Portabase Logo
Portabase Agent

Environment Variables

Complete reference of .env configuration options.

Portabase provides flexibility through environment variables. These let you customize application behavior, database connection, authentication and storage.

If you use Docker Compose, set these variables in your .env file at the root of the project.


VariableTypeOptionalDefaultDescription
EDGE_KEYstringNoNoneYour agent's unique key from the dashboard.
TZstringYesUTCTimezone for the agent (e.g. UTC, Europe/Paris).
POLLINGnumberYes5Frequency (in seconds) to check for new tasks.
DATA_PATHstringYes/dataInternal path where the agent stores its data.
TMPDIRstringYes/tmpDirectory where the agent builds the temporary backup/restore archive. Point it at a disk with enough free space for your largest volume (see Docker Volume).
RETRY_ATTEMPTSnumberYes3Total attempts (not retries after the first) for a database dump, each storage upload, and the restore download. 3 means one initial try plus two retries. Must be between 3 and 5.
RETRY_BACKOFF_MSnumberYes1000Base delay between retry attempts. Doubles each attempt, with equal jitter and a 30s ceiling per wait, so the default spends at most ~3s sleeping per seam. Must be between 100 and 30000.
SSL_CERT_FILEstringYesNonePath to a CA bundle used for the agent's outgoing TLS connections. Needed when the agent must trust an internal certificate authority (see below).

Internal certificate authority: update-ca-certificates has no effect

The agent is written in Rust and uses rustls, which does not read the system CA directory. Dropping your certificate into /usr/local/share/ca-certificates/ and running update-ca-certificates satisfies tools such as curl, but the agent keeps failing with InvalidCertificate(UnknownIssuer).

Mount a CA bundle and point SSL_CERT_FILE at it instead:

docker-compose.yml
volumes:
  - ./ca-bundle.crt:/etc/ssl/certs/portabase-ca-bundle.crt:ro
environment:
  - SSL_CERT_FILE=/etc/ssl/certs/portabase-ca-bundle.crt

SSL_CERT_FILE replaces the default root store, it does not add to it. The bundle must therefore contain the standard Mozilla root certificates concatenated with your internal CA — otherwise the agent stops trusting public hosts, such as your S3 storage.

Last updated on