Skip to main content

CodeGraph server environment variables

Compare CodeGraph server settings with the shipped .env sample and Docker Compose fallbacks before starting the deployment services.

Getting Started

This reference is for server deployment operators. It lists every name in the shipped .env.example and the current docker-compose.yml substitutions. Set values in the protected /opt/codegraph/.env only for enabled services and features.

“Sample” is the value in .env.example. Set credentials and replace example addresses with your deployment addresses before starting the relevant services. “Compose fallback” applies when a variable is unset. With ${VARIABLE:-value}, an explicitly empty value also selects the fallback. A dash means the source does not define the value; “no fallback” means direct ${VARIABLE} substitution. An unset value produces a warning and an empty string. Set the secrets needed by enabled services in .env. Select the provider and enable the features that use those credentials in config.yaml.

For the setup workflow, see Configure a deployment. Keep the live .env out of source control and support requests.

Database, API and browser access

These settings cover the database, initial administrator, browser access, public API addresses, and approved Git servers. Replace codegraph.ru addresses with your own deployment addresses where the relevant interfaces are exposed to users.

CODEGRAPH_OUTBOUND_GIT_ORIGIN_ALLOWLIST takes exact HTTPS origins separated by commas, for example https://git.internal.example,https://git2.internal.example:8443. An empty value grants no private Git exceptions. IP ranges and wildcards are unsupported.

Database, API and browser access
Variable Sample Compose fallback
API_ADMIN_PASSWORD empty no fallback
API_PROVIDER_SECRET_KEY empty empty
API_ADMIN_USERNAME admin admin
API_ALLOWED_HOSTS localhost,127.0.0.1,::1,api,codegraph-api,api.codegraph.ru,codegraph.ru localhost,127.0.0.1,::1,api,codegraph-api,api.codegraph.ru,codegraph.ru
API_JWT_SECRET empty no fallback
CODEGRAPH_AGENT_PLUGIN_MCP_PUBLIC_URL https://api.codegraph.ru/agent-plugin/mcp https://api.codegraph.ru/agent-plugin/mcp
CODEGRAPH_API_BIND — 8000
CODEGRAPH_DASHBOARD_INLINE_ENTRY_ASSETS — 1
CODEGRAPH_FRONTEND_BIND — 3100
CODEGRAPH_MCP_OAUTH_ISSUER https://api.codegraph.ru/api/v1/auth/mcp https://api.codegraph.ru/api/v1/auth/mcp
CODEGRAPH_MCP_PUBLIC_URL https://api.codegraph.ru/mcp https://api.codegraph.ru/mcp
CODEGRAPH_MCP_REMOTE_AUTH_MODE oauth legacy
CODEGRAPH_OUTBOUND_GIT_ORIGIN_ALLOWLIST empty empty
CORS_ALLOWED_ORIGINS empty empty
ENVIRONMENT production —
LOG_LEVEL INFO INFO
MCP_HTTP_BIND — 127.0.0.1:27495
POSTGRES_PASSWORD empty no fallback

Model providers and OpenViking

Set credentials only for selected providers. OPENVIKING_CONFIG_TEMPLATE selects the template file; OPENVIKING_API_KEY protects its API. For local embedding and rerank, also set COMPOSE_PROFILES=local-models.

Model providers and OpenViking
Variable Sample Compose fallback
CODEGRAPH_EMBED_MODEL_REVISION — dd76d535f5447ca3897a9c893fb1e612ead98192
CODEGRAPH_RERANK_MODEL_REVISION — d7d7e73b6ea138ced340b83865931b5dfb6c97aa
GIGACHAT_AUTH_KEY empty empty
GIGACHAT_BASE_URL https://gigachat.devices.sberbank.ru/api/v1 https://gigachat.devices.sberbank.ru/api/v1
GIGACHAT_BILLING_ACCOUNT_ID empty empty
GIGACHAT_BILLING_MODE auto auto
GIGACHAT_CA_BUNDLE_FILE empty empty
GIGACHAT_CLIENT_ID empty empty
GIGACHAT_CREDENTIALS empty empty
GIGACHAT_MODEL GigaChat-2-Pro GigaChat-2-Pro
GIGACHAT_SCOPE GIGACHAT_API_PERS GIGACHAT_API_PERS
GIGACHAT_SPACE_ID empty empty
GIGACHAT_TIMEOUT 60.0 60.0
GIGACHAT_VERIFY_SSL_CERTS true true
OPENAI_API_KEY empty —
OPENVIKING_API_KEY — no fallback / empty
OPENVIKING_BASE_URL — http://openviking:1933
OPENVIKING_BOT_BIND — 127.0.0.1:8020
OPENVIKING_BOT_PORT — 8020
OPENVIKING_CA_BUNDLE — empty
OPENVIKING_CLIENT_CERT — empty
OPENVIKING_CLIENT_KEY — empty
OPENVIKING_CONFIG_TEMPLATE — ov.conf
OPENVIKING_HTTP_BIND — 127.0.0.1:1933
OPENVIKING_IMAGE_TAG — v0.4.16
OPENVIKING_WITH_BOT — 0
PRELOAD_EMBEDDING_MODEL — 0
YANDEX_API_KEY empty no fallback / empty
YANDEX_BILLING_ACCOUNT_ID — empty
YANDEX_FOLDER_ID empty no fallback / empty
YANDEX_IAM_TOKEN — empty
YANDEX_SERVICE_ACCOUNT_KEY_PATH — empty

