Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Environment variables

boatramp reads its configuration from three places, in precedence order: command-line flag > environment variable > config file. Every variable below overrides the corresponding config field and is itself overridden by an explicit flag. Secrets (tokens, signing keys) belong in the environment rather than in a config file on disk.

Client commands

Read by sync, build, bundle, and the other project commands. See project.cfg.

VariableOverridesDescription
BOATRAMP_SERVERpublish.serverServer base URL.
BOATRAMP_SITEpublish.siteSite to publish to.
BOATRAMP_PROJECTpublish.projectTarget project for site-scoped commands; falls back to [publish].project, then the default project.
BOATRAMP_TOKENpublish.tokenControl-plane token. Prefer the env var so it is never on disk.
BOATRAMP_TOKEN_HOLDER_KEY—Holder private key ("<alg>:<hex>") for a PoP-bound token: every request is signed with a fresh proof. Inert unless set alongside BOATRAMP_TOKEN + BOATRAMP_POP_ORIGIN. See PoP-bind a token.
BOATRAMP_POP_ORIGIN—The server’s canonical origin the PoP proof binds (aud); must equal the server’s serve.pop_origin.
BOATRAMP_MCP_CONFIG—Path to the MCP instance registry (default ~/.config/boatramp/mcp.toml).

Server (serve)

Read by boatramp serve. Each maps to a serve.* field in boatramp.cfg; the flag of the same name wins over both.

VariableDescription
BOATRAMP_ADDRAddress to bind (e.g. 0.0.0.0:8080).
BOATRAMP_DATA_DIRData directory (blobs + embedded KV).
BOATRAMP_DEFAULT_SITESite to serve for an unmatched Host instead of 404.
BOATRAMP_POP_ORIGINCanonical origin a per-request proof-of-possession must bind (serve.pop_origin). Required for holder-bound (cnf/PoP) tokens; compared against the proof, never a request header.
BOATRAMP_HTTP_REDIRECT_ADDRIn a TLS mode, a second plain-HTTP listener that 308-redirects to HTTPS (e.g. 0.0.0.0:80).
BOATRAMP_PROTECT_PREVIEWSRequire a valid token to view deployment previews.
BOATRAMP_LOG_FORMATjson for structured logs (anything else = human-readable).

Upload limits

VariableDescription
BOATRAMP_MAX_UPLOAD_BYTESReject blob uploads larger than this (default: unlimited).
BOATRAMP_UPLOAD_IDLE_TIMEOUTAbort an upload stalled this many seconds (slowloris guard).
BOATRAMP_MAX_CONCURRENT_UPLOADSCap simultaneous uploads; further uploads get 503 until a slot frees.

Authentication & tokens

See Bootstrap authentication and Authentication & authorization.

VariableDescription
BOATRAMP_AUTH_ROOT_PUBLIC_KEYThe trust anchor. Every node needs it to verify tokens.
BOATRAMP_AUTH_ROOT_PRIVATE_KEYThe signing key. Needed only where tokens are minted; keep it off verify-only nodes.
BOATRAMP_BOOTSTRAP_SECRETSingle-use secret that mints the first admin token, then is retired.
BOATRAMP_HOLDER_KEYHolder private key used to sign an offline delegation with token attenuate.

An external signer (KMS/HSM/Vault) replaces BOATRAMP_AUTH_ROOT_PRIVATE_KEY with its own credentials — see Hold the signing key in a KMS/HSM/Vault.

OIDC federation

For exchanging an identity-provider JWT for a boatramp token. See Federate CI auth with OIDC.

VariableDescription
BOATRAMP_OIDC_ISSUERTrusted issuer URL (its JWKS is fetched for verification).
BOATRAMP_OIDC_AUDIENCERequired audience claim.
BOATRAMP_OIDC_SCOPE_CLAIMClaim carrying the granted roles.

