Skip to main content

Environment Variables

Agent Environment Variables​

VariableRequiredDefaultDescription
JOKOWIPE_AGENT_TOKENYes*—Agent authentication token
JOKOWIPE_AGENT_NAMENohostnameAgent display name
JOKOWIPE_SERVER_URLNohttps://api.jokowipe.idControl plane URL
JOKOWIPE_LOG_LEVELNoinfodebug, info, warn, error
JOKOWIPE_LOG_FORMATNojsonjson or text
JOKOWIPE_DATABASE_URLNo—Default database URL
JOKOWIPE_STORAGE_TYPENo—Storage provider type
JOKOWIPE_TEMP_DIRNo/var/tmp/jokowipeTemp directory for backups
JOKOWIPE_MAX_CONCURRENT_JOBSNo1Max parallel backup jobs

*Required if not set in config file.

AWS / S3 Variables​

VariableDescription
AWS_ACCESS_KEY_IDAWS access key ID
AWS_SECRET_ACCESS_KEYAWS secret access key
AWS_SESSION_TOKENAWS session token (for temporary credentials)
AWS_DEFAULT_REGIONDefault AWS region
AWS_PROFILEAWS CLI profile to use

These standard AWS variables are automatically used if access_key_id and secret_access_key are not set in the config file.

Google Cloud Variables​

VariableDescription
GOOGLE_APPLICATION_CREDENTIALSPath to service account JSON file

Azure Variables​

VariableDescription
AZURE_STORAGE_ACCOUNTAzure storage account name
AZURE_STORAGE_KEYAzure storage account key
AZURE_STORAGE_SAS_TOKENAzure SAS token

Self-Hosted Server Variables​

VariableRequiredDefaultDescription
JOKOWIPE_LICENSE_KEYYes—Self-hosted license key
JOKOWIPE_DOMAINYes—Public domain for the server
JOKOWIPE_SECRET_KEYYes—JWT signing key (32+ chars)
DATABASE_URLYes—PostgreSQL DSN
REDIS_URLYes—Redis DSN
CLICKHOUSE_URLNo—ClickHouse DSN (for analytics)
ANTHROPIC_API_KEYNo—Anthropic Claude API key
PORTNo8080API server port
SMTP_HOSTNo—SMTP server hostname
SMTP_PORTNo587SMTP port
SMTP_USERNo—SMTP username
SMTP_PASSNo—SMTP password
SMTP_FROMNo—Sender email address
VAULT_ENCRYPTION_KEYNoAuto-generated64-char hex key for secrets

Self-Hosted OAuth Variables​

VariableDescription
GITHUB_CLIENT_IDGitHub OAuth App client ID
GITHUB_CLIENT_SECRETGitHub OAuth App client secret
GOOGLE_CLIENT_IDGoogle OAuth client ID
GOOGLE_CLIENT_SECRETGoogle OAuth client secret

Feature Flags (Self-Hosted)​

VariableDefaultDescription
FEATURE_AI_ANOMALYtrueEnable AI anomaly detection
FEATURE_OAUTHtrueEnable OAuth login
FEATURE_SSOtrueEnable SAML/OIDC SSO
FEATURE_SCIMtrueEnable SCIM provisioning
FEATURE_AUDIT_LOGtrueEnable audit logging
FEATURE_WEBHOOKStrueEnable webhooks
FEATURE_BILLINGfalseEnable billing (disabled in self-hosted)

Using Environment Variables in Config File​

In agent.yaml, reference environment variables with ${VAR_NAME} syntax:

agent:
token: "${JOKOWIPE_AGENT_TOKEN}"
storage:
s3:
access_key_id: "${AWS_ACCESS_KEY_ID}"
secret_access_key: "${AWS_SECRET_ACCESS_KEY}"

Setting Variables in systemd​

Add environment variables to the systemd service:

# /etc/systemd/system/jokowipe-agent.service.d/override.conf
[Service]
EnvironmentFile=/etc/jokowipe/agent.env
# /etc/jokowipe/agent.env (chmod 600)
JOKOWIPE_AGENT_TOKEN=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...
AWS_ACCESS_KEY_ID=AKIAIOSFODNN7EXAMPLE
AWS_SECRET_ACCESS_KEY=wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY
sudo systemctl daemon-reload
sudo systemctl restart jokowipe-agent