Skip to content

Environment Variables ​

Overview ​

VariableDescription
PORTHTTP port inside the container (default 3080).
HTTPS_PORTHTTPS port when using built-in TLS (default 3443).
KEYCHAIN_PASSPHRASEEncrypts stored Apple ID credentials in the keychain file. Use a strong random value.
ADMIN_INIT_PINPIN for first /setup and admin password recovery.
ADMIN_RECOVERY_ENABLEDSet true to enable /recover (optional).
ALLOW_LAN_ACCESSAllow LAN IP origins (default true). Set false on the public internet.
ALLOWED_DOMAINSComma-separated browser origins allowed for API access.
TRUST_PROXYSet 1 behind nginx/Cloudflare so rate limits use the real client IP.
ENABLE_MORE_LOGSVerbose server logs when true.
WEBAUTHN_RP_IDPasskey RP ID — domain without port, e.g. example.com.
WEBAUTHN_RP_NAMEHuman-readable name shown in Passkey UI.
WEBAUTHN_ALLOWED_ORIGINSComma-separated Origins for WebAuthn (must match the address bar, including port).
NODE_ENVUsually production in deployments.
DBUS_SESSION_BUS_ADDRESSUse unix:path=/nonexistent on Linux without a desktop keyring.
JWT_SECRETAdmin JWT secret (optional; use a random value in production).
ENABLE_AUTO_CERTSet true to auto-generate LAN HTTPS certs (requires openssl in the container).
LAN_IPLAN IP for auto-cert SAN (e.g. 192.168.1.101).
LAN_HOSTNAMELocal hostname for DNS / WebAuthn (e.g. ipa-harbor.local).
MAX_CONCURRENT_DOWNLOADSConcurrent download jobs (default 2).
MANIFEST_TICKET_TTL_MSOTA manifest ticket TTL in ms (default 3 minutes).
PACKAGE_TICKET_TTL_MSIPA package ticket TTL in ms (default 1 day).
WEBAUTHN_CHALLENGE_TTL_MSPasskey challenge TTL in ms (default 5 minutes).
WEBAUTHN_CHALLENGE_CLEANUP_INTERVAL_MINUTESPasskey challenge cleanup interval in minutes (default 5).

PORT ​

Default 3080. Override with -e PORT=… for the in-container listener; in -p host:container, the right side must match PORT (e.g. -p 3388:3080).

HTTPS_PORT ​

Default 3443. Override with -e HTTPS_PORT=…; map with e.g. -p 8443:3443. Omit the mapping if you do not use built-in TLS.

KEYCHAIN_PASSPHRASE ​

Required — the app will not start without it. See Compose comments for generating a random value; never leak or commit it.

ADMIN_INIT_PIN ​

Required to start when no admin exists. See Forgot admin password.

ADMIN_RECOVERY_ENABLED ​

Turn off again after an emergency reset and restart.

ALLOW_LAN_ACCESS ​

Must be literally true for LAN origins; use false on the public internet (Compose example). Image Dockerfile defaults to true.

ALLOWED_DOMAINS ​

Hostnames only, comma-separated, no https://. Passkey also needs WEBAUTHN_ALLOWED_ORIGINS matching the URL users open.

TRUST_PROXY ​

Set 1 behind a reverse proxy so rate limits use the real IP; omit for direct container access.

WEBAUTHN_RP_ID ​

Configure together with WEBAUTHN_ALLOWED_ORIGINS; see Admin — Passkey login.

WEBAUTHN_ALLOWED_ORIGINS ​

Each entry must match the address bar Origin (scheme and port).

ENABLE_AUTO_CERT ​

Use either this or manual certs/ mounts. Optional LAN_IP / LAN_HOSTNAME — see Compose comments.

Examples ​

bash
-p 3388:3080
-e ENABLE_MORE_LOGS=true
-e KEYCHAIN_PASSPHRASE=X96A49763R
-v ipa_data:/app/data
-v ipa_certs:/app/certs
--name ipa-harbor

See also server/docker-compose.example.yml.