Cluster & shared-store frontends

VariableDescription
BOATRAMP_CLUSTER_RATE_LIMITRate-limit cluster-wide via the shared KV instead of per-node buckets.
BOATRAMP_SHARED_CACHE_COHERENCEKeep local config caches coherent across frontends sharing one KV. See Cache coherence.
BOATRAMP_BLOBSBlob backend (fs, s3, gcs, azure); env form of --blobs.
BOATRAMP_KVMetadata KV backend (slatedb, memory, cloudflare); env form of --kv.
BOATRAMP_KV_S3Run the SlateDB control-plane KV on the S3/R2 object store (reusing the --blobs s3 config) instead of local disk — durable metadata for a volumeless container. Env form of --kv-s3.
BOATRAMP_KV_S3_PREFIXKey prefix for the --kv-s3 store within the bucket (default _kv).
BOATRAMP_S3_BUCKETS3/R2 bucket for s3 blobs and (with --kv-s3) the SlateDB KV.
BOATRAMP_S3_ENDPOINTS3-compatible endpoint URL (R2: https://<account>.r2.cloudflarestorage.com).
BOATRAMP_S3_REGIONBucket region (R2 uses auto).
BOATRAMP_S3_PATH_STYLEUse path-style addressing (for non-AWS endpoints; R2 accepts it).
AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEYCredentials for the s3/R2 backend (standard AWS resolution).

Compute backend

Map to the [compute] section in boatramp.cfg. Set any of these and the section is enabled even without a config file (a set variable wins over its file value; an unset one defers to the file/default). See Run compute workloads.

VariableOverridesDescription
BOATRAMP_COMPUTE_BRIDGEcompute.bridgeBridge the container veths / VM taps attach to (default br-boatramp).
BOATRAMP_COMPUTE_SUBNETcompute.subnetGuest IP subnet (default 10.0.0.0/24).
BOATRAMP_COMPUTE_VCPUScompute.vcpusvCPUs advertised as schedulable (0 = detect from the host).
BOATRAMP_COMPUTE_MEM_MIBcompute.mem_mibMemory (MiB) advertised as schedulable (0 = a 1 GiB default).
BOATRAMP_COMPUTE_REGIONcompute.regionThis node’s region tag for nearest-replica routing.
BOATRAMP_COMPUTE_SQL_SHIM_URLcompute.sql_shim_urlGuest-reachable base URL of the compute SQL shim (enables a workload’s --bind sql).
BOATRAMP_COMPUTE_MANAGED_DB_PRIVILEGEcompute.managed_db_privilegeHow a managed DB image runs on a shared-kernel backend: rootless (default) or caps.
BOATRAMP_COMPUTE_DOCKER_ENDPOINTcompute.docker_endpointRemote-Docker endpoint mode: published (default) or bridge.
BOATRAMP_COMPUTE_DOCKER_VOLUME_MODEcompute.docker_volume_modeRemote-Docker volume mode: named (default) or bind.
BOATRAMP_COMPUTE_KERNEL_SIGNING_PUBKEYScompute.kernel_signing_pubkeysComma-separated <alg>:<hex> kernel-signing trust anchors (replaces, not appends to, the defaults).
BOATRAMP_COMPUTE_KERNEL_ALLOWED_HASHEScompute.kernel_allowed_hashesComma-separated sha256-hex allow-list of kernel content hashes (replaces the defaults).
BOATRAMP_COMPUTE_INTERNAL_DNScompute.internal_dnsRun the per-project internal DNS resolver on the bridge gateway so a guest resolves a sibling workload by name (default true; Linux + container backend). See internal name resolution.
BOATRAMP_COMPUTE_DNS_UPSTREAMcompute.dns_upstreamUpstream resolver (host:port) the internal DNS forwards external names to (default 1.1.1.1:53).
BOATRAMP_COMPUTE_DNS_DOMAINcompute.dns_domainInternal DNS suffix names live under, <workload>.<project>.<domain> (default boatramp.internal).

Security-critical: BOATRAMP_COMPUTE_KERNEL_SIGNING_PUBKEYS and BOATRAMP_COMPUTE_KERNEL_ALLOWED_HASHES are the kernel trust anchors for the posture-scaled kernel bar — a value here decides which kernels a multi-tenant node will boot. In a 12-factor deployment the environment is the operator’s trusted config source (a fly.toml [env] is committed the same as a file), so they are settable here; but the environment is more visible than a file (it leaks through /proc/<pid>/environ and is inherited by subprocesses), so prefer a config file for them when one is available.

