Skip to content

Environment Variables

All configuration options can be set using environment variables with the prefix Cratis__Chronicle__. Use double underscores (__) to represent nested configuration sections.

{
"port": 35000,
"features": {
"api": true,
"workbench": true
},
"storage": {
"type": "MongoDB",
"connectionDetails": "mongodb://localhost:27017"
}
}

The table below covers the variables most deployments need. It is not the complete option surface — every property on Chronicle’s options types has an environment-variable form, built by joining the section names with __. When a setting is missing here, find it on its own configuration page and translate the JSON path the same way (compliance.encryption.migrateFromDefaultStorage becomes Cratis__Chronicle__Compliance__Encryption__MigrateFromDefaultStorage).

VariableDescription
Cratis__Chronicle__PortThe single Chronicle port — gRPC (HTTP/2) and HTTP/1.1
Cratis__Chronicle__HealthCheckEndpointHealth check endpoint path
Cratis__Chronicle__Health__PortDedicated HTTP/1.1 port for the health endpoint
Cratis__Chronicle__Health__TlsWhether the dedicated health port uses TLS (default true)
Cratis__Chronicle__Features__ApiEnable REST API endpoint
Cratis__Chronicle__Features__WorkbenchEnable Workbench UI
Cratis__Chronicle__Features__ChangesetStorageEnable changeset storage
Cratis__Chronicle__Features__OAuthAuthorityEnable internal OAuth authority
Cratis__Chronicle__Storage__TypeStorage provider type
Cratis__Chronicle__Storage__ConnectionDetailsStorage connection string
Cratis__Chronicle__Observers__SubscriberTimeoutSeconds an observer waits for its subscriber to answer (0 = indefinitely)
Cratis__Chronicle__Observers__MaxRetryAttemptsMaximum retry attempts for observers
Cratis__Chronicle__Observers__BackoffDelayInitial observer backoff delay in seconds
Cratis__Chronicle__Observers__ExponentialBackoffDelayFactorExponential backoff multiplier
Cratis__Chronicle__Observers__MaximumBackoffDelayMaximum observer backoff delay in seconds
Cratis__Chronicle__ReadModels__ReplayedVersionsToKeepNumber of replay-generated read model versions to keep
Cratis__Chronicle__Events__QueuesNumber of event queues
Cratis__Chronicle__Authentication__EnabledWhether authentication is enforced (default true) - see Authentication before turning it off
Cratis__Chronicle__Authentication__AuthorityExternal OAuth authority URL
Cratis__Chronicle__Authentication__DefaultAdminUsernameDefault admin username
Cratis__Chronicle__Authentication__AdminUser__UsernameBootstrap admin username (falls back to the default admin username when empty)
Cratis__Chronicle__Authentication__AdminUser__PasswordBootstrap admin password, hashed on first startup
Cratis__Chronicle__Authentication__AdminUser__EmailBootstrap admin email address
Cratis__Chronicle__Authentication__AdminUser__RequirePasswordChangeOnFirstLoginForce a password change on the admin’s first login
Cratis__Chronicle__Jobs__MaxParallelStepsMaximum parallel job steps
Cratis__Chronicle__Clustering__TypeClustering provider — Localhost (default) or MongoDB
Cratis__Chronicle__Clustering__ClusterIdOrleans cluster id, identical on every node
Cratis__Chronicle__Clustering__ServiceIdOrleans service id, identical on every node
Cratis__Chronicle__Clustering__SiloPortOrleans silo port (default 11111)
Cratis__Chronicle__Clustering__GatewayPortOrleans gateway port (default 30000)
Cratis__Chronicle__Clustering__AdvertisedIPIP address this node advertises to the cluster
Cratis__Chronicle__Tls__CertificatePathTLS certificate path (PFX)
Cratis__Chronicle__Tls__CertificatePasswordTLS certificate password
Cratis__Chronicle__EncryptionCertificate__CertificatePathEncryption certificate path (PFX) — OAuth keys, webhook credentials, Data Protection keys
Cratis__Chronicle__EncryptionCertificate__CertificatePasswordEncryption certificate password
Cratis__Chronicle__EncryptionCertificate__Previous__0__CertificatePathPath to a certificate that was active before, kept for decryption only during a rotation. Index upwards for more than one
Cratis__Chronicle__EncryptionCertificate__Previous__0__CertificatePasswordPassword for that certificate
OTEL_EXPORTER_OTLP_ENDPOINTOTLP receiver endpoint for telemetry export
OTEL_EXPORTER_OTLP_PROTOCOLOTLP export protocol (grpc or http/protobuf)
OTEL_EXPORTER_OTLP_HEADERSAdditional headers for the OTLP exporter
OTEL_SERVICE_NAMEService name reported to the telemetry backend
Terminal window
# The single Chronicle port — gRPC (HTTP/2) plus HTTP/1.1 (default: 35000)
Cratis__Chronicle__Port=35000
Terminal window
# Health check endpoint path (default: /health)
Cratis__Chronicle__HealthCheckEndpoint=/health
Terminal window
# Enable or disable API (default: true)
Cratis__Chronicle__Features__Api=true
# Enable or disable Workbench (default: true)
Cratis__Chronicle__Features__Workbench=true
# Enable or disable Changeset Storage (default: false)
Cratis__Chronicle__Features__ChangesetStorage=false
# Enable or disable internal OAuth authority (default: true)
# Automatically disabled when external authority is configured
Cratis__Chronicle__Features__OAuthAuthority=true
Terminal window
# Storage type (e.g., "MongoDB")
Cratis__Chronicle__Storage__Type=MongoDB
# MongoDB connection string
Cratis__Chronicle__Storage__ConnectionDetails=mongodb://localhost:27017
Terminal window
# Seconds an observer waits for its subscriber to answer a batch (0 = indefinitely, default: 30)
Cratis__Chronicle__Observers__SubscriberTimeout=30
# Maximum retry attempts for failed partitions (0 = infinite, default: 10)
Cratis__Chronicle__Observers__MaxRetryAttempts=10
# Initial backoff delay in seconds (default: 1)
Cratis__Chronicle__Observers__BackoffDelay=1
# Exponential backoff factor (default: 2)
Cratis__Chronicle__Observers__ExponentialBackoffDelayFactor=2
# Maximum backoff delay in seconds (default: 600)
Cratis__Chronicle__Observers__MaximumBackoffDelay=600
Terminal window
# Number of appended event queues to use (default: 2)
Cratis__Chronicle__Events__Queues=2
Terminal window
# Number of replay-generated read model versions to keep per read model (default: 1)
Cratis__Chronicle__ReadModels__ReplayedVersionsToKeep=1
Terminal window
# External OAuth authority URL (optional)
# When not set, uses internal OpenIdDict-based authority
Cratis__Chronicle__Authentication__Authority=https://your-oauth-provider.com
# Default admin username (default: "admin")
Cratis__Chronicle__Authentication__DefaultAdminUsername=admin
# Bootstrap the initial admin user on first startup. The password is hashed
# immediately on use and never retained. Supply it from your secret store.
Cratis__Chronicle__Authentication__AdminUser__Username=admin
Cratis__Chronicle__Authentication__AdminUser__Password=your-secure-password
Cratis__Chronicle__Authentication__AdminUser__RequirePasswordChangeOnFirstLogin=true

