Platform
Learn
Developer docs User guide Quickstart Blog
Company
Services About Contact Links Get started

Configuration

Updated

Raytha is configured with environment variables. This page lists every variable the 2.0 code reads, with its default, and ends with the settings that live in the database instead.

How configuration is read

The app builds its configuration from the standard ASP.NET Core sources. Later sources win:

  1. appsettings.json (and appsettings.Development.json in Development), shipped with the app.
  2. Process environment variables.
  3. Command-line arguments.

Before any of that, Raytha loads a .env file into the process environment. It looks in the working directory and then in each parent directory. Values in .env replace variables that are already set in the real environment (checked: a .env with PATHBASE beat an exported PATHBASE). With Docker Compose, --env-file .env feeds the variables into the container as usual. Nested keys use a double underscore, which is why the connection string is ConnectionStrings__DefaultConnection.

Values are read when the process starts. Restart the app after you change one.

The tables show the default the code uses when a variable is not set. Where appsettings.json ships a different value, the table says so.

Database

VariableDefaultWhat it does
ConnectionStrings__DefaultConnectionHost=localhost;Port=5432;Username=postgres;Password=changeme;Database=raythaNpgsql connection string. PostgreSQL 17 is the supported database; SQL Server is no longer supported. The repository's Compose file defaults to Host=db;....
APPLY_PENDING_MIGRATIONStrue in appsettings.json, false if the key is missing entirelyWhen true, start-up applies pending EF Core migrations and then makes sure the default theme's content exists. Set it to false if you run migrations from the SQL scripts in db/.
DATABASE_MAX_SIZE1000000000 (bytes)The size shown as the limit on the dashboard and maintenance page. It is display-only: Raytha does not stop writes when the database passes it.

Server and runtime

VariableDefaultWhat it does
ASPNETCORE_ENVIRONMENTProductionDevelopment turns off HTTPS enforcement and lets the sign-in cookie travel over HTTP. Any other value keeps the cookie Secure, redirects HTTP to HTTPS and sends HSTS (unless ENFORCE_HTTPS=false).
ASPNETCORE_URLShttp://0.0.0.0:5200, only when no URL or port setting exists at allWhere Kestrel listens. The Docker image listens on 8080 through the .NET base image's ASPNETCORE_HTTP_PORTS setting.
PATHBASEemptyServe the app under a prefix such as /mywebsite. Public-page URLs get the prefix. In 2.0.0 the admin bundle still references /raytha/... assets without it, so test the admin before relying on this.
ENFORCE_HTTPStrueOutside Development, redirect HTTP to HTTPS and send HSTS. Set false when a proxy already enforces HTTPS and you want Raytha to stay out of it. Does nothing in Development.
REDIRECT_WEBSITEemptyA valid absolute URL makes public site requests redirect there. Use it as a maintenance switch.
NUM_BACKGROUND_WORKERS4How many workers pull jobs off the background task queue (CSV imports and other queued jobs). Raytha also runs one scheduler for recurring jobs.

Proxy trust

These control which callers may set X-Forwarded-For and X-Forwarded-Proto. Raytha never honours X-Forwarded-Host. Details and examples are in Running behind a proxy.

VariableDefaultWhat it does
TRUSTED_PROXIESall (also when unset or empty)all, none, private, or a comma-separated list of IP addresses and CIDR ranges. all and none must be the only value; private can be mixed with addresses and ranges. private covers loopback, link-local, RFC 1918, 100.64.0.0/10 and fc00::/7. An invalid entry stops start-up.
TRUSTED_PROXY_HOPS1With all (or unset), how many proxies sit in front of the app. Setting it together with a list or none stops start-up.

Security and limits

VariableDefaultWhat it does
ALLOW_INTERNAL_URL_IMPORTSfalseBy default, theme and CSV imports, webhook deliveries and HTTP calls made from Raytha Functions refuse to connect to localhost, private networks and cloud metadata addresses. Set true to allow them, for example to deliver a webhook to a service on your own network.
AUTH_RATE_LIMIT_PER_MINUTE30Requests per client IP per minute to the sign-in, magic link, forgot-password and setup endpoints. Over the limit, Raytha answers 429 with Retry-After. The client IP depends on correct proxy trust.
IMPERSONATION_MAX_MINUTES60Maximum length of an "impersonate this user" session. Values are clamped to 1–1440.

SMTP

See Sending emails for setup and testing.

VariableDefaultWhat it does
SMTP_HOSTempty (127.0.0.1 in appsettings.json)SMTP server. If it is empty, Raytha reports the system SMTP as missing and uses the SMTP override saved in the admin (Settings, Configuration).
SMTP_PORT25 in appsettings.jsonSMTP port. TLS is switched on only for ports 587 and 465.
SMTP_USERNAME, SMTP_PASSWORDemptyCredentials, if the server needs them.
SMTP_FROM_ADDRESS, SMTP_FROM_NAMEemptySender. When set, they win over the defaults saved in the admin.

