Environment variables
Every setting of the Docker package, which ones you must fill in and which ones compose sets for you.
Orlok reads its settings from .env.production, which compose.yaml passes to the containers. Start from the example in the package:
cp .env.production.example .env.production
docker compose --env-file .env.production up -d --build
Never commit the filled-in file: it holds the keys that protect your data.
Required
| Variable | What it is |
|---|---|
ORLOK_PUBLIC_URL |
The address people use to open Orlok, e.g. https://orlok.example.com or http://192.168.1.20:8080. It is used in the links sent by email and to check where uploads come from. Behind a reverse proxy, this is the proxy's address. |
ORLOK_SECRET_KEY |
A 32-byte key, base64-encoded, that encrypts the model providers' API keys and the people's credentials at rest. Generate it with openssl rand -base64 32. |
POSTGRES_PASSWORD |
The password of the database user. It ends up inside a connection URL, so use URL-safe characters: openssl rand -hex 24. |
ORLOK_RUNNER_TOKEN |
The token the app and the runner share. Random, at least 32 characters: openssl rand -hex 32. |
If one of them is missing, docker compose stops before starting anything and names it.
Keep the secret key outside the database, and back it up. It is never stored in Orlok. Without it, saved provider keys and credentials cannot be decrypted, and a database backup alone cannot bring them back. See Backup.
Cookies follow the address. Sign-in cookies are marked secure only when
ORLOK_PUBLIC_URLstarts withhttps://. Over plainhttpon a local address they still work, but anyone on the network path can read them: usehttponly on a network you trust. See HTTPS.
Optional
| Variable | Default | What it is |
|---|---|---|
ORLOK_PORT |
8080 |
The host port the app publishes. Inside the container the app listens on 3000. |
POSTGRES_USER |
orlok |
The database user, created on the first start. |
POSTGRES_DB |
orlok |
The database, created on the first start. |
ORLOK_EMBEDDINGS_THREADS |
half the cores, at most 8 | Threads of the built-in embedding model that indexes the wiki for search. |
ORLOK_APP_IMAGE |
orlok:latest |
The name of the app image to build or pull. It is also shown at the bottom of the menu, so you can tell at a glance which version is running. |
ORLOK_RUNNER_IMAGE |
orlok-runner:latest |
The name of the runner image to build or pull. |
POSTGRES_USER and POSTGRES_DB take effect only on an empty database volume: changing them later does not rename an existing user or database.
Set by compose
compose.yaml sets these for the containers. You do not need to put them in .env.production.
| Variable | Container | Value |
|---|---|---|
DATABASE_URL |
app | Built from the Postgres user, password and database. |
ORLOK_RUNNER_URL |
app | http://runner:3100, on the internal network shared with the runner only. |
ORLOK_IMAGE |
app | The value of ORLOK_APP_IMAGE: a container cannot read its own image tag. |
ORLOK_RUNNER_SANDBOX_UID_BASE |
runner | 20000: each job runs as its own user, starting from this id. |
Leave the sandbox on. Without
ORLOK_RUNNER_SANDBOX_UID_BASEthe runner still works, but every job runs as the runner's own user and the runner logs a warning. The package sets it for you.
Runner limits
The runner applies resource limits to each command it starts and to each local MCP server. compose.yaml does not pass these variables, so the defaults apply. To change them, add them to the runner's environment in a compose.override.yaml next to compose.yaml, which Docker Compose reads automatically:
services:
runner:
environment:
ORLOK_RUNNER_MAX_JOBS: "4"
| Variable | Default | What it limits |
|---|---|---|
ORLOK_RUNNER_MAX_JOBS |
8 |
Commands running at the same time; the others wait their turn. |
ORLOK_RUNNER_MAX_MCP_SESSIONS |
16 |
Local MCP servers (those started as a command) running at the same time. Remote MCP servers do not count. |
ORLOK_RUNNER_LIMIT_MEMORY_MB |
4096 |
Memory of each process. |
ORLOK_RUNNER_LIMIT_CPU_SECONDS |
900 |
CPU time of each command. MCP servers have no CPU limit, since they stay up. |
ORLOK_RUNNER_LIMIT_FILE_MB |
1024 |
Size of each file a process writes. |
ORLOK_RUNNER_LIMIT_OPEN_FILES |
1024 |
Open files of each process. |
ORLOK_RUNNER_LIMIT_PROCESSES |
256 |
Processes of each job's user. It applies only with the sandbox on. |
Set a limit to 0 to turn it off.