When AdminUser__Password is left empty, the admin user is created without a password and goes through the initial password setup flow in the Workbench. See Authentication for the full flow.

Terminal window
# Required in production - the internal OAuth authority refuses to start without it
Cratis__Chronicle__EncryptionCertificate__CertificatePath=/certs/encryption-cert.pfx
Cratis__Chronicle__EncryptionCertificate__CertificatePassword=your-certificate-password

See Data Protection Key Encryption for generating and mounting the certificate.

Terminal window
# Clustering provider - must be MongoDB for every multi-node deployment
Cratis__Chronicle__Clustering__Type=MongoDB
# Identical on every node so they join the same cluster
Cratis__Chronicle__Clustering__ClusterId=chronicle
Cratis__Chronicle__Clustering__ServiceId=chronicle

See Clustering for the full set of clustering properties.

Terminal window
# OTLP receiver endpoint (e.g. local Aspire Dashboard or OpenTelemetry Collector)
OTEL_EXPORTER_OTLP_ENDPOINT=http://localhost:4317
# Export protocol: grpc (default) or http/protobuf
OTEL_EXPORTER_OTLP_PROTOCOL=grpc
# Additional headers, e.g. API keys for cloud backends
OTEL_EXPORTER_OTLP_HEADERS=x-api-key=your-api-key
# Override the service name reported to the telemetry backend
OTEL_SERVICE_NAME=Chronicle

See the Open Telemetry configuration page for full details.