Data Plane — Configuration Reference
Environment variables that configure the data-plane (57 settings).
Configuration
FABURAI_DP_PORT
- description
- Server
- default
- 8080
- type
- int
- required
- no
- field
- Port
FABURAI_DP_HOST
- default
- 0.0.0.0
- type
- string
- required
- no
- field
- Host
FABURAI_DP_ENV_NAME
- default
- development
- type
- string
- required
- no
- field
- EnvName
FABURAI_DP_DATABASE_URL
- description
- Database
- type
- string
- required
- yes
- field
- DatabaseURL
FABURAI_DP_JWT_SECRET
- description
- Auth
- default
- dev-secret-change-me
- type
- string
- required
- no
- holds credential
- yes
- field
- JWTSecret
FABURAI_DP_JWT_ISSUER
- default
- faburai-dp
- type
- string
- required
- no
- field
- JWTIssuer
FABURAI_DP_JWT_EXPIRY_MIN
- default
- 5
- type
- int
- required
- no
- field
- JWTExpiryMin
FABURAI_DP_EVENT_BUS_TYPE
- description
- Event Bus
- default
- inmemory
- type
- string
- required
- no
- field
- EventBusType
FABURAI_DP_NATS_URL
- default
- nats://localhost:4222
- type
- string
- required
- no
- field
- NATSUrl
FABURAI_DP_MEMGRAPH_URL
- description
- Memgraph (optional in Phase 0)
- type
- string
- required
- no
- field
- MemgraphURL
FABURAI_DP_STATIC_DIR
- description
- Frontend
- default
- app/ui/dist
- type
- string
- required
- no
- field
- StaticDir
FABURAI_DP_DOCS_CORPUS_DIR
- description
- DocsCorpusDir is the Canonical Documentation Corpus baked into the image at build time. Empty or missing means embedded documentation is simply not mounted — the plane boots fine without it, which keeps the corpus a build artifact rather than a runtime dependency.
- default
- docs-corpus
- type
- string
- required
- no
- field
- DocsCorpusDir
FABURAI_DP_LOG_LEVEL
- description
- Logging
- default
- info
- type
- string
- required
- no
- field
- LogLevel
FABURAI_DP_LOG_FORMAT
- default
- json
- type
- string
- required
- no
- field
- LogFormat
FABURAI_DP_CP_ENDPOINT
- description
- Control Plane connection
- type
- string
- required
- no
- field
- CPEndpoint
FABURAI_DP_TENANT_ID
- type
- string
- required
- no
- field
- TenantID
FABURAI_DP_TENANT_NAME
- description
- friendly name shown in UI header
- type
- string
- required
- no
- field
- TenantName
FABURAI_DP_CLUSTER_ID
- type
- string
- required
- no
- field
- ClusterID
FABURAI_DP_CLUSTER_NAME
- description
- friendly name shown in UI header
- type
- string
- required
- no
- field
- ClusterName
FABURAI_DP_REGISTRATION_TOKEN
- type
- string
- required
- no
- holds credential
- yes
- field
- RegistrationToken
FABURAI_DP_ACCOUNT_KIND
- description
- AccountKind is paid|trial|internal, set by the CP provisioner at deploy time. The DP UI reads this to gate features (slice T-1) and render the "Trial: X days remaining" topbar chip (slice T-2). Defaults to "paid" so existing DPs without this env var keep working exactly as before. See D-4.12 (universal-first reshape).
- default
- paid
- type
- string
- required
- no
- field
- AccountKind
FABURAI_DP_ONBOARDING_STATE
- description
- OnboardingState drives the universal onboarding banner (slice U-1). not_started → mcp_done → graph_seen → completed. CP provisioner sets "not_started" for fresh trial tenants; existing tenants get "completed" at boot. The DP re-fetches via /tenant-info as it advances, so this env var only seeds the first read.
- default
- completed
- type
- string
- required
- no
- field
- OnboardingState
FABURAI_DP_TIER
- description
- Tier is orthogonal to AccountKind — it says whether THIS DP is running as the public "demo" showcase (demo.faburai.com), a trial workspace, or a paid deployment. Read by: - middleware.DemoReadOnly (reads FABURAI_DP_TIER directly today; this field mirrors it so /tenant-info can expose it to the SPA) - the demo-tier email-gate flow (welcome modal + demo session cookie) Values: "demo" | "trial" | "paid" | "" (paid/legacy default).
