Skip to content

Platform Environment Variables ​

Settings → Environment Variables answers one question: which environment-variable names can platform configuration read? It is a read-only inventory - values are never shown anywhere, and nothing is edited here.

What you see ​

  • All discovered names - every environment-variable name reported by the running processes, each with a scope badge: API, Worker, or API + Worker.
  • API process - the names visible to the API server.
  • Workers - the names visible to each worker, listed per worker.

The scope matters: a secret backend's settings are resolved by both the API and the workers, so a name it reads must be set on both.

Where an environment variable can be used ​

Only platform configuration that platform admins manage can read an environment variable, with {{ env('NAME') }} or {{ env('NAME', 'fallback') }}:

  • secret backend settings (for example the backend's bootstrap token)
  • inventory provider settings (the provider token_ref)

Flows, variables, devices, notifications, and git and file repositories are organization content, and they cannot read the platform's environment: it holds platform credentials. Store a value an organization needs as a secret and reference it with {{ secret('backend://path/key') }}, or as a variable when it is not sensitive. See Platform-only references for the full rule.

What this page is not ​

  • It does not show values - by design, the only protection an environment variable gets in the UI is that its value is never displayed.
  • It is not where you define values. Environment variables are set on the deployment itself (compose files, container environment) by whoever operates the platform.
  • It is not the platform's own configuration reference. Hegemony's HEGEMONY_-prefixed settings are documented separately in the environment variable reference.

This page requires the admin role.

Released as open source under the AGPL-3.0-or-later license. Development is sponsored by Rexonix s.r.o.. Contact — [email protected].