Every workspace reads the same .env at the repo root. .env.example has working values for local development, except the secrets.
Set these first
| Variable | What it's for |
|---|
BETTER_AUTH_SECRET | Signs sessions. Any long random string |
GOOGLE_CLIENT_ID, GOOGLE_CLIENT_SECRET | Google sign-in. Leave blank to use email only |
For Google, add http://localhost:3003 as an authorized JavaScript origin and http://localhost:3000/api/auth/callback/google as the redirect URI.
Backend
| Variable | Local value | In production |
|---|
DATABASE_URL | Docker Postgres | Your RDS URL |
BETTER_AUTH_URL | http://localhost:3000 | The backend's public URL |
TRUSTED_ORIGINS | The app and desktop origins | Your app's origins |
PORT | 3000 | Whatever the host expects |
Storage
| Variable | What it's for |
|---|
S3_BUCKET, S3_AVATAR_BUCKET, S3_BLOG_MEDIA_BUCKET, S3_LOG_BUCKET | Bucket names |
AWS_REGION, AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY | Credentials. Local values are RustFS's |
S3_ENDPOINT, S3_PUBLIC_ENDPOINT, S3_FORCE_PATH_STYLE | Point at RustFS locally. Unset in production |
S3_ENDPOINT is how the backend reaches storage inside Docker. S3_PUBLIC_ENDPOINT is how your browser reaches it, and is used to sign upload and download URLs.
Email
| Variable | What it's for |
|---|
EMAIL_FROM | The sender. Needs a verified SES identity in production |
EMAIL_SMTP_HOST, EMAIL_SMTP_PORT | Send through Mailpit locally. Unset in production to use SES |
Chatbot
| Variable | What it's for |
|---|
CHAT_PROVIDER | ollama locally, bedrock in production |
OLLAMA_BASE_URL, OLLAMA_MODEL | The local model |
BEDROCK_MODEL_ID | The Claude model on Bedrock |
Logs
| Variable | What it's for |
|---|
LOG_DIR | Where log files are written |
LOG_ARCHIVE_CRON | When closed log files upload to S3_LOG_BUCKET |
Frontends
| Variable | What it's for |
|---|
VITE_BACKEND_URL | Where the web app sends requests. Its own origin locally, so the Vite proxy handles them |
VITE_DESKTOP_BACKEND_URL | The backend, reached directly by the desktop app |
VITE_BLOG_URL, NEXT_PUBLIC_BLOG_URL | Where the blog lives, for links to it |
The blog and docs have their own .env.example for their public URLs.