English
Environment Variables
Overview
| Variable | Description |
|---|---|
PORT | HTTP port inside the container (default 3080). |
HTTPS_PORT | HTTPS port when using built-in TLS (default 3443). |
KEYCHAIN_PASSPHRASE | Encrypts stored Apple ID credentials in the keychain file. Use a strong random value. |
ADMIN_INIT_PIN | PIN for first /setup and admin password recovery. |
ADMIN_RECOVERY_ENABLED | Set true to enable /recover (optional). |
ALLOW_LAN_ACCESS | Allow LAN IP origins (default true). Set false on the public internet. |
ALLOWED_DOMAINS | Comma-separated browser origins allowed for API access. |
TRUST_PROXY | Set 1 behind nginx/Cloudflare so rate limits use the real client IP. |
ENABLE_MORE_LOGS | Verbose server logs when true. |
WEBAUTHN_RP_ID | Passkey RP ID — domain without port, e.g. example.com. |
WEBAUTHN_RP_NAME | Human-readable name shown in Passkey UI. |
WEBAUTHN_ALLOWED_ORIGINS | Comma-separated Origins for WebAuthn (must match the address bar, including port). |
NODE_ENV | Usually production in deployments. |
DBUS_SESSION_BUS_ADDRESS | Use unix:path=/nonexistent on Linux without a desktop keyring. |
JWT_SECRET | Admin JWT secret (optional; use a random value in production). |
ENABLE_AUTO_CERT | Set true to auto-generate LAN HTTPS certs (requires openssl in the container). |
LAN_IP | LAN IP for auto-cert SAN (e.g. 192.168.1.101). |
LAN_HOSTNAME | Local hostname for DNS / WebAuthn (e.g. ipa-harbor.local). |
MAX_CONCURRENT_DOWNLOADS | Concurrent download jobs (default 2). |
MANIFEST_TICKET_TTL_MS | OTA manifest ticket TTL in ms (default 3 minutes). |
PACKAGE_TICKET_TTL_MS | IPA package ticket TTL in ms (default 1 day). |
WEBAUTHN_CHALLENGE_TTL_MS | Passkey challenge TTL in ms (default 5 minutes). |
WEBAUTHN_CHALLENGE_CLEANUP_INTERVAL_MINUTES | Passkey challenge cleanup interval in minutes (default 5). |
PORT
Default 3080. Override with -e PORT=… for the in-container listener; in -p host:container, the right side must match PORT (e.g. -p 3388:3080).
HTTPS_PORT
Default 3443. Override with -e HTTPS_PORT=…; map with e.g. -p 8443:3443. Omit the mapping if you do not use built-in TLS.
KEYCHAIN_PASSPHRASE
Required — the app will not start without it. See Compose comments for generating a random value; never leak or commit it.
ADMIN_INIT_PIN
Required to start when no admin exists. See Forgot admin password.
ADMIN_RECOVERY_ENABLED
Turn off again after an emergency reset and restart.
ALLOW_LAN_ACCESS
Must be literally true for LAN origins; use false on the public internet (Compose example). Image Dockerfile defaults to true.
ALLOWED_DOMAINS
Hostnames only, comma-separated, no https://. Passkey also needs WEBAUTHN_ALLOWED_ORIGINS matching the URL users open.
TRUST_PROXY
Set 1 behind a reverse proxy so rate limits use the real IP; omit for direct container access.
WEBAUTHN_RP_ID
Configure together with WEBAUTHN_ALLOWED_ORIGINS; see Admin — Passkey login.
WEBAUTHN_ALLOWED_ORIGINS
Each entry must match the address bar Origin (scheme and port).
ENABLE_AUTO_CERT
Use either this or manual certs/ mounts. Optional LAN_IP / LAN_HOSTNAME — see Compose comments.
Examples
bash
-p 3388:3080
-e ENABLE_MORE_LOGS=true
-e KEYCHAIN_PASSPHRASE=X96A49763R
-v ipa_data:/app/data
-v ipa_certs:/app/certs
--name ipa-harborSee also server/docker-compose.example.yml.