# skgate environment. Copy to .env and edit. Every variable the binary reads is listed; # commented lines show the default. Values are placeholders. # --- Secrets --- # Key that encrypts stored upstream secrets (tokens, headers, env values): 32 bytes base64, or any # passphrase. Unset: a random key file (secrets.key) is created next to the database. # Set it to keep the database volume alone useless to whoever gets a copy of it. # SECRETS_KEY= # Optional GitHub token for Suggest when it reads a repository (raises GitHub's rate limit). An # upstream's own access token takes precedence. # GITHUB_TOKEN= # --- Core --- # Public origin users and MCP clients reach skgate at (no trailing slash). PUBLIC_URL=https://skgate.example.com # Listen address inside the container. # LISTEN_ADDR=:8080 # SQLite database file. Keep it on a persistent volume. # DB_PATH=/data/skgate.db # info | debug (debug adds request detail; secrets are never logged). # LOG_LEVEL=info # Lines of output kept per managed process (its last two runs), 10 to 10000. Also capped at 512 KB. # LOG_LINES=1000 # Container starts as root, chowns the data dir to PUID:PGID, then drops to it. Must not be 0. # PUID=1000 # PGID=1000 # --- Admin sign-in (OIDC) --- # Any OIDC provider: Authelia, Authentik, Keycloak, Okta, ... # Must equal the "issuer" in the provider's discovery document. OIDC_ISSUER=https://auth.example.com OIDC_CLIENT_ID=skgate OIDC_CLIENT_SECRET=change-me # OIDC_SCOPES=openid profile email groups # Register this exact URL at the provider. Default: PUBLIC_URL/admin/oidc/callback # OIDC_REDIRECT_URL=https://skgate.example.com/admin/oidc/callback # Comma lists. If both are empty, every user the provider lets through is an admin. # OIDC_ALLOWED_EMAILS=admin@example.com # OIDC_ALLOWED_GROUPS=admins # --- Managed MCP upstreams (full image only) --- # The full image (:latest) lets admins run MCP servers as child processes of skgate (commands, git # repos); admins can execute commands in the container. The slim image is proxy only. # Work dirs, clones, per-process HOME. Default: managed/ next to the database. # MANAGED_DIR=/data/managed # Concurrent child processes; 0 = unlimited. # MANAGED_MAX_PROCS=0 # --- MCP inbound --- # true: show an Approve/Deny page after login at /authorize. # MCP_OAUTH_REQUIRE_CONSENT=true # The ?key= switch (keys end up in logs) is per key, in the key's edit dialog on the admin keys page, off by default. # --- Admin UI --- # The version in the admin header turns yellow when GitHub has a newer stable release. skgate asks the public # GitHub API (anonymous, at most every few hours) from the server; false disables the check. # UPDATE_CHECK=true # The Grok provider needs no variables: its sign-in client and API hosts are built in, and the API # base and fallback can be changed in its details dialog in the admin UI.