Configuration reference
PULSE is configured through environment variables. This page lists the ones the backend reads, grouped by purpose. It names variables and describes their effect. It does not show values: secrets come from the secret store, and CORE’s operator projects the rest.
Command line
| Command | Meaning |
|---|---|
pulse-server serve | Starts the backend. |
--port, -p | The port to listen on. Defaults to PORT when set, otherwise 0, which picks a free port. |
Server
| Variable | Effect |
|---|---|
PORT | Default for --port. |
PULSE_WEB_DIR | Directory of the Flutter web build. When set, the backend serves the app on the same origin as the API. |
CORS_ALLOWED_ORIGINS | Comma-separated origins allowed to call the API cross-origin. Unset means *. Only an exact listed origin gets credentials. |
PULSE_ENV | production turns the insecure-configuration warnings into a refusal to start. See Operations. |
PULSE_GRPC_REFLECTION | true turns on gRPC reflection. Off by default. For local work only. |
PULSE_RATE_RPS, PULSE_RATE_BURST | Per-caller rate limit, keyed by peer IP. Off unless PULSE_RATE_RPS is above zero. |
PULSE_PUBLIC_BASE_URL | The public origin, used for absolute URLs in the podcast feed. The feed refuses to render without it. |
APP_VERSION | The version stamped on log lines. |
FEATURED_MESSAGES_PATH | The file behind the featured-message strip. |
A2A_ORGANIZATION | The organization named on the A2A agent card. Falls back to RUNINK_ORG, then CORE_GITHUB_ORG, then empty. |
Security
| Variable | Effect |
|---|---|
PULSE_JWT_SECRET | Required. The key that signs and verifies every session. There is no default. It must never be a value that has been committed anywhere. |
CORE_ENVELOPE_KEK | Required. The key that seals OAuth tokens in the database. The database refuses to open without it. |
PULSE_TLS_CERT, PULSE_TLS_KEY | In-process TLS for direct exposure. Set both or neither. TLS 1.2 minimum, forward-secret AEAD suites only. |
MESH_MTLS | true requires mutual TLS on the listener, with rotating certificates from the shared mesh CA. Takes precedence over PULSE_TLS_*. TLS 1.3 only. |
MESH_CA_CERT, MESH_CA_KEY | The mesh CA, from the secret store. Needed when MESH_MTLS=true. |
MESH_ADVERTISE_IP, MESH_ADVERTISE_HOST | Extra IP and DNS names on the mesh certificate. |
LICENSE, LICENSE_FILE, LICENSE_PUBLIC_KEY | An offline licence, inline or as a file, and the key that verifies it. With no licence there is no gating. |
Sign-in and users
| Variable | Effect |
|---|---|
PULSE_ADMIN_PASSWORD (or ADMIN_PASSWORD) | Seeds the break-glass admin. Without it, no password login exists. |
PULSE_ADMIN_USERNAME, PULSE_ADMIN_EMAIL | Overrides the break-glass admin’s username (admin) and email. |
GOOGLE_CLIENT_ID | The Google OAuth client. Without it, Google sign-in is off. |
OIDC_ISSUER | Overrides the token issuer that Google sign-in trusts. |
AUTH_GOOGLE_ONLY | true hides the password form. |
AUTH_ALLOWED_EMAILS | The Google sign-in allowlist. Empty means nobody signs in with Google. |
AUTH_SEED_USERS | Operator-granted roles as email=persona,…. Applied at every start. |
PULSE_CLIENT_INSTANCE, PULSE_CLIENT_INSTANCE_NAMESPACE | The ClientInstance this deployment is. Lets the Admin page write member changes back to it. |
GOOGLE_CLIENT_SECRET, GOOGLE_TOKEN_ENDPOINT | Used to refresh a Google integration’s access token for YouTube uploads. |
See Users and access.
Storage
| Variable | Effect |
|---|---|
PULSE_DB_PATH | The SQLite file. Default ./pulse.db. |
PULSE_DATA_DIR | Working data directory. Default ./data. |
PULSE_APPFS_BUCKET | Bucket for the sealed app root (sessions, media, memo cache) on the object store. |
PULSE_APPFS_DIR | Local sealed app root when there is no object store. Default $PULSE_DATA_DIR/appfs. |
OBJECTSTORE_ENDPOINT, OBJECTSTORE_BUCKET, OBJECTSTORE_ACCESS_KEY, OBJECTSTORE_SECRET_KEY | The object store for the retrieval corpus and the app root. |
LITESTREAM_ENDPOINT, LITESTREAM_BUCKET, LITESTREAM_ACCESS_KEY_ID, LITESTREAM_SECRET_ACCESS_KEY | Litestream replication of the database. |
Inference
| Variable | Effect |
|---|---|
INFERENCE_REMOTE_URL | Use the shared inference plane at this address. Unset means PULSE starts its own mistralrs-server. |
INFERENCE_MODEL | The model to request. Code default GLM-4-9B-Chat-Q4_K_M.gguf, which mistral.rs does not load (chatglm) — set a Qwen-family model. Must match what the server loads. |
INFERENCE_API_KEY | Key for the inference server. |
INFERENCE_HOST, INFERENCE_IP, INFERENCE_PORT, MISTRAL_PORT | Where a local inference child listens. |
BINARY_MISTRALRS_SERVER, MODEL_DIR, PULSE_AGENT_CONFIG | The local engine binary, the model directory, and the agent config (default ./agents/pulse.ini). |
VOXTRAL_REMOTE_URL | The speech-to-text server. |
INFERENCE_DECODE_TOK_S | The platform decode rate that generation budgets are sized from. CORE injects it. |
PULSE_FIRST_TOKEN_SECONDS | Wait allowed for the first token. Default 5 minutes. |
PULSE_GENERATION_TIMEOUT_SECONDS | Overrides the decode budget outright. |
PULSE_ADMIT_MAX, PULSE_ADMIT_QUEUE, PULSE_ADMIT_MODE, PULSE_ADMIT_WEIGHTS | In-process admission control. Off unless PULSE_ADMIT_MAX is above zero. |
PULSE_GATE_MAX_INFLIGHT, PULSE_GATE_FIRST_TOKEN_SECONDS | Cross-app admission gate for the shared plane. Off unless one is set. |
PULSE_DEDUP_TTL | How long a repeated generation is reused. Go duration, default 1h. |
PULSE_JUDGEMENT | off disables the judging ladder. |
PULSE_EGRESS_ALL_AGENTS | Screens every agent’s output, not only content agents. |
EMBEDDING_URL | The embeddings endpoint for grounding. |
EMBEDDING_FORMAT | qwen3-embedding (default), nomic-v1.5, or raw. Anything else stops the server. |
MODEL_EMBEDDING_DIM | Vector width. Default 768. |
CORE_HEALTH_URL | Where agent health reports go. Unset means no reports. |
See Sovereign inference.
