Skip to content
Configuration reference

Configuration reference

This reference was built from the code. It lists every environment variable read by the FACE backend (grpc/), the platform libraries it links (security, store, inference), its Litestream configuration and the frontend sleeve. It leaves out variables read only by build tooling, benchmarks and tests, and variables read only by the separate voice calling-agent image.

In a cluster, set values through the ControlPlane or FaceInstance env list, never on the live Deployment (see Deployment model). Locally, export them before core dev up face.

Secret in the Source column means the value is resolved through the platform secret backend (SECRET_BACKEND), so it can come from a mounted file instead of the environment. Everything else is read from the environment.

Connector and integration credentials (warehouses, SaaS APIs, maps keys) do not belong in environment variables. They are entered per connection in the cockpit and stored sealed in FACE’s credential store. The few integration variables below are the exceptions the code still reads.

Required at boot

VariableSourcePurpose
AUTH_JWT_SECRETsecretSigns the pre-TOTP MFA challenge. The process refuses to start without it.
MESH_CA_CERTsecretThe shared cluster CA certificate. Each pod issues its own rotating mTLS leaves from it.
MESH_CA_KEYsecretThe shared cluster CA private key.
CORE_ENVELOPE_KEKsecretA base64-encoded 32-byte key-encryption key for everything sealed at rest.
INFERENCE_REMOTE_URLenvThe base URL of the shared inference plane. No other name is read for it.

Prerequisites and ordering has the exact refusal messages.

Process, role and platform

VariableDefaultPurpose
SERVICE_ROLEcontrol planerunner makes this process a fetch runner. Any other value makes it a control plane. The operator sets server or runner.
PORTnoneThe default for serve --port. The image entrypoint uses 7000 when PORT is unset. The operator sets 7100 (control plane) or 7102 (runner).
APP_VERSIONemptyThe version stamped on structured logs.
SECRET_BACKENDenvenv or file. With file, secrets are read from SECRETS_DIR with the environment as fallback. Any other value makes every secret lookup fail.
SECRETS_DIR/var/run/secretsThe directory for the file backend. A file is named after the variable, or in lower case with dashes.
RUNINK_VARIANTstandardThe declared variant. demo seeds the demo connection set. When the process has no in-cluster ServiceAccount token, demo also offers a single local-development instance in the instance picker.
DEMO_SEED_DATAunsettrue also seeds the demo connection set. It does not enable the local instance card. Prefer RUNINK_VARIANT=demo.
RUNINK_APPfaceThe app name that filters ClientInstances in the instance picker.
FACE_CLIENT_INSTANCEnoneThe name of this deployment’s own ClientInstance, used by the access page. There is no fallback.
FACE_CLIENT_INSTANCE_NAMESPACEPOD_NAMESPACEThe namespace of that ClientInstance.
POD_NAMESPACEnoneThe pod’s namespace, from the downward API. Also used when publishing connectors to CORE.
POD_NAMEnoneThe instance name on lineage reports sent to CORE.
HOSTNAMEset by KubernetesThe runner id fallback when RUNNER_ID is unset.
KUBERNETES_SERVICE_HOST, KUBERNETES_SERVICE_PORTkubernetes.default.svc, 443The API server FACE lists ClientInstances from.
TENANT_IDnoneThe pod’s tenant for subscription checks. Also names the connectors ConfigMap FACE publishes to CORE (face-<tenant>).
SUBSCRIPTION_TIER, SUBSCRIPTION_STATUS, SUBSCRIPTION_SEATSnoneThe subscription the operator mirrors from the ClientInstance. A subscription is reported only when the tier and TENANT_ID are set and match the tenant asked about.
CORE_PLATFORM_ADMINnoneThe installation admin’s e-mail. That account sees every instance. When it is unset, nobody gets that grant.
LICENSEnoneA signed licence blob, as base64 or raw JSON.
LICENSE_FILEnoneA path to read the licence from when LICENSE is unset.
LICENSE_PUBLIC_KEYnoneThe base64 Ed25519 public key licences are verified against.
CORE_HEALTH_URL, CORE_HEALTH_TOKENnoneWhere FACE reports observed lineage to the CORE console, and the bearer token it uses.
CORS_ALLOWED_ORIGINSunsetA comma-separated allowlist of browser origins for gRPC-web. Set it to your cockpit origin(s).
FACE_RATE_RPS, FACE_RATE_BURSTunsetThe per-caller request rate (requests per second) and burst. Callers over the limit get ResourceExhausted.
ENV, GCP_REGIONemptyLabels printed into the system state that compliance and domain analyses read.

