Skip to content

Server configuration

The Noset server reads its configuration from the environment. On an installation made by the install command it lives in /etc/noset/noset.env. The env file holds only what the server needs before the database exists; everything else is set in the web app and kept in the database, its secrets sealed with the master key.

After a change, restart the server: cd /opt/noset && docker compose up -d --force-recreate server.

Variable
NOSET_PUBLIC_URL The address people and gates use, e.g. https://noset.example.com. Required.
NOSET_LISTEN The address the server listens on. Default 127.0.0.1:8100; the install command puts Caddy in front.
NOSET_SERVER_NAME The name noset login shows for this server.
NOSET_TRUSTED_PROXIES The reverse proxies whose X-Forwarded-For the server believes: addresses and CIDR prefixes, comma-separated, loopback (the default) or none.
NOSET_LOG_LEVEL debug, info (default), warn or error.
NOSET_SESSION_TTL How long a web session lasts. Default 8h.
Variable
NOSET_DATABASE_URL The postgres:// connection string. Required.
NOSET_DATABASE_PASSWORD The database password, kept out of the URL.
NOSET_SIGNING_SECRET Hex, at least 32 bytes: your organization’s signing keys are derived from it. Required.
NOSET_MASTER_KEY Hex, at least 32 bytes: seals the secrets of the settings in the database. Losing it means entering those secrets again.
NOSET_SETUP_TOKEN The one-time token that opens the setup wizard. Spent when the first admin signs in.

The install command generates all of these and never prints them.

Variable
NOSET_OIDC_ISSUER, NOSET_OIDC_CLIENT_ID, NOSET_OIDC_CLIENT_SECRET Only for an installation configured through its env file: the identity provider. With them, the setup wizard is off. Leave them out to set the provider in the wizard.
NOSET_OIDC_SCOPES Default openid profile email.
Variable
NOSET_SMTP_HOST, NOSET_SMTP_PORT The SMTP server. The port defaults to 587, 465 or 25 to match the security.
NOSET_SMTP_SECURITY starttls (default), tls or none.
NOSET_SMTP_USERNAME, NOSET_SMTP_PASSWORD The login. A user name needs a password and encryption.
NOSET_SMTP_FROM, NOSET_SMTP_FROM_NAME The sender’s address (required with the others) and display name.

Optional on-prem. When set, these win over the email settings in the web app, which then show them read-only. The server does not start with an incomplete set, and never logs or shows the password.

Variable
NOSET_GATE_CHANNEL Where your gates come from: prod (default, https://get.noset.ai) or dev (https://get.noset.dev). Gates › Connect a server shows that channel’s commands.
NOSET_GATE_MIN_VERSION The oldest gate version the server accepts. Default: every one.
NOSET_TSA_URLS The RFC 3161 time-stamp authorities for the hourly checkpoints, comma-separated and tried in order, or off. The setting in the web app takes precedence.
Variable
NOSET_MODE onprem (default): the setup wizard and one organization. cloud: many organizations.
NOSET_OPERATORS The email addresses of the people who create organizations.
NOSET_SLACK_CLIENT_ID, NOSET_SLACK_CLIENT_SECRET, NOSET_SLACK_SIGNING_SECRET Noset’s own Slack app, which every organization adds to its workspace. All three or none.
NOSET_TEAMS_APP_ID, NOSET_TEAMS_APP_PASSWORD, NOSET_TEAMS_APP_TENANT Noset’s own Microsoft Teams bot, which every organization adds to its tenant.