The Noset server reads its configuration from the environment. On an installation made by the install command it lives in /etc/noset/noset.env. The env file holds only what the server needs before the database exists; everything else is set in the web app and kept in the database, its secrets sealed with the master key.
After a change, restart the server: cd /opt/noset && docker compose up -d --force-recreate server.
| Variable |
|
NOSET_PUBLIC_URL |
The address people and gates use, e.g. https://noset.example.com. Required. |
NOSET_LISTEN |
The address the server listens on. Default 127.0.0.1:8100; the install command puts Caddy in front. |
NOSET_SERVER_NAME |
The name noset login shows for this server. |
NOSET_TRUSTED_PROXIES |
The reverse proxies whose X-Forwarded-For the server believes: addresses and CIDR prefixes, comma-separated, loopback (the default) or none. |
NOSET_LOG_LEVEL |
debug, info (default), warn or error. |
NOSET_SESSION_TTL |
How long a web session lasts. Default 8h. |
| Variable |
|
NOSET_DATABASE_URL |
The postgres:// connection string. Required. |
NOSET_DATABASE_PASSWORD |
The database password, kept out of the URL. |
NOSET_SIGNING_SECRET |
Hex, at least 32 bytes: your organization’s signing keys are derived from it. Required. |
NOSET_MASTER_KEY |
Hex, at least 32 bytes: seals the secrets of the settings in the database. Losing it means entering those secrets again. |
NOSET_SETUP_TOKEN |
The one-time token that opens the setup wizard. Spent when the first admin signs in. |
The install command generates all of these and never prints them.
| Variable |
|
NOSET_OIDC_ISSUER, NOSET_OIDC_CLIENT_ID, NOSET_OIDC_CLIENT_SECRET |
Only for an installation configured through its env file: the identity provider. With them, the setup wizard is off. Leave them out to set the provider in the wizard. |
NOSET_OIDC_SCOPES |
Default openid profile email. |
| Variable |
|
NOSET_SMTP_HOST, NOSET_SMTP_PORT |
The SMTP server. The port defaults to 587, 465 or 25 to match the security. |
NOSET_SMTP_SECURITY |
starttls (default), tls or none. |
NOSET_SMTP_USERNAME, NOSET_SMTP_PASSWORD |
The login. A user name needs a password and encryption. |
NOSET_SMTP_FROM, NOSET_SMTP_FROM_NAME |
The sender’s address (required with the others) and display name. |
Optional on-prem. When set, these win over the email settings in the web app, which then show them read-only. The server does not start with an incomplete set, and never logs or shows the password.
| Variable |
|
NOSET_GATE_CHANNEL |
Where your gates come from: prod (default, https://get.noset.ai) or dev (https://get.noset.dev). Gates › Connect a server shows that channel’s commands. |
NOSET_GATE_MIN_VERSION |
The oldest gate version the server accepts. Default: every one. |
NOSET_TSA_URLS |
The RFC 3161 time-stamp authorities for the hourly checkpoints, comma-separated and tried in order, or off. The setting in the web app takes precedence. |
| Variable |
|
NOSET_MODE |
onprem (default): the setup wizard and one organization. cloud: many organizations. |
NOSET_OPERATORS |
The email addresses of the people who create organizations. |
NOSET_SLACK_CLIENT_ID, NOSET_SLACK_CLIENT_SECRET, NOSET_SLACK_SIGNING_SECRET |
Noset’s own Slack app, which every organization adds to its workspace. All three or none. |
NOSET_TEAMS_APP_ID, NOSET_TEAMS_APP_PASSWORD, NOSET_TEAMS_APP_TENANT |
Noset’s own Microsoft Teams bot, which every organization adds to its tenant. |