Authentication

VariableSourceDefaultPurpose
ADMIN_EMAILenvnoneThe break-glass admin account seeded at boot.
ADMIN_PASSWORDsecretnoneIts password. If either value is missing, FACE logs break-glass admin not seeded and disables password admin login.
AUTH_GOOGLE_ONLYenvunsettrue rejects password sign-in with Password sign-in is disabled — use Google sign-in. The break-glass admin is exempt.
AUTH_SEED_USERSenvnoneComma-separated email=role pairs to seed. The operator projects them from ClientInstance users.
AUTH_USERS_PATHenvthe data directoryA legacy users file. It is imported once into the accounts table and then sealed as <path>.migrated.
OIDC_ISSUERenvnoneThe OIDC issuer. Single sign-on is on only when both this and OIDC_CLIENT_ID are set.
OIDC_CLIENT_IDenvnoneFACE’s OAuth client id, and the default token audience. It must equal the cockpit’s google_client_id.
OIDC_AUDIENCEenvOIDC_CLIENT_IDAn explicit audience override.
OIDC_JWKS_URLenvdiscoveredAn explicit JWKS URL instead of discovery.
AUTH_ALLOWED_EMAILSenvnoneThe single sign-on allowlist. When SSO is configured and this is empty, every SSO login is refused (SSO is not available on this instance). An unlisted account gets This account is not authorized for this instance. The operator projects it from the face-oauth Secret. Changes take effect when the pod restarts.
HCAPTCHA_SECRETsecretnoneThe secret for verifying hCaptcha on login.

Inference and the model plane

VariableDefaultPurpose
INFERENCE_REMOTE_URLnone (required)The base URL for chat completions, and for embeddings when EMBEDDING_URL is unset.
INFERENCE_API_KEYemptySecret. Sent as Authorization: Bearer when it is set. FACE never generates one. The placeholder application-generated-key counts as empty.
VISION_REMOTE_URLINFERENCE_REMOTE_URLThe base URL for vision calls.
VOICE_REMOTE_URLINFERENCE_REMOTE_URLThe base URL for voice calls.
INFERENCE_CONTEXT_SIZE16384The prompt window, in tokens, that the agent loop budgets against.
INFERENCE_DECODE_TOK_S3.4The measured decode rate of the text tier. It sizes time budgets.
INFERENCE_VISION_DECODE_TOK_S1.0The same, for the vision tier.
REACT_DECODE_TOK_SINFERENCE_DECODE_TOK_SOverrides the decode rate for the agent loop’s turn budgets.
REACT_PREFILL_TOK_S38The prefill rate for the agent loop’s turn budgets.
POSTURE_DECODE_TOK_SINFERENCE_DECODE_TOK_SOverrides the decode rate for posture analysis.
POSTURE_LLM_TIMEOUT_SECONDS120The model time budget for posture analysis.
COMPLIANCE_LLM_BUDGET_SECONDS15The model time budget for compliance analysis.
METASEARCH_BUDGET_SECONDS90The time budget for the trend metasearch step of a fetch.
FACE_ADMIT_MAX0 (off)The maximum number of concurrent inference calls. 0 dispatches directly with no scheduling. The operator sets 1.
FACE_ADMIT_QUEUE0 (unbounded)The maximum number of waiters before backpressure. The operator sets 32.
FACE_ADMIT_MODErejectreject or degrade when the queue is full.
FACE_ADMIT_WEIGHTSnoneTier weights, for example interactive:4,batch:1.
FACE_ADMIT_COALESCEofftrue lets identical concurrent prompts share one generation.
FACE_GATE_MAX_INFLIGHToffThe concurrent-submission cap of the inference gate.
FACE_GATE_FIRST_TOKEN_SECONDSoffThe longest acceptable queue wait. The gate is on only when this or FACE_GATE_MAX_INFLIGHT is positive.
FACE_GATE_DECODE_RATEnoneThe measured tokens per second the gate assumes.
FACE_GATE_REQUEST_SECONDSoffThe per-request time budget for inference calls.