Site audit and scoring
| Variable | Effect |
|---|---|
PULSE_SCORING_CONFIG | A JSON file overlaid on the built-in scoring config. |
PULSE_AUDIT_CACHE_TTL | How long an audit result is cached, in seconds. Default 3600. |
PULSE_PROSPECT_AUDIT_TIMEOUT | Time limit for auditing one prospect’s site during lead prospecting. Go duration, for example 20s. |
PULSE_SITE_AUDIT_URL | The site the daily audit engine checks. Falls back to PULSE_SITE_BASE_URL. |
Publishing
| Variable | Effect |
|---|---|
PULSE_APPLY_ENABLED | The global kill switch. Only the exact value true arms anything. |
PULSE_PUBLISH_<CHANNEL> | Narrows one channel: BLOG, PODCAST, AUDIOBOOK, YOUTUBE, INSTAGRAM, SPOTIFY, LINKEDIN. |
PULSE_PUBLISH_CONFIG_PATH, PULSE_PUBLISH_CONFIG_JSON | The per-channel arming file, or the same JSON inline. |
PULSE_SITE_REPO, PULSE_SITE_BRANCH, PULSE_SITE_BLOG_DIR, PULSE_SITE_PUBLISH_MODE, PULSE_SITE_AUTHOR, PULSE_SITE_BASE_URL | Blog publishing to your website. |
PULSE_GIT_AUTHOR_NAME, PULSE_GIT_AUTHOR_EMAIL | The author on commits PULSE makes. |
YOUTUBE_PRIVACY_STATUS | public, unlisted, or private. Unset means private. |
LINKEDIN_ACCESS_TOKEN, LINKEDIN_AUTHOR_URN, LINKEDIN_API_VERSION | The LinkedIn publisher’s token (from a secret), the member to post as, and the API version header. |
PULSE_PODCAST_TITLE, PULSE_PODCAST_DESCRIPTION, PULSE_PODCAST_LANGUAGE | Podcast feed metadata. |
See Publishing controls and Site pipeline.
Media
| Variable | Effect |
|---|---|
BINARY_VIDEO_CLI | The video generation tool. Without it, video creatives, course videos, and the shorts engine are off. |
VIDEO_MODEL_DIR | Model directory for video generation. |
FFMPEG_PATH | Overrides the ffmpeg binary. |
ORPHEUS_BACKEND | The compute backend passed to the video tool. Default vulkan. |
Telephony and messaging
| Variable | Effect |
|---|---|
AUDIOSOCKET_ADDR | The TCP listener Asterisk streams call audio to. |
ASTERISK_ARI_URL, ASTERISK_ARI_USER, ASTERISK_ARI_PASSWORD | Asterisk’s REST interface, for placing calls. Leave empty to keep outbound calls off. |
ASTERISK_ENDPOINT_PATTERN, ASTERISK_CONTEXT, ASTERISK_EXTENSION, ASTERISK_CALLER_ID | The dial string, dialplan target, and caller ID. |
CALLING_AGENT_URL | The platform calling agent that carries browser voice calls. |
PULSE_WEBRTC_SIGNALING_ONLY | true answers WebRTC offers locally for signaling tests. Such a call cannot hear the caller. |
TWILIO_ACCOUNT_SID, TWILIO_AUTH_TOKEN, TWILIO_WHATSAPP_FROM, TWILIO_FROM_NUMBER | The WhatsApp and SMS edge. |
PULSE_WHATSAPP_USER_ID | Which user’s HubSpot connection backs the WhatsApp sender allowlist. |
Billing and tenancy
| Variable | Effect |
|---|---|
TENANT_ID | This deployment’s tenant. |
SUBSCRIPTION_TIER, SUBSCRIPTION_SEATS, SUBSCRIPTION_STATUS | The subscription the Billing page shows. |
See Billing.
Names that are no longer read
Setting these does nothing. PULSE does not warn about them.
- Every
LLAMA_*variable, includingLLAMA_MODELandLLAMA_REMOTE_URL. UseINFERENCE_MODELandINFERENCE_REMOTE_URL. SD_REMOTE_URL. The image-generation tier was retired.TTS_REMOTE_URL. Speech synthesis runs inside PULSE.