Orlok

Environment variables

Every setting of the Docker package, which ones you must fill in and which ones compose sets for you.

Orlok reads its settings from .env.production, which compose.yaml passes to the containers. Start from the example in the package:

cp .env.production.example .env.production
docker compose --env-file .env.production up -d --build

Never commit the filled-in file: it holds the keys that protect your data.

Required

Variable What it is
ORLOK_PUBLIC_URL The address people use to open Orlok, e.g. https://orlok.example.com or http://192.168.1.20:8080. It is used in the links sent by email and to check where uploads come from. Behind a reverse proxy, this is the proxy's address.
ORLOK_SECRET_KEY A 32-byte key, base64-encoded, that encrypts the model providers' API keys and the people's credentials at rest. Generate it with openssl rand -base64 32.
POSTGRES_PASSWORD The password of the database user. It ends up inside a connection URL, so use URL-safe characters: openssl rand -hex 24.
ORLOK_RUNNER_TOKEN The token the app and the runner share. Random, at least 32 characters: openssl rand -hex 32.

If one of them is missing, docker compose stops before starting anything and names it.

Keep the secret key outside the database, and back it up. It is never stored in Orlok. Without it, saved provider keys and credentials cannot be decrypted, and a database backup alone cannot bring them back. See Backup.

Cookies follow the address. Sign-in cookies are marked secure only when ORLOK_PUBLIC_URL starts with https://. Over plain http on a local address they still work, but anyone on the network path can read them: use http only on a network you trust. See HTTPS.

Optional

Variable Default What it is
ORLOK_PORT 8080 The host port the app publishes. Inside the container the app listens on 3000.
POSTGRES_USER orlok The database user, created on the first start.
POSTGRES_DB orlok The database, created on the first start.
ORLOK_EMBEDDINGS_THREADS half the cores, at most 8 Threads of the built-in embedding model that indexes the wiki for search.
ORLOK_APP_IMAGE orlok:latest The name of the app image to build or pull. It is also shown at the bottom of the menu, so you can tell at a glance which version is running.
ORLOK_RUNNER_IMAGE orlok-runner:latest The name of the runner image to build or pull.

POSTGRES_USER and POSTGRES_DB take effect only on an empty database volume: changing them later does not rename an existing user or database.

Set by compose

compose.yaml sets these for the containers. You do not need to put them in .env.production.

Variable Container Value
DATABASE_URL app Built from the Postgres user, password and database.
ORLOK_RUNNER_URL app http://runner:3100, on the internal network shared with the runner only.
ORLOK_IMAGE app The value of ORLOK_APP_IMAGE: a container cannot read its own image tag.
ORLOK_RUNNER_SANDBOX_UID_BASE runner 20000: each job runs as its own user, starting from this id.

Leave the sandbox on. Without ORLOK_RUNNER_SANDBOX_UID_BASE the runner still works, but every job runs as the runner's own user and the runner logs a warning. The package sets it for you.

Runner limits

The runner applies resource limits to each command it starts and to each local MCP server. compose.yaml does not pass these variables, so the defaults apply. To change them, add them to the runner's environment in a compose.override.yaml next to compose.yaml, which Docker Compose reads automatically:

services:
  runner:
    environment:
      ORLOK_RUNNER_MAX_JOBS: "4"
Variable Default What it limits
ORLOK_RUNNER_MAX_JOBS 8 Commands running at the same time; the others wait their turn.
ORLOK_RUNNER_MAX_MCP_SESSIONS 16 Local MCP servers (those started as a command) running at the same time. Remote MCP servers do not count.
ORLOK_RUNNER_LIMIT_MEMORY_MB 4096 Memory of each process.
ORLOK_RUNNER_LIMIT_CPU_SECONDS 900 CPU time of each command. MCP servers have no CPU limit, since they stay up.
ORLOK_RUNNER_LIMIT_FILE_MB 1024 Size of each file a process writes.
ORLOK_RUNNER_LIMIT_OPEN_FILES 1024 Open files of each process.
ORLOK_RUNNER_LIMIT_PROCESSES 256 Processes of each job's user. It applies only with the sandbox on.

Set a limit to 0 to turn it off.