These variables are read into the process configuration for compatibility. FACE starts no model server of its own, so they neither choose nor tune what the plane serves. Set the model on the plane instead. They are: INFERENCE_PORT, INFERENCE_HOST, INFERENCE_MODEL, INFERENCE_TIMEOUT, INFERENCE_PARALLEL, INFERENCE_CACHE_RAM, INFERENCE_CPU_STRICT, INFERENCE_THREADS, INFERENCE_BATCH, INFERENCE_GPU_LAYERS, INTERNAL_INFERENCE_IP, INTERNAL_BRIDGE_IP, INTERNAL_SUBNET, MODEL_DIR, MODEL_EMBEDDING, MODEL_VOXTRAL, MODEL_WHISPER, MODEL_INFERENCE_TTS, MODEL_WAV_TOKENIZER and MODEL_VISION. (MODEL_VISION is also printed in the boot line that names the vision tier.)

Embeddings

VariableDefaultPurpose
EMBEDDING_URLINFERENCE_REMOTE_URLA dedicated embedding endpoint. Without it, embeddings go to the chat plane, and semantic grounding is expected to report INACTIVE.
MODEL_EMBEDDING_DIM768The vector width the knowledge index is built for. The endpoint’s vectors must have this width after the format’s fit.
EMBEDDING_FORMATqwen3-embeddingThe instruction format of the embedding model: qwen3-embedding, nomic-v1.5 or raw. It must name the model EMBEDDING_URL actually serves. An unknown name stops the process.

See Model plane.

Storage and persistence

VariableSourceDefaultPurpose
OBJECTSTORE_ENDPOINTenvunsetThe object store (host:port or https://host:port). When it is unset, the appfs root uses an encrypted local directory. A cleartext endpoint is accepted only for a loopback or cluster-internal name.
OBJECTSTORE_ACCESS_KEY, OBJECTSTORE_SECRET_KEYsecretnoneObject-store credentials. They are required when an endpoint is set.
OBJECTSTORE_VACUUM_ACCESS_KEY, OBJECTSTORE_VACUUM_SECRET_KEYsecretnoneAn optional second credential used for every delete. Set both or neither.
OBJECTSTORE_BUCKETenvcoreThe object-store bucket for records, knowledge and evidence. The appfs root always uses its own bucket, face.
CORE_ENVELOPE_KEK_RETIREDsecretnoneRetired KEKs (comma- or space-separated, base64), accepted for decryption only.
SQLITE_PATH<data dir>/face.dbThe MetaDB file. The entrypoint requires an absolute path. The operator sets /data/face.db.
FACE_APPFS_DIRappfs/ beside face.dbThe encrypted local appfs root, used only when there is no object store.
FACE_TENANTdefault-tenantThe tenant sub-root, tenants/<tenant>/. Set it before the first boot (see Persistence).
RUNNER_IDHOSTNAMEOn a runner, names its private tables. The operator sets a stable value.
FACE_CONNECTIONS_DIRnoneThe legacy connection directory. It is imported once into the appfs root.
FACE_DCI_CORPUS_DIRnoneOverrides the directory the grep-based grounding reads.
FETCH_LEDGER_DIR./data/fetch-ledgerThe fetch cascade ledger.
RALPH_RUN_DIR./data/ralph-runsThe agent run journal, used to resume runs.
FACE_VOICE_SOURCE_DIR$RALPH_RUN_DIR/voice-sourcesWhere recorded voice sources are written.
RALPH_READ_ROOT.The root agents may read files under. Paths that escape it are rejected.
FEATURED_MESSAGES_PATHfeatured_messages.json on the data pathA file of featured activity messages.
FACE_DEPLOY_SECRETS_DIRnoneA directory of runner deploy secrets, read by path.
EVIDENCE_FRAME_RETENTION0 (none kept)How long camera evidence frames are kept, as a Go duration. It is capped at 720h.