Security posture

Map to the [security] section in boatramp.cfg. Setting any of these materialises the posture even without a config file: an unset section resolves to the strict multi-tenant default and each variable layers over it exactly as a file overrides block would (a set variable wins over the file). See boatramp.cfg and boatramp security explain. Byte caps take 0 = unlimited; booleans accept true/false, 1/0, yes/no, on/off.

VariableOverridesDescription
BOATRAMP_SECURITY_PROFILEsecurity.profileBase profile: multi-tenant (default), single-tenant, dev, or a custom profiles name.
BOATRAMP_SECURITY_ALLOW_UNAUTHENTICATED_PUBLIC_BINDoverrides.allow_unauthenticated_public_bindPermit a non-loopback bind with control-plane auth disabled.
BOATRAMP_SECURITY_MAX_UPLOAD_BYTESoverrides.max_upload_bytesDefault blob-upload cap in bytes (0 = unlimited).
BOATRAMP_SECURITY_ALLOW_SITE_UNIX_UPSTREAMSoverrides.allow_site_unix_upstreamsPermit site-declared unix: gateway upstreams.
BOATRAMP_SECURITY_ALLOW_SITE_PRIVATE_UPSTREAMSoverrides.allow_site_private_upstreamsPermit site-declared gateway upstreams to private/loopback IPs.
BOATRAMP_SECURITY_ALLOW_GUEST_PRIVATE_EGRESSoverrides.allow_guest_private_egressPermit a guest’s outbound wasi:http to reach private/loopback IPs.
BOATRAMP_SECURITY_ALLOW_GUEST_SELF_EGRESSoverrides.allow_guest_self_egressPermit a guest’s outbound wasi:http to reach this instance’s own serve socket.
BOATRAMP_SECURITY_ALLOW_GUEST_EGRESS_EXTRA_CAoverrides.allow_guest_egress_extra_caPermit the guest egress TLS client to trust an operator-supplied extra CA (BOATRAMP_GUEST_EGRESS_EXTRA_CA_FILE) on top of the webpki roots. Widens trust, never bypasses verification. Off under multi-tenant.
BOATRAMP_SECURITY_MAX_HANDLER_BLOB_BYTESoverrides.max_handler_blob_bytesCap on handler blobstore host reads/ranges/copies (0 = unlimited).
BOATRAMP_SECURITY_MAX_COMPONENT_BYTESoverrides.max_component_bytesCap on a Wasm component blob (0 = unlimited).
BOATRAMP_SECURITY_OIDC_REQUIRE_AUDIENCEoverrides.oidc_require_audienceRequire an OIDC audience when OIDC is enabled.
BOATRAMP_SECURITY_DOMAIN_VERIFY_ALLOW_PRIVATEoverrides.domain_verify_allow_privatePermit HTTP domain-verification probes to private hosts.
BOATRAMP_SECURITY_DOMAIN_VERIFY_SELF_SERVEoverrides.domain_verify_self_serveServe pending ownership challenges from the edge (the domain-attach fix).
BOATRAMP_SECURITY_ALLOW_SHARED_KERNEL_COMPUTEoverrides.allow_shared_kernel_computePermit untrusted workloads on shared-kernel compute backends.
BOATRAMP_SECURITY_ALLOW_COMPUTE_EXECoverrides.allow_compute_execPermit boatramp compute exec (run a command inside a running workload). Off in every profile but dev — it is arbitrary code execution in the workload; opt in for migrations/backups/debug.
BOATRAMP_SECURITY_RATELIMIT_FAIL_OPENoverrides.ratelimit_fail_openFail open instead of closed when the rate-limit KV is unreadable.
BOATRAMP_SECURITY_ALLOW_IMPLICIT_ROUTINGoverrides.allow_implicit_routingResolve an unmatched Host to a site without an explicit domain registration.
BOATRAMP_SECURITY_REQUIRE_POPoverrides.require_popRequire every token to be cnf-bound and PoP-proven fleet-wide.
BOATRAMP_SECURITY_REQUIRE_DOMAIN_VERIFICATIONoverrides.require_domain_verificationRefuse to serve a non-local Host that isn’t a verified, attached virtualhost.
BOATRAMP_SECURITY_ALLOW_ENV_SECRET_REFSoverrides.allow_env_secret_refsPermit a handler’s / function’s secrets map to name a bare / env:-scheme reference into the serve process’s own environment. Off under multi-tenant.
BOATRAMP_SECURITY_REQUIRE_TENANCY_DECLARATIONoverrides.require_tenancy_declarationRequire every sql/orm-opening component to make an explicit in-site tenancy decision (disabled or scoped). On under multi-tenant.
BOATRAMP_SECURITY_ALLOW_CROSS_TENANT_DBoverrides.allow_cross_tenant_dbPermit a component to declare a cross-tenant (all) read/write access mode. Off under multi-tenant (capped to own).
BOATRAMP_SECURITY_ALLOW_GUEST_MINT_CAPABILITYoverrides.allow_guest_mint_capabilityPermit a guest’s capability capability to mint fleet-signed target-capability tokens. Off under multi-tenant.
BOATRAMP_SECURITY_MAX_GUEST_CAPABILITY_TTL_SECSoverrides.max_guest_capability_ttl_secsOperator ceiling (seconds) on a guest-minted capability’s TTL; a larger request is clamped. 0 disables minting.
BOATRAMP_SECURITY_ALLOW_GUEST_EMAILoverrides.allow_guest_emailPermit a guest handler’s/function’s email capability to send. Off under multi-tenant (an SMTP profile + secrets envelope still gate actual delivery).
BOATRAMP_SECURITY_ALLOW_GUEST_ADMIN_DOMAINSoverrides.allow_guest_admin_domainsPermit a guest’s admin capability to manage the project’s domains. Off under multi-tenant.
BOATRAMP_SECURITY_ALLOW_GUEST_ADMIN_EMAILoverrides.allow_guest_admin_emailPermit a guest’s admin capability to manage the project’s SMTP email profiles. Off under multi-tenant.
BOATRAMP_SECURITY_ALLOW_GUEST_ADMIN_SITEoverrides.allow_guest_admin_sitePermit a guest’s admin capability to write the project’s site config + aliases. Off under multi-tenant.
BOATRAMP_SECURITY_ALLOW_GUEST_ADMIN_SECRETSoverrides.allow_guest_admin_secretsPermit a guest’s admin capability to write the project’s sealed secrets. Off under multi-tenant.

