# Port to expose Rackpad on (default: 3000) RACKPAD_PORT=3000 # Background health-check loop interval in milliseconds MONITOR_INTERVAL_MS=300000 # Background discovery schedule and Docker status refresh intervals DISCOVERY_SCAN_SCHEDULE_INTERVAL_MS=60000 DOCKER_STATUS_SYNC_INTERVAL_MS=300000 # Optional operator-mounted directory for native SQLite snapshots. Leave empty # to keep native backup unavailable; JSON export remains available. RACKPAD_NATIVE_BACKUP_DIR= # Comma/space-separated trusted reverse-proxy IPs/CIDRs, or 0 to disable. # Example: 172.18.0.2,10.20.0.0/24. Hop counts and true/yes/on disable trust with a warning. # The public proxy must overwrite forwarding headers; restrict direct app-port access. TRUST_PROXY=0 # Optional comma-separated hostnames Rackpad should accept in production # Example: TRUSTED_HOSTS=rackpad.example.com TRUSTED_HOSTS= # Optional comma-separated browser origins Rackpad should trust in production # Example: TRUSTED_ORIGINS=https://rackpad.example.com TRUSTED_ORIGINS= # API rate limit. Disable only in isolated automated-test environments. RACKPAD_RATE_LIMIT_DISABLED=0 RACKPAD_RATE_LIMIT_MAX=600 RACKPAD_RATE_LIMIT_WINDOW=1 minute # Optional OIDC sign-in. APP_URL should be the public Rackpad origin. OIDC_ENABLED=0 APP_URL= OIDC_ISSUER_URL= OIDC_CLIENT_ID= OIDC_CLIENT_SECRET= OIDC_REDIRECT_URI= OIDC_LABEL=OIDC OIDC_DEFAULT_ROLE=viewer OIDC_CLIENT_AUTH_METHOD=client_secret_basic OIDC_SCOPES=openid profile email OIDC_USERNAME_CLAIM=preferred_username OIDC_DISPLAY_NAME_CLAIM=name OIDC_ROLE_CLAIM=groups OIDC_ALLOWED_DOMAINS= # Set to 1 while troubleshooting issuer/discovery/token endpoint problems. OIDC_DEBUG=0 # Optional comma-separated role mappings. OIDC_ADMIN_USERS= OIDC_EDITOR_USERS= OIDC_VIEWER_USERS= OIDC_ADMIN_GROUPS= OIDC_EDITOR_GROUPS= OIDC_VIEWER_GROUPS= # Set to 0 to prevent discovery from refreshing IEEE MAC OUI vendor data. OUI_AUTO_UPDATE=1 # MAC discovery mode: auto, neighbor, arp-scan, nmap, or off. # auto tries arp-scan/nmap when available, then falls back to the OS neighbor cache. DISCOVERY_MAC_SCAN_MODE=auto # Bound concurrent discovery work. Manual and scheduled scans share this queue. DISCOVERY_SCAN_MAX_ACTIVE=2 DISCOVERY_SCAN_MAX_ACTIVE_PER_LAB=1 DISCOVERY_SCAN_MAX_QUEUED=32 # Background connection-status refresh for controller integrations # (Proxmox/UniFi/Omada/OPNsense/Dockhand) in milliseconds. Re-runs each # enabled connection's lightweight test call so the Integrations panel stays # live. This controls status checks only; configured sync schedules are # independent and can write automatically. 0 disables status refresh. INTEGRATION_STATUS_SYNC_INTERVAL_MS=300000 # ── SNMP monitoring, sync, and traps ────────────────────────── # Required before storing inline SNMP communities, shared SNMP credential secrets, or controller # integration credentials (Proxmox/UniFi/Omada/OPNsense/Dockhand). Use a long # random value (e.g. `openssl rand -hex 32`). Retain the existing key on upgrade. # Without it, secrets cannot be saved and legacy plaintext community conversion # aborts atomically. ICMP/TCP/HTTP monitoring does not require this key. RACKPAD_SECRET_KEY= # Set to 1 to enable SNMP inventory sync for VLANs, subnets, and valid, # conflict-free DHCP scopes. Disabled by default. SNMP_INVENTORY_SYNC=0 # SNMP trap receiver. Disabled by default; set to 1 to listen on UDP 1162. # The default Compose files deliberately do not publish this UDP port; # explicitly add a UDP port mapping or use the host-discovery profile when traps # must arrive from outside the container network. # When enabled, traps are logged; monitor state only changes when the trap matches # configured credentials or an encrypted inline community. When containerised, also # publish the port, e.g. `-p 1162:1162/udp`. SNMP_TRAP_ENABLED=0 SNMP_TRAP_PORT=1162 SNMP_TRAP_BIND=0.0.0.0 # GitHub user/org that owns the GHCR image (used by docker-compose.yml) GITHUB_REPO_OWNER=kobii-git # Full image repository used by the release and host-discovery Compose files RACKPAD_IMAGE=ghcr.io/kobii-git/rackpad # Image tag or release version to pull RACKPAD_TAG=latest