Litestream, read by /app/litestream.yml and set by the operator: SQLITE_PATH, MINIO_ENDPOINT (host and port only, with no scheme), MINIO_BUCKET, MINIO_ACCESS_KEY, MINIO_SECRET_KEY. The image entrypoint also checks MINIO_ENDPOINT to decide whether to run the server under Litestream.

Consensus, mesh and resilience

VariableDefaultPurpose
RAFT_NODE_IDunsetThis node’s consensus id. When it is unset, the process does not join consensus (runners). When it is set, a failure to start the orchestrator stops the process.
RAFT_PEERSnoneThe peers, as id@host:port,….
RAFT_PIPE_DIRnoneThe local proposal-pipe directory.
RAFT_DATA_DIRunset (in memory)The durable consensus state. When it is unset, FACE warns that the state is memory-only.
RAFT_MTLS_ADDRunsetThe listen address of the mTLS raft peer plane. A voting control plane must set it.
RAFT_ADVERTISE_IP, RAFT_ADVERTISE_HOSTnoneExtra IP and DNS SANs on the mesh leaf certificates.
LOAD_SHED_THRESHOLD0.85The orchestrator’s load-shed threshold.
SNAPSHOT_THRESHOLD, SNAPSHOT_RETAIN1000, 100Raft snapshot cadence and retention, in entries.
WATCHDOG_CPU_THRESHOLD99.5The watchdog’s CPU alarm, in percent.
WATCHDOG_MEMORY_THRESHOLD_MBlibrary defaultThe watchdog’s memory alarm.
WATCHDOG_GOROUTINE_THRESHOLD10000The watchdog’s goroutine alarm.
WATCHDOG_RUNNER_DIAL_TIMEOUT_SECONDS5The runner reachability probe timeout.
CIRCUIT_BREAKER_FAILURE_THRESHOLD5Failures before the breaker opens.
CIRCUIT_BREAKER_RECOVERY_TIMEOUT_SECONDS30How long the breaker stays open before it tries again.
SELF_HEAL_AUTONOMOUSonfalse limits the self-healing reasoner to ENDPOINT_UNHEALTHY events.