The four tenancy/capability variables above set the fleet posture; a per-project override of the same knobs is config-file only (see security.projects). Guest-admin surface knobs (allow_guest_admin_*) and allow_guest_email are file-only — not env-settable.

Handler backends

The [handlers.bindings.sql] knobs (the single managed-SQL backend) map to these; set any and the section is created even without a config file (env wins over the file value; secrets stay indirected via the *_TOKEN_ENV names, never the token itself). See Handler bindings.

VariableOverridesDescription
BOATRAMP_HANDLERS_SQL_DIRbindings.sql.dirSingle-node: root dir for the per-site embedded databases (default <data-dir>/handlers-sql).
BOATRAMP_HANDLERS_SQL_URLbindings.sql.urlCluster: base sqld data URL — switches from single-node to a shared sqld cluster.
BOATRAMP_HANDLERS_SQL_ADMIN_URLbindings.sql.admin_urlCluster: sqld admin API base URL (required when url is set).
BOATRAMP_HANDLERS_SQL_REPLICA_URLbindings.sql.replica_urlCluster: optional read-replica data URL for read-only transactions.
BOATRAMP_HANDLERS_SQL_TOKEN_ENVbindings.sql.token_envName of the env var holding the sqld data auth token.
BOATRAMP_HANDLERS_SQL_ADMIN_TOKEN_ENVbindings.sql.admin_token_envName of the env var holding the sqld admin API key.
BOATRAMP_HANDLERS_SQL_PREVIEW_MODEbindings.sql.preview_modePreview-database policy: empty (default), branch, or shared.
BOATRAMP_HANDLERS_SQL_PREVIEW_INITbindings.sql.preview_initPath to an idempotent SQL script run when an empty preview db is first opened.
BOATRAMP_HANDLERS_SQL_DEPROVISION_GRACE_SECSbindings.sql.deprovision_grace_secsSoft-delete grace window (seconds) for a per-tenant managed DB. Default 604800 (7 days). On a project/site delete, a Shared + Postgres tenant is soft-deleted (its database renamed aside, role disabled) and stays recoverable for this long before a reaper hard-drops it; 0 disables the soft path (immediate, irreversible hard drop). MySQL and all Single tenants always hard-drop immediately.
BOATRAMP_SQL_TOKEN—Auth token for a remote libsql database referenced by the SQL binding.
(your url_env)—Connection URL (a secret) for an external bring-your-own SQL database — the var name is whatever you set as url_env / read_url_env under [handlers.bindings.sql.databases]. See Bring your own database.
BOATRAMP_FC_*—Embedded-VMM / Firecracker compute-backend settings (kernel, rootfs, bridge, subnet, …). See Run compute workloads.
BOATRAMP_VMM_SERIAL—Attach the microVM serial console (debugging).