Orchestration and finance

These settings control Temporal, task handoff, and financial artifact verification. Source signing and verification keys from an approved secret store. TEMPORAL_WORKER_CONTAINER_MEMORY_LIMIT caps the temporal-worker container; its fallback is 4G. Account for this limit alongside the GoCPG limits below.

Orchestration and finance
Variable Sample Compose fallback
CODEGRAPH_CODEX_PLATFORM_ROOT_USAGE_ATTESTATION_ISSUER_ID empty —
CODEGRAPH_CODEX_PLATFORM_ROOT_USAGE_ATTESTATION_KEY_ID empty —
CODEGRAPH_CODEX_PLATFORM_ROOT_USAGE_ATTESTATION_PUBLIC_KEY empty —
CODEGRAPH_CODEX_PLATFORM_SUBAGENT_ATTESTATION_PUBLIC_KEY empty —
CODEGRAPH_EVA_ARTIFACT_SIGNING_KEY_FILE ./secrets/eva/eva-artifact-signing.key —
CODEGRAPH_EVA_HOOK_ARTIFACT_DIR ./data/eva/artifacts —
CODEGRAPH_EVA_PROVIDER_OUTBOX_HMAC_KEY_B64 empty no fallback
CODEGRAPH_EVA_PROVIDER_OUTBOX_HMAC_KEY_ID empty no fallback
CODEGRAPH_EVA_PROVIDER_OUTBOX_HMAC_VERIFICATION_KEYS_JSON {} {}
CODEGRAPH_HANDOFF_EXECUTION_MODE auto —
CODEGRAPH_LOCAL_OPERATOR_HANDOFF_BINDING empty —
CODEGRAPH_PROVIDER_WORKER_HANDOFF_BINDING empty —
TEMPORAL_ADDRESS — temporal:7233
TEMPORAL_ENABLED true true
TEMPORAL_GRPC_BIND — 127.0.0.1:7233
TEMPORAL_MODE shadow shadow
TEMPORAL_NAMESPACE default default
TEMPORAL_OUTBOX_DISPATCHER_ENABLED true true
TEMPORAL_SERVER_VERSION — 1.29.3
TEMPORAL_UI_BIND — 127.0.0.1:8233
TEMPORAL_UI_URL — http://localhost:8233
TEMPORAL_UI_VERSION — 2.50.0
TEMPORAL_WORKER_CONTAINER_MEMORY_LIMIT — 4G
TEMPORAL_WORKER_ROLE all all

Git and integration credentials

These settings cover GitVerse and GitHub connections and GoCPG. For GitLab, use the approved origin above and store the connection secret through the UI or API.

Git and integration credentials
Variable Sample Compose fallback
CODEGRAPH_GITHUB_API_TOKEN empty empty
DUCKDB_VERSION — 1.5.5
GITVERSE_API_URL — https://api.gitverse.ru
GITVERSE_ENABLED false false
GITVERSE_TOKEN — empty
GITVERSE_WEBHOOK_SECRET — empty
GOCPG_GRPC_BIND — 127.0.0.1:50051
GOCPG_SKIP_TESTS — true
GOCPG_CONTAINER_MEMORY_LIMIT 4G 4G
GOCPG_DUCKDB_BULK_MEMORY_LIMIT 2GB 2GB
GOCPG_DUCKDB_READONLY_MEMORY_LIMIT 1GB 1GB
GOCPG_SOURCE_PATH . —
OAUTH_GITVERSE_CLIENT_ID empty empty
OAUTH_GITVERSE_CLIENT_ID_VAULT_KEY client_id client_id
OAUTH_GITVERSE_CLIENT_SECRET empty empty
OAUTH_GITVERSE_CLIENT_SECRET_VAULT_KEY client_secret client_secret
OAUTH_GITVERSE_SERVER_URL https://gitverse.ru https://gitverse.ru
OAUTH_GITVERSE_SERVER_URL_VAULT_KEY server_url server_url
OAUTH_GITVERSE_VAULT_PATH empty empty