Fetch, runners and agents

VariableDefaultPurpose
MANAGED_RUNNER_ENDPOINTface-runner:7102Where the control plane forwards fetches.
REQUIRE_RUNNER_ISOLATIONunsettrue makes an unreachable runner a hard failure instead of a fallback to the control plane’s in-process SQL service.
RUNNER_PORTnoneThe port used when dialling a configured runner endpoint that has none.
RUNNER_ENROLL_ADDRunsetOn a self-hosted runner, the control-plane address it enrols with (see Runners).
RUNNER_ENROLL_TOKENnoneThe service-account token the runner enrols with. It is required when the address is set.
RUNNER_ENROLL_TLStrueTLS with system roots for the enrolment dial.
RUNNER_NAME, RUNNER_VERSIONemptyShown in the control plane’s runner registry.
RUNNER_COMPUTE_POOL, RUNNER_CPU_LIMIT, RUNNER_MEMORY_LIMITnone, 1, 1GInputs to runink runner create for the Snowflake runner type.
SCHEDULE_EXECUTE_FETCHofftrue makes schedules run real fetches. When it is off, a schedule logs a dry run.
FETCH_CACHE_TTL10mHow long a fetch result may be reused. 0 disables reuse.
FETCH_CACHE_MIN_CONFIDENCE0.7The minimum confidence for a cached result to be reused.
FACE_RALPH_JUDGEMENTonoff, false, 0, no or disabled turns off judging of proposed actions.
FACE_RALPH_JUDGE_MAX_ACTIONS3The number of actions judged per answer (1–20).
FACE_RALPH_JUDGE_REVISIONS1The number of revision rounds after dissent (0–3).
FACE_FAST_JUDGEMENTonThe local fast-path judge in front of the model.
FACE_A2A_PEERSnoneAgent-to-agent delegation peers, separated by commas, spaces or newlines.
A2A_ORGANIZATIONfalls back to RUNINK_ORG, then CORE_GITHUB_ORGThe organization published on the agent card.
FACE_AGENT_EMAIL_ALLOWLISTnoneThe addresses or @domain suffixes agents may e-mail autonomously.
ENFORCE_AUDIT_LOGGING, REQUIRE_HITL, DATABASE_ENGINE, PRIMARY_SERVER_URLunsetReported into every compliance analysis as the controls actually in place. They never stop the process.

Connectors, vision and integrations

VariableDefaultPurpose
FACE_BROWSER_CONCURRENCY12The number of headless-Chrome renders run at once. Lower it on small hosts.
FACE_MAX_DOWNLOAD_BYTES2 GiBThe largest file a connector downloads.
SCRAPER_USER_AGENTMozilla/5.0 (compatible; RuninkFACE/1.0)The user agent for crawling.
VISION_DETECT_INSTANCESofftrue adds a per-instance detection turn per camera frame. It roughly doubles the vision time per frame.
VISION_MAX_EDGE448Frames are downscaled to this longest edge. 0 disables downscaling. Keep it below 1000.
VISION_SWEEP_FRAMES2The number of frames sampled per camera ingest (at most 8).
VISION_RESOLVE_ITEMSofftrue resolves detected objects against the item catalogue.
OCR_VISION_FALLBACKofftrue lets OCR fall back to the vision model.
GOOGLE_CREDENTIALS_JSONsecretA Google Workspace service-account JSON. The stored integration config is used when it is empty.
HUBSPOT_API_KEYnoneThe key for the HubSpot read paths.
TWILIO_ACCOUNT_SID, TWILIO_AUTH_TOKEN, TWILIO_FROM_NUMBER, TWILIO_WHATSAPP_FROMnoneVoice, SMS and WhatsApp. FACE refuses to send by name when they are missing.
PUBLIC_URLlocalhost:8080The public host used for Twilio media-stream callbacks.
CALLING_AGENT_URLnoneThe shared calling agent that WebRTC signalling is forwarded to. When it is unset, the call RPC answers Unavailable.

Frontend sleeve

PORT (default 8080), WEB_DIR (/web) and BACKEND_ADDR. See Deployment model.

Removed and renamed names

These are listed to help an upgrade. FACE ignores every one of them, except OBJECTSTORE_USE_SSL, which it refuses. Remove them from your resources.

NameStatus
REMOTE_LLAMA_URL, LLAMA_REMOTE_URLRenamed to INFERENCE_REMOTE_URL. A manifest that sets only the old name has no inference endpoint, and the process refuses to start.
LLAMA_API_KEYRenamed to INFERENCE_API_KEY.
MESH_MTLS, ENABLE_ALTSRemoved. Mesh mTLS is unconditional.
REQUIRE_MTLS_INGRESSRemoved.
OBJECTSTORE_USE_SSLRemoved, and refused if it is set. Put the scheme in OBJECTSTORE_ENDPOINT.
CORE_ENVELOPE_ENCRYPTIONRemoved. Sealing at rest is unconditional.
GOOGLE_API_KEYRead by no code. Maps keys are entered per connection in the cockpit.