk_autorotate_cron string "0 30 3 1 * * *"
Variable Key Type Example
GUARD_LOGGING_FORMAT logging.format string "plain"
GUARD_LOGGING_LEVEL logging.level string "info"
Variable Key Type Example
GUARD_OBSERVABILITY_ALLOW_INSECURE_ENDPOINT observability.allow_insecure_endpoint boolean false
GUARD_OBSERVABILITY_BATCH_DELAY_MS observability.batch_delay_ms integer 5000
GUARD_OBSERVABILITY_BATCH_EXPORT_SIZE observability.batch_export_size integer 512
GUARD_OBSERVABILITY_BATCH_QUEUE_SIZE observability.batch_queue_size integer 2048
GUARD_OBSERVABILITY_ENABLED observability.enabled boolean false
GUARD_OBSERVABILITY_ENDPOINT observability.endpoint string "http://localhost:4318"
GUARD_OBSERVABILITY_EXPORT_TIMEOUT_MS observability.export_timeout_ms integer 10000
GUARD_OBSERVABILITY_LOGS observability.logs boolean true
GUARD_OBSERVABILITY_PARENT_BASED observability.parent_based boolean true
GUARD_OBSERVABILITY_PROTOCOL observability.protocol string "http/protobuf"
GUARD_OBSERVABILITY_RESOURCE_ATTRIBUTES observability.resource_attributes list (comma-separated) ["deployment.environment=production"]
GUARD_OBSERVABILITY_SAMPLE_RATIO observability.sample_ratio number 1.0
GUARD_OBSERVABILITY_SERVICE_NAME observability.service_name string "tinyguard"
GUARD_OBSERVABILITY_TRACES observability.traces boolean true
Variable Key Type Example
GUARD_SECURITY_BLACKLIST security.blacklist list (comma-separated) []
GUARD_SECURITY_BLACKLIST_MINUTES security.blacklist_minutes integer 5
GUARD_SECURITY_SCAN_TARGET_PATHS security.scan_target_paths list (comma-separated) ["/wp-admin", "/.env"]
Variable Key Type Example
GUARD_SERVER_CONSOLE_STATIC_DIR server.console_static_dir string "/app/console"
GUARD_SERVER_DOCS_ENABLED server.docs.enabled boolean false
GUARD_SERVER_DOCS_PUBLIC server.docs.public boolean false
GUARD_SERVER_GRACEFUL_SHUTDOWN_SECONDS server.graceful_shutdown_seconds integer 10
GUARD_SERVER_HTTP_PORT server.http_port integer 8080
GUARD_SERVER_HTTP_WORKERS server.http_workers integer 0
GUARD_SERVER_HTTPS_PORT server.https_port integer 8443
GUARD_SERVER_LISTEN_HOST server.listen_host string "0.0.0.0"
GUARD_SERVER_LISTEN_SCHEME server.listen_scheme string "http"
GUARD_SERVER_METRICS_ENABLED server.metrics.enabled boolean false
GUARD_SERVER_METRICS_LISTEN_HOST server.metrics.listen_host string "0.0.0.0"
GUARD_SERVER_METRICS_PORT server.metrics.port integer 9090
GUARD_SERVER_PROXY_ENABLED server.proxy_enabled boolean false
GUARD_SERVER_PUBLIC_URL server.public_url string "localhost:8080"
GUARD_SERVER_TLS_CERT_PATH server.tls.cert_path string "tls/tls.crt"
GUARD_SERVER_TLS_KEY_PATH server.tls.key_path string "tls/tls.key"
GUARD_SERVER_TLS_SELF_SIGNED server.tls.self_signed boolean false
GUARD_SERVER_TLS_CERT_DIR server.tls_cert_dir string "/app/tls-hostnames"
GUARD_SERVER_TRUSTED_PROXIES server.trusted_proxies list (comma-separated) ["10.0.0.0/8"]
GUARD_SERVER_UNIX_SOCKET_PATH server.unix_socket_path string "/run/idp/server.sock"
GUARD_SERVER_WHOAMI_HEADERS server.whoami_headers boolean false
Variable Key Type Example
GUARD_STORAGE_AUTO_MIGRATE storage.auto_migrate boolean true
GUARD_STORAGE_CA_FILE storage.ca_file string "/etc/ssl/pg-ca.pem"
GUARD_STORAGE_CONNECT_TIMEOUT_SECONDS storage.connect_timeout_seconds integer 10
GUARD_STORAGE_DATA_DIRECTORY storage.data_directory string "./data"
GUARD_STORAGE_DB_NAME storage.db_name string "idp"
GUARD_STORAGE_HOST storage.host string "localhost"
GUARD_STORAGE_MODE storage.mode string "embedded"
GUARD_STORAGE_PASSWORD storage.password string "$SECRETS.pg_password"
GUARD_STORAGE_POOL_SIZE storage.pool_size integer 10
GUARD_STORAGE_PORT storage.port integer 5432
GUARD_STORAGE_SCHEMA storage.schema string "tinyguard"
GUARD_STORAGE_STATEMENT_TIMEOUT_SECONDS storage.statement_timeout_seconds integer 30
GUARD_STORAGE_TLS_MODE storage.tls_mode string "verify-full"