GoCPG and DuckDB memory

GOCPG_CONTAINER_MEMORY_LIMIT sets the total memory limit for the gocpg container. GOCPG_DUCKDB_BULK_MEMORY_LIMIT limits DuckDB memory when building or updating a CPG; GOCPG_DUCKDB_READONLY_MEMORY_LIMIT applies to reads. A CPG is a code property graph used to analyze a project. Both DuckDB settings are passed to api, mcp, temporal-worker, and gocpg, which can run the native analyzer or read a CPG.

A DuckDB limit does not cap the entire process. The parser, graph, and GoCPG analyses need additional memory within the container limit. Account for the other services and the server’s available memory as well. Start with 8G / 3GB / 1GB, measure memory use with your project and adjust the limits from the results.

On the Docker Compose host, open the existing .env in the distribution directory and add these lines. Preserve the other settings and secrets:

GOCPG_CONTAINER_MEMORY_LIMIT=8G
GOCPG_DUCKDB_BULK_MEMORY_LIMIT=3GB
GOCPG_DUCKDB_READONLY_MEMORY_LIMIT=1GB

Wait for active imports and audits to finish. Run the following commands from that directory in Bash (Linux/macOS) or PowerShell. If the deployment uses additional Compose files, include the same -f options when restarting:

docker compose up -d --no-build --no-deps api mcp temporal-worker gocpg
docker compose exec -T gocpg sh -c 'printenv GOCPG_DUCKDB_BULK_MEMORY_LIMIT GOCPG_DUCKDB_READONLY_MEMORY_LIMIT'
docker inspect codegraph-gocpg --format '{{.HostConfig.Memory}}'
docker stats --no-stream codegraph-api codegraph-mcp codegraph-temporal-worker codegraph-gocpg

With these values, printenv returns 3GB and 1GB, and docker inspect returns 8589934592 (8 GiB in bytes). Repeat the audit and observe memory use. After a failure, check Docker events: an automatic restart can hide an earlier OOM in the container’s current state.

docker events --since 30m --until 0s --filter container=codegraph-gocpg --filter event=oom

For GoCPG run directly outside this Compose distribution, native defaults are 8GB for writes and 4GB for reads. The DuckDB environment variables override those defaults; GOCPG_CONTAINER_MEMORY_LIMIT applies only to Compose.

Security and secret storage

Feature flags enable security controls; Vault and mTLS settings configure secret retrieval and client certificate verification.

Security and secret storage
Variable Sample Compose fallback
DLP_ENABLED true true
RELEASE_CONTROL_ENABLED false false
SECURITY_ENABLED true true
SERVICE_ACCOUNT_MTLS_ENABLED false false
SERVICE_ACCOUNT_MTLS_FINGERPRINT_HEADER X-Client-Cert-Fingerprint X-Client-Cert-Fingerprint
SERVICE_ACCOUNT_MTLS_REQUIRED_INTERFACES ["grpc","acp"] ["grpc","acp"]
SERVICE_ACCOUNT_MTLS_SUBJECT_HEADER X-Client-Cert-Subject X-Client-Cert-Subject
SIEM_ENABLED false false
VAULT_ADDR http://localhost:8200 http://localhost:8200
VAULT_AUTH_METHOD token token
VAULT_ENABLED false false
VAULT_KUBERNETES_ROLE empty empty
VAULT_ROLE_ID empty empty
VAULT_SECRETS_MOUNT secret secret
VAULT_SECRET_ID empty empty
VAULT_TLS_VERIFY true true
VAULT_TOKEN empty empty

Monitoring and notifications

Sample Sentry, email, and metrics addresses describe an example environment; replace them with your infrastructure endpoints before enabling those services.