External SQL databases ([handlers.bindings.sql.databases])

The bring-your-own / managed-compute database map is env-settable too, so a managed co-located Postgres needs no config file. Each database <NAME> is declared by setting one or more BOATRAMP_HANDLERS_SQL_DB_<NAME>_<FIELD> variables; the member names are discovered from the environment (there is no file to enumerate them). An env-declared database is merged over — per field, by key — whatever the file declared under that name.

The default database (the empty-string map key, opened as sql.open("")) is addressed by the reserved name token DEFAULT: BOATRAMP_HANDLERS_SQL_DB_DEFAULT_KIND populates the "" key.

<FIELD> is one of KIND, URL_ENV, READ_URL_ENV, COMPUTE, DATABASE, USER, PASSWORD_ENV, POOL_MAX, READ_ONLY, ALLOW_PREVIEW, CONNECT_TIMEOUT_SECS, IMAGE, VOLUME_SIZE_MIB, STARTUP_GRACE_SECS (each mirrors a field of the RON databases entry; secrets stay indirected via the *_ENV names). STARTUP_GRACE_SECS sets how long a freshly launched managed-DB replica may take to become healthy before the reconcile treats it as a broken launch; omit it for the per-engine default (Postgres 60 s, MySQL 120 s). See Startup grace. Example — a managed Postgres as the default database, with boatramp managing the credential (no PASSWORD_ENV):

BOATRAMP_HANDLERS_SQL_DB_DEFAULT_KIND=postgres
BOATRAMP_HANDLERS_SQL_DB_DEFAULT_COMPUTE=pg
BOATRAMP_HANDLERS_SQL_DB_DEFAULT_DATABASE=appdb
BOATRAMP_HANDLERS_SQL_DB_DEFAULT_USER=app

For a managed co-located database (COMPUTE set, no PASSWORD_ENV), boatramp auto-registers the backing compute workload — so the four lines above are enough to boot a Postgres; no separate compute set / apply step. IMAGE overrides the stock image (default pgvector/pgvector:pg16 for postgres, mysql:8.0 for mysql) and VOLUME_SIZE_MIB the persistent data-volume size (default 10240 = 10 GiB). An operator-declared workload of the same name always wins over the auto-registered one.

Handler secrets are injected by reference: the site config names a host env-var, and the server resolves it at instantiation so the literal never lands in a manifest. See Handler host bindings.

Secrets envelope

Map to the [secrets] section in boatramp.cfg — envelope encryption for private keys at rest. Set any and the section is created even without a config file. kek_file holds a path (never key material); the Vault token stays indirected via token_env (a variable name, not the token).

VariableOverridesDescription
BOATRAMP_SECRETS_ENVELOPEsecrets.envelopeBackend: local (machine-local AES-256-GCM KEK) or vault (Vault Transit).
BOATRAMP_SECRETS_KEK_FILEsecrets.kek_filePath to the local-KEK key file (auto-generated 0600 if absent). Default <data-dir>/secrets/kek.
BOATRAMP_SECRETS_VAULT_ADDRsecrets.vault.addrVault address, e.g. https://vault:8200.
BOATRAMP_SECRETS_VAULT_KEYsecrets.vault.keyVault Transit key name to wrap under.
BOATRAMP_SECRETS_VAULT_TOKEN_ENVsecrets.vault.token_envName of the env var holding the Vault token (default VAULT_TOKEN).