- type
- string
- required
- no
- field
- Tier
FABURAI_DP_EXTERNAL_ENDPOINT
- description
- External URL — how end users reach this DP (used as OIDC redirect base)
- type
- string
- required
- no
- field
- ExternalEndpoint
FABURAI_DP_AUTH_PROVIDER
- description
- AuthProvider selects the OIDC backend for the browser-session flow. "auth0" → uses OIDCIssuerDomain/ClientID (existing paid-tenant path) "cognito" → uses CognitoIssuer/ClientID/HostedUI (trial-tenant path) "" → same as "auth0" for backward compat with older DPs Only one is active per DP. Paid tenants keep Auth0 until BYOIdP lands; trial-stage flips to Cognito via [[project_cognito_migration]].
- type
- string
- required
- no
- field
- AuthProvider
FABURAI_DP_COGNITO_ISSUER
- description
- Cognito (OIDC) — trial tenants only. Coordinates come from [[reference_cognito_trials]]. The DP redirects users to the Hosted UI domain for login, then handles the OAuth code callback like any OIDC flow. Slug lives in `custom:tenant_slug` ID-token claim.
- type
- string
- required
- no
- field
- CognitoIssuer
FABURAI_DP_COGNITO_CLIENT_ID
- type
- string
- required
- no
- field
- CognitoClientID
FABURAI_DP_COGNITO_CLIENT_SECRET
- type
- string
- required
- no
- holds credential
- yes
- field
- CognitoClientSecret
FABURAI_DP_COGNITO_HOSTED_UI
- description
- https://<domain>.auth.<region>.amazoncognito.com
- type
- string
- required
- no
- field
- CognitoHostedUI
FABURAI_DP_TRIAL_ONBOARDING_PATH
- description
- Trial-mode routing paths (used by the shared trial-stage landing DP). Defaults match what nginx + the SPA expect; only override in tests or if the route structure changes.
- default
- /onboarding
- type
- string
- required
- no
- field
- TrialOnboardingPath
FABURAI_DP_TRIAL_TENANT_PATH_PREFIX
- description
- per-trial URL prefix (nginx routes /t/<slug>/)
- default
- /t/
- type
- string
- required
- no
- field
- TrialTenantPathPrefix
FABURAI_DP_CP_ADMIN_BASE_URL
- description
- CP admin API — where the landing DP calls to provision a trial namespace on first login (CG-4). Empty disables JIT provisioning and the /onboarding page reports the trial is offline.
- type
- string
- required
- no
- field
- CPAdminBaseURL
FABURAI_DP_CP_ADMIN_SHARED_TOKEN
- description
- pre-shared secret CP validates (staff-auth for now)
- type
- string
- required
- no
- holds credential
- yes
- field
- CPAdminSharedToken
FABURAI_DP_OIDC_ISSUER_DOMAIN
- description
- OIDC (Auth0)
- type
- string
- required
- no
- field
- OIDCIssuerDomain
FABURAI_DP_OIDC_CLIENT_ID
- type
- string
- required
- no
- field
- OIDCClientID
FABURAI_DP_OIDC_CLIENT_SECRET
- type
- string
- required
- no
- holds credential
- yes
- field
- OIDCClientSecret
FABURAI_DP_OIDC_AUDIENCE
- default
- https://api.faburai.com
- type
- string
- required
- no
- field
- OIDCAudience
FABURAI_DP_OIDC_TENANT_ORG_ID
- description
- Auth0 Organization for this tenant
- type
- string
- required
- no
- field
- OIDCTenantOrgID
FABURAI_DP_OIDC_REQUIRE_AUTH
- description
- Defaults true: any deploy with OIDC configured locks down /api/* by default. Set FABURAI_DP_OIDC_REQUIRE_AUTH=false explicitly for local dev without Auth0.
- default
- true
- type
- bool
- required
- no
- field
- OIDCRequireAuth
FABURAI_DP_OIDC_ROLES_CLAIM
- description
- Custom JWT claim where IdP roles live. Auth0 convention is a fully- qualified URL like https://faburai.com/roles. Empty → /userinfo fallback.