File storage

See File storage for provider setup.

VariableDefaultWhat it does
FILE_STORAGE_PROVIDERLocalLocal, AzureBlob or S3 (case-insensitive). Anything else stops start-up.
FILE_STORAGE_MAX_FILE_SIZE20000000 (bytes)Largest upload the admin uploader, the Local provider and CSV import accept. Cloud direct uploads go straight to the bucket and are not size-checked by Raytha.
FILE_STORAGE_MAX_TOTAL_DISK_SPACE1000000000 (bytes)Display-only storage limit shown on the dashboard.
FILE_STORAGE_ALLOWED_MIMETYPEStext/*,image/*,video/*,audio/*,application/pdfComma-separated allow-list. Enforced on the server for every upload path.
FILE_STORAGE_USE_DIRECT_UPLOAD_TO_CLOUDtrueBrowsers upload straight to Azure or S3 using a signed URL. Always off for Local.
FILE_STORAGE_LOCAL_DIRECTORYuser-uploadsDirectory for the Local provider, relative to the app's working directory (/app in Docker). Files are served from /_static-files.
FILE_STORAGE_AZUREBLOB_CONNECTION_STRINGemptyRequired for Azure Blob.
FILE_STORAGE_AZUREBLOB_CONTAINERemptyRequired for Azure Blob.
FILE_STORAGE_AZUREBLOB_CUSTOM_DOMAINemptyReplaces the storage host in generated URLs, for a CDN or custom domain.
FILE_STORAGE_S3_ACCESS_KEY, FILE_STORAGE_S3_SECRET_KEYemptyRequired for S3.
FILE_STORAGE_S3_BUCKETemptyRequired for S3.
FILE_STORAGE_S3_SERVICE_URLemptyRequired for S3, including AWS (for example https://s3.us-east-1.amazonaws.com). A non-HTTPS URL only works with direct upload on.
FILE_STORAGE_S3_REGIONus-east-1Signing region.

Raytha Functions

VariableDefaultWhat it does
RAYTHA_FUNCTIONS_MAX_ACTIVE5How many functions may run at the same time. 0 disables Functions.
RAYTHA_FUNCTIONS_TIMEOUT10000 (ms)How long one execution may run.
RAYTHA_FUNCTIONS_QUEUE_TIMEOUT10000 (ms)How long a call waits for a free slot before it gives up.

Observability

Everything here is off until you set it. When any sink is configured, Serilog replaces the default console logger.

VariableDefaultWhat it does
SENTRY_DSNemptyEnables Sentry error reporting.
SENTRY_TRACES_SAMPLE_RATE0Fraction of requests traced by Sentry, 0 to 1.
OTEL_EXPORTER_OTLP_ENDPOINTemptyTurns on OpenTelemetry traces and metrics, plus an OTLP log sink.
OTEL_EXPORTER_OTLP_PROTOCOLemptygrpc, or anything else for HTTP/protobuf.
OTEL_SERVICE_NAMEraythaService name on exported telemetry.
OBSERVABILITY_LOGGING_ENABLE_CONSOLEtrueWrite logs to the console.
OBSERVABILITY_LOGGING_ENABLE_LOKIfalseShip logs to Loki (or a compatible endpoint such as VictoriaLogs). Needs LOKI_URL.
LOKI_URL, LOKI_USERNAME, LOKI_PASSWORDemptyLoki endpoint and optional basic-auth credentials.

Admin app development

Only local development uses these. The Docker image sets AdminSpa__AutoStart=false.

VariableWhat it does
AdminSpa__AutoStartStart the Vite dev server together with the app.
AdminSpa__DevServerUrlWhere the Vite dev server listens (http://localhost:5203 in tools/dev.sh). Raytha proxies the admin to it.

Settings stored in the database

These are not environment variables. Change them in the admin under Settings.

  • Configuration: organization name, Website URL, time zone, default sender address and name, and an SMTP override (host, port, username, password).
  • Authentication: sign-in methods, including JWT and SAML schemes.
  • Maintenance, Data retention: how many days to keep the audit log, email log, webhook deliveries and finished background tasks. The default is 180 days for each; 0 or less keeps them forever. A background job purges expired rows daily at 03:00 UTC.

Gotchas

  • The file storage provider is fixed at start-up. Changing FILE_STORAGE_PROVIDER does not move existing files; see File storage.
  • .env.example and appsettings.json say the S3 service URL is not needed for AWS. The code requires it, and the first upload fails with "S3 Environment Variables were not found" without it.
  • DATABASE_MAX_SIZE and FILE_STORAGE_MAX_TOTAL_DISK_SPACE do not limit anything. They only change what the dashboard shows.
  • A password containing ; must be quoted in the connection string, or avoided.
  • A stray .env in the app's working directory or any parent directory silently overrides real environment variables. If a setting seems to be ignored, look for one.
  • Keep .env out of version control; it holds your database password and SMTP credentials.

Next steps