Monitoring and notifications
Variable Sample Compose fallback
ALERTMANAGER_BIND — 127.0.0.1:9093
ALERTMANAGER_CONFIG_FILE — ./monitoring/alertmanager.yml
ALERTMANAGER_CREDENTIALS_FILE — ./secrets/leads-api-key.txt
ALERTMANAGER_WEBHOOK_URL http://localhost:9095/alert —
DASHBOARD_EMAIL_FROM hello@codegraph.ru empty
DASHBOARD_EMAIL_TO empty empty
DASHBOARD_SMTP_HOST smtp.yandex.ru empty
DASHBOARD_SMTP_PASSWORD empty empty
DASHBOARD_SMTP_PORT 587 587
DASHBOARD_SMTP_USER empty empty
DASHBOARD_TELEGRAM_CHAT_ID — empty
DASHBOARD_TELEGRAM_TOKEN — empty
DASHBOARD_WEBHOOK_AUTH_HEADER — empty
DASHBOARD_WEBHOOK_URL — empty
DORA_METRICS_REFRESH_ACTION_KIND dora_metrics_refresh dora_metrics_refresh
DORA_METRICS_REFRESH_CADENCE 0 6,18 * * * 0 6,18 * * *
DORA_METRICS_REFRESH_ENABLED true true
DORA_METRICS_REFRESH_ENVIRONMENT prod prod
DORA_METRICS_REFRESH_HTTP_TIMEOUT_SECONDS 90.0 90.0
DORA_METRICS_REFRESH_ISSUE_LIMIT 50 50
DORA_METRICS_REFRESH_PROVIDER_PROFILE yandex-cloud-sentry yandex-cloud-sentry
DORA_METRICS_REFRESH_RETRY_ATTEMPTS 5 5
DORA_METRICS_REFRESH_RETRY_BACKOFF_SECONDS 10.0 10.0
DORA_METRICS_REFRESH_SERVICE_ACCOUNT_REF svc:scheduled-project-actions svc:scheduled-project-actions
DORA_METRICS_REFRESH_STATS_PERIOD 24h 24h
DORA_METRICS_REFRESH_TIMEZONE Asia/Yekaterinburg Asia/Yekaterinburg
GRAFANA_ADMIN_PASSWORD empty no fallback
GRAFANA_ADMIN_USER admin admin
GRAFANA_BIND — 127.0.0.1:3000
GRAFANA_ROOT_URL http://localhost:3000 http://localhost:3000
PROMETHEUS_BIND — 127.0.0.1:9090
PROMETHEUS_RETENTION_SIZE — 5GB
SENTRY_ALERT_EXPORTER_PORT 9102 9102
SENTRY_ALERT_LEVELS error,fatal error,fatal
SENTRY_AUTH_TOKEN empty empty
SENTRY_BASE_URL https://sentry.codegraph.ru https://sentry.codegraph.ru
SENTRY_DSN empty empty
SENTRY_ENVIRONMENT production production
SENTRY_ISSUE_ADMIN_TOKEN empty empty
SENTRY_ORG codegraph codegraph
SENTRY_POLL_SECONDS 60 60
SENTRY_PROJECT codegraph-backend codegraph-backend
SENTRY_PROJECTS codegraph-backend,codegraph-frontend ${SENTRY_PROJECT:-codegraph-backend}
SENTRY_RELEASE empty empty
VITE_GITVERSE_ENABLED false false
VITE_RELEASE_CONTROL_ENABLED false false
VITE_SENTRY_DSN empty empty
VITE_SENTRY_ENVIRONMENT production production
VITE_SENTRY_RELEASE empty empty

Deployment and Docker

These settings label the deployment, pin images, and limit Docker logs.

Deployment and Docker
Variable Sample Compose fallback
CODEGRAPH_DEPLOYED_AT empty empty
CODEGRAPH_DEPLOYED_BRANCH main main
CODEGRAPH_DEPLOYED_COMMIT empty empty
CODEGRAPH_DEPLOYED_RELEASE_ID empty empty
CODEGRAPH_DOCKER_LOG_MAX_FILES — 3
CODEGRAPH_DOCKER_LOG_MAX_SIZE — 10m
FRONTEND_NODE_IMAGE_TAG — 22.18-bookworm-slim

COMPOSE_PROFILES is a Docker Compose control rather than a substitution in docker-compose.yml. It is empty by default, so optional profiles are off. Set local-models for local models; check the release’s Compose file for available profiles.