Docs

Control Plane — Configuration Reference

Environment variables that configure the control-plane (27 settings).

Configuration

FABURAI_CP_PORT
description
Server
default
8080
type
int
required
no
field
Port
FABURAI_CP_HOST
default
0.0.0.0
type
string
required
no
field
Host
FABURAI_CP_ENV_NAME
default
development
type
string
required
no
field
EnvName
FABURAI_CP_DATABASE_URL
description
Database
type
string
required
yes
field
DatabaseURL
FABURAI_CP_JWT_SECRET
description
Auth
default
dev-secret-change-me
type
string
required
no
holds credential
yes
field
JWTSecret
FABURAI_CP_JWT_ISSUER
default
faburai-cp
type
string
required
no
field
JWTIssuer
FABURAI_CP_JWT_EXPIRY_MIN
default
5
type
int
required
no
field
JWTExpiryMin
FABURAI_CP_STATIC_DIR
description
Frontend
default
app/ui/dist
type
string
required
no
field
StaticDir
FABURAI_CP_DOCS_CORPUS_DIR
description
DocsCorpusDir is the Canonical Documentation Corpus baked into the image at build time. Empty or missing means embedded documentation is simply not mounted — the plane boots fine without it, which keeps the corpus a build artifact rather than a runtime dependency.
default
docs-corpus
type
string
required
no
field
DocsCorpusDir
FABURAI_CP_LOG_LEVEL
description
Logging
default
info
type
string
required
no
field
LogLevel
FABURAI_CP_LOG_FORMAT
default
json
type
string
required
no
field
LogFormat
FABURAI_CP_EXTERNAL_ENDPOINT
description
External address — how DPs reach this CP (for heartbeats/registration) For local dev with kind: http://172.18.0.1:8082 (host gateway IP + CP port)
type
string
required
no
field
ExternalEndpoint
FABURAI_CP_OIDC_ISSUER_DOMAIN
description
Auth0 / OIDC Domain like dev-m1ccjy5auy7h7h8e.us.auth0.com (no scheme, no trailing slash)
type
string
required
no
field
OIDCIssuerDomain
FABURAI_CP_OIDC_CLIENT_ID
type
string
required
no
field
OIDCClientID
FABURAI_CP_OIDC_CLIENT_SECRET
type
string
required
no
holds credential
yes
field
OIDCClientSecret
FABURAI_CP_OIDC_AUDIENCE
default
https://api.faburai.com
type
string
required
no
field
OIDCAudience
FABURAI_CP_OIDC_SUPERADMIN_ORG_ID
description
OIDCSuperAdminOrgID gates Super Admin via IdP org membership. (D-9.8) Kept alongside role-based check as belt-and-braces — either one grants Super Admin. Legacy env name OIDC_STAFF_ORG_ID still read for backwards compat.
type
string
required
no
field
OIDCSuperAdminOrgID
FABURAI_CP_OIDC_STAFF_ORG_ID
description
deprecated alias, drop after all envs migrated
type
string
required
no
field
OIDCStaffOrgID
FABURAI_CP_OIDC_ROLES_CLAIM
description
OIDCRolesClaim is the JWT claim path that carries FaburAI role strings. Same convention as DP: Auth0 Actions and Cognito Pre-Token Generation Lambdas both stamp it. Empty = don't try to read roles (org check alone gates Super Admin).
default
https://faburai.com/roles
type
string
required
no
field
OIDCRolesClaim
FABURAI_CP_OIDC_DEFAULT_ORG_ID
description
pre-selected if no ?org= in URL
type
string
required
no
field
OIDCDefaultOrgID
FABURAI_CP_OIDC_REQUIRE_AUTH
description
Defaults true: any deploy with OIDC configured locks down /api/* by default. Set FABURAI_CP_OIDC_REQUIRE_AUTH=false explicitly for local dev without Auth0.
default
true
type
bool
required
no
field
OIDCRequireAuth
FABURAI_CP_SESSION_KEY
description
Cookie signing key — 32+ random bytes, base64
default
dev-session-key-change-me-32bytes
type
string
required
no
holds credential
yes
field
SessionKey
FABURAI_CP_SECRETS_KEY
description
Per-tenant credential encryption — AES-GCM. 32 bytes, base64 encoded. REQUIRED when any tenant has IdP credentials configured. Without this, the secrets module fails fast at startup so we never silently store plaintext. Generate via: openssl rand -base64 32
type
string
required
no
holds credential
yes
field
SecretsKey
FABURAI_CP_CLERK_JWKS_URL
description
Clerk — used by the trial-signup endpoint (POST /trials/signup) which authenticates a public web visitor without Auth0. If unset, the signup route is not mounted and the trial SPA falls back to staff-mediated provisioning.
type
string
required
no
field
ClerkJWKSURL
FABURAI_CP_CLERK_ISSUER
type
string
required
no
field
ClerkIssuer
FABURAI_CP_CLERK_SECRET_KEY
type
string
required
no
holds credential
yes
field
ClerkSecretKey
FABURAI_CP_TRIAL_DP_BASE_URL
description
TrialDPBaseURL is the base of the shared trial DP (e.g. https://trial-stage-dp.faburai.com). The signup handler appends /t/<slug> and returns it as Trial.TenantDPUrl. Empty disables the computed URL — the SPA stays on the provisioning screen.
type
string
required
no
field
TrialDPBaseURL