Cluster section ([cluster])

Map to the [cluster] section in boatramp.cfg — the self-hosted cluster mode’s own config, distinct from the founding/joining action flags in the Cluster & shared-store frontends table above (BOATRAMP_CLUSTER_INIT / BOATRAMP_CLUSTER_JOIN / BOATRAMP_CLUSTER_ADVERTISE_ADDR). A BOATRAMP_CLUSTER_LISTEN materialises an absent section (a node must know where to bind its mesh); the other fields then layer on. List-valued vars are comma-separated.

VariableOverridesDescription
BOATRAMP_CLUSTER_LISTENcluster.listenAddress to bind this node’s Raft peer mesh on (e.g. 10.0.0.2:7000). Required to materialise an absent section.
BOATRAMP_CLUSTER_ROOT_PUBKEYScluster.root_pubkeysComma-separated es256:/ed25519: root anchor set defining the cluster identity.
BOATRAMP_CLUSTER_SEEDScluster.seedsComma-separated control-plane addresses of existing members to join through.
BOATRAMP_CLUSTER_JOIN_TOKENcluster.join_tokenSingle-use join token (kept out of plain sight via an env:VAR / path:/file prefix).
BOATRAMP_CLUSTER_STORE_DIRcluster.store_dirDirectory for this node’s durable Raft log/state (default <data-dir>/raft).
BOATRAMP_CLUSTER_MESH_KEY_FILEcluster.mesh.key_filePath to this node’s Ed25519 mesh identity key (auto-generated 0600).
BOATRAMP_CLUSTER_MESH_KEY_ROTATIONcluster.mesh.key_rotationAutomatic mesh key-rotation cadence (e.g. 30d).
BOATRAMP_CLUSTER_MESH_JOIN_TOKEN_TTLcluster.mesh.join_token_ttlTTL for a single-use join token (e.g. 1h).
BOATRAMP_CLUSTER_MESH_GATE_CLIENT_WRITEScluster.mesh.gate_client_writesGate mesh client-writes behind a control-plane cluster-write capability.

TLS / ACME (incl. wildcard DNS-01)

The listener’s TLS mode and the ACME issuance parameters — previously serve flags only — are env-settable too, so wildcard DNS-01 can be configured with no config file (e.g. a fly [env]). The DNS provider credentials are already env-only (below).

VariableFlagDescription
BOATRAMP_TLS--tlsListener TLS mode: off (default), custom, acme, acme-dns, rpk. Use acme-dns for wildcard certs.
BOATRAMP_ACME_DOMAINS--acme-domainComma-separated domains to certify. An explicit wildcard (*.example.com) is issued via DNS-01.
BOATRAMP_ACME_DNS_PROVIDER--acme-dns-providerDNS-01 provider: manual, cloudflare, route53, oci, digitalocean, hetzner, ns1, dnsimple, gcp, azure, akamai.
BOATRAMP_ACME_CONTACT--acme-contactContact email for the ACME account.
BOATRAMP_ACME_DIRECTORY--acme-directoryACME directory URL (default Let’s Encrypt production).
BOATRAMP_ACME_CACHE--acme-cacheCertificate cache directory (default ./data/acme).
BOATRAMP_ACME_CA_CERT--acme-ca-certExtra root CA (PEM) to trust for the ACME server (e.g. Pebble’s).
BOATRAMP_ACME_WILDCARD_PREVIEW--acme-wildcard-previewAlso issue a *.deploy.<domain> wildcard for preview hosts (true/false).

An exact host (an apex/www/console site or cert) always wins over a wildcard, in both host→site routing and SNI cert selection — so *.example.com never shadows a declared exact host.

DNS provider credentials

Auto-DNS and --tls acme-dns read provider credentials (CLOUDFLARE_API_TOKEN, AWS_KEY, HETZNER_DNS_TOKEN, …) from the environment. Each provider’s exact variables are listed in DNS providers & credentials.

Test-only variables

Variables prefixed BOATRAMP_TEST_ gate #[ignore] live integration tests (cloud KMS, SoftHSM, libsql, Docker, S3). They have no effect on a running server and are not part of the operational surface.