GUARD_STORAGE_USER storage.user string "idp"
Variable Key Type Example
GUARD_TENANTS_DNS_RESOLVERS tenants.dns_resolvers list (comma-separated) ["1.1.1.1", "9.9.9.9:53"]
GUARD_TENANTS_DOMAIN_CLAIM_DAYS tenants.domain_claim_days integer 14
GUARD_TENANTS_DOMAIN_GRACE_DAYS tenants.domain_grace_days integer 14
GUARD_TENANTS_DOMAIN_RECHECK_HOURS tenants.domain_recheck_hours integer 24
GUARD_TENANTS_ENABLED tenants.enabled boolean false
GUARD_TENANTS_HOSTNAME_SUFFIX tenants.hostname_suffix string "guard.example.com"
GUARD_TENANTS_TENANT_HOSTNAMES tenants.tenant_hostnames boolean false
Variable Key Type Example
GUARD_USERS_ACTION_LINK_LIFETIME_MINUTES users.action_link_lifetime_minutes integer 30
GUARD_USERS_ALLOW_OPEN_REDIRECTS users.allow_open_redirects boolean false
GUARD_USERS_FORCE_ADMIN_MFA users.force_admin_mfa boolean false
GUARD_USERS_LIST_MODE_THRESHOLD users.list_mode_threshold integer 1000
GUARD_USERS_PICTURE_SIZE_LIMIT_BYTES users.picture_size_limit_bytes integer 524288
GUARD_USERS_PICTURE_STORAGE users.picture_storage string "disabled"
GUARD_USERS_PREFERRED_USERNAME_BLACKLIST users.preferred_username_blacklist list (comma-separated) ["admin", "root"]
GUARD_USERS_PREFERRED_USERNAME_IMMUTABLE users.preferred_username_immutable boolean false
GUARD_USERS_PREFERRED_USERNAME_REQUIRED users.preferred_username_required boolean false
GUARD_USERS_REGISTRATION_ENABLED users.registration_enabled boolean false
GUARD_USERS_RELAX_RESET_BINDING users.relax_reset_binding boolean false
GUARD_USERS_SELF_DELETION_ENABLED users.self_deletion_enabled boolean false
Variable Key Type Example
GUARD_WEBAUTHN_CEREMONY_LIFETIME_SECS webauthn.ceremony_lifetime_secs integer 90
GUARD_WEBAUTHN_CHALLENGE_EXPIRY_SECS webauthn.challenge_expiry_secs integer 60
GUARD_WEBAUTHN_FORCE_USER_VERIFICATION webauthn.force_user_verification boolean false
GUARD_WEBAUTHN_MFA_COOKIE_HOURS webauthn.mfa_cookie_hours integer 2160
GUARD_WEBAUTHN_NO_PASSWORD_EXPIRY_WITH_PASSKEY webauthn.no_password_expiry_with_passkey boolean false
GUARD_WEBAUTHN_RENEW_MFA_ON_SESSION_RENEW webauthn.renew_mfa_on_session_renew boolean false

These are not configuration keys: the server or the loader reads them directly. A variable marked secret also takes a _FILE form (one trailing newline is dropped; both set is an error).

Variable Purpose
GUARD_BOOTSTRAP_ADMIN_EMAIL The first administrator’s address (default admin@idp.local). Read on the first boot of an empty store.
GUARD_BOOTSTRAP_ADMIN_PASSWORD_ARGON2ID (secret) The first administrator’s password as an Argon2id hash. Wins over the plain form.
GUARD_BOOTSTRAP_ADMIN_PASSWORD_PLAIN (secret) The first administrator’s password in clear. Without either, one is generated and printed once.
GUARD_BOOTSTRAP_PLATFORM_API_KEY (secret) A provisioning credential, <name>$<secret>, holding only the tenants grant. Created or rotated on every boot. See Tenants.
GUARD_LOCAL_TEST true uses the bundled demo configuration with generated secrets. Never for production.
GUARD_VAULT_CONFIG true fetches the whole configuration from a vault-style source, set by GUARD_VAULT_ADDR, GUARD_VAULT_MOUNT, GUARD_VAULT_CONFIG_PATH and GUARD_VAULT_TOKEN (secret).
GUARD_KEK_TOKEN (secret) The key-encryption-key manager’s token, when [encryption] is used and encryption.kek_token_env is not changed.
GUARD_DEPLOYMENT_MODE self_hosted selects the self-hosted policy for tenant secret managers. Anything else, including unset, is the hosted policy, which fails closed.
GUARD_AWS_PLATFORM_ROLE_ARN, GUARD_AWS_PLATFORM_CREDENTIALS_FILE The platform’s AWS role and credentials file for cross-account tenant secret managers (hosted deployments).
GUARD_TENANT_TOKENS_ROOT, GUARD_TENANT_SECRETS_ROOT Directories of per-tenant secret-manager tokens and mounted secrets (hosted deployments). GUARD_TENANT_<SLUG>_… names carry one tenant’s token.