- default
- https://faburai.com/roles
- type
- string
- required
- no
- field
- OIDCRolesClaim
FABURAI_DP_SESSION_KEY
- default
- dev-session-key-change-me-32bytes
- type
- string
- required
- no
- holds credential
- yes
- field
- SessionKey
FABURAI_DP_CLERK_JWKS_URL
- description
- Clerk — secondary IdP used by the trial-signup SPA on trial-stage.faburai.com. When ClerkJWKSURL + ClerkIssuer are set, the DP will: 1. Accept Bearer <clerk_jwt> on /api/* (Mode 4 in RequireAPIAuth) 2. Mount /auth/clerk-handoff?token=<jwt> which validates the JWT and sets the same `faburai_dp_session` cookie an Auth0 login would set, so the SPA can hand a freshly-signed-up user to the DP with no second login. Empty disables both — existing Auth0-only deployments keep working unchanged.
- type
- string
- required
- no
- field
- ClerkJWKSURL
FABURAI_DP_CLERK_ISSUER
- description
- e.g. https://renewed-tetra-49.clerk.accounts.dev
- type
- string
- required
- no
- field
- ClerkIssuer
FABURAI_DP_CLERK_SECRET_KEY
- description
- sk_test_... — fallback for email lookup
- type
- string
- required
- no
- holds credential
- yes
- field
- ClerkSecretKey
FABURAI_DP_TRIAL_SIGNUP_URL
- description
- TrialSignupURL is where /auth/login redirects when AccountKind=trial. Defaults to https://trial-stage.faburai.com if unset.
- type
- string
- required
- no
- field
- TrialSignupURL
FABURAI_DP_POLICY_LLM_PROVIDER
- description
- Policy NLP — natural-language policy drafting via an LLM. Provider selects which backend implements the Drafter interface; default is "openai" because GPT-4o-mini is ~6× cheaper than Haiku for this task with no quality difference. Set "anthropic" to use Claude instead. Empty key for the chosen provider disables the endpoint (returns 503).
- default
- openai
- type
- string
- required
- no
- field
- PolicyLLMProvider
FABURAI_DP_OPENAI_API_KEY
- type
- string
- required
- no
- holds credential
- yes
- field
- OpenAIAPIKey
FABURAI_DP_OPENAI_MODEL
- default
- gpt-4o-mini
- type
- string
- required
- no
- field
- OpenAIModel
FABURAI_DP_ANTHROPIC_API_KEY
- type
- string
- required
- no
- holds credential
- yes
- field
- AnthropicAPIKey
FABURAI_DP_ANTHROPIC_MODEL
- default
- claude-haiku-4-5-20251001
- type
- string
- required
- no
- field
- AnthropicModel
FABURAI_DP_SUPPORT_LLM_ENDPOINT
- description
- Support Guide — customer-hosted OpenAI-compatible inference for the embedded assistant (Venkat PRD v0.2). All three fields default empty; when unset the service falls back to (OpenAIAPIKey, OpenAIModel) so the DP already has an LLM without extra env plumbing. Empty on both paths ⇒ heuristic-only mode (still functional, just no LLM answers).
- type
- string
- required
- no
- field
- SupportLLMEndpoint
FABURAI_DP_SUPPORT_LLM_MODEL
- type
- string
- required
- no
- field
- SupportLLMModel
FABURAI_DP_SUPPORT_LLM_TOKEN
- type
- string
- required
- no
- holds credential
- yes
- field
- SupportLLMToken
FABURAI_DP_IDP_PROVIDER
- description
- IdP — identity provider used to sync roles into gcdm_roles. Type tells the DP which driver to use; the credential fields are only used by the driver matching IdpProviderType. CP provisioner injects these per-tenant.
- type
- string
- required
- no
- field
- IdpProviderType
FABURAI_DP_AUTH0_DOMAIN
- type
- string
- required
- no
- field
- Auth0Domain
FABURAI_DP_AUTH0_M2M_CLIENT_ID
- type
- string
- required
- no
- field
- Auth0M2MClientID
FABURAI_DP_AUTH0_M2M_CLIENT_SECRET
- type
- string
- required
- no
- holds credential
- yes
- field
- Auth0M2MClientSecret

Docs