TREK Docker Deployment Environment Variables: Complete Configuration Guide
TREK accepts over 40 environment variables via Docker to control server behavior, authentication, email delivery, and feature toggles, with defaults defined in charts/trek/values.yaml and full documentation maintained in the wiki/Environment-Variables.md file.
When deploying the mauriceboe/TREK travel management application in a containerized environment, you configure the application through environment variables passed via your docker run command, docker-compose.yml file, or Helm values. These variables govern everything from the HTTP port and encryption keys to SSO integration and MCP rate limits.
Core Server Configuration
TREK requires several fundamental variables to define how the Node.js server operates inside the container.
PORT: The HTTP port the container listens on. Defaults to3000in Docker environments.HOST: The bind address. Only relevant for non-container installs (like Proxmox); containers default to all interfaces.NODE_ENV: Set toproductionordevelopment. Defaults toproductionin container images.ENCRYPTION_KEY: At-rest encryption key for sensitive data. Auto-generated if omitted, but explicit assignment prevents key rotation issues.TZ: Server timezone. Defaults toUTC.LOG_LEVEL: Verbosity control, eitherinfoordebug. Defaults toinfo.DEFAULT_LANGUAGE: Default UI language code (e.g.,en,de). Defaults toen.APP_URL: Public base URL (e.g.,https://trek.example.com). Required for generating correct OIDC redirects and email links.
According to the source code in server/src/config.ts, the runtime resolution logic handles ENCRYPTION_KEY generation and validation when values are not explicitly provided.
Session and Security Settings
Control JWT lifetimes and cross-origin behavior with these variables.
SESSION_DURATION: JWT lifetime when "Remember me" is unchecked. Defaults to24h.SESSION_DURATION_REMEMBER: JWT lifetime when "Remember me" is checked. Defaults to30d.ALLOWED_ORIGINS: CORS whitelist as comma-separated values. Defaults to same-origin.ALLOW_INTERNAL_NETWORK: Permit outbound calls to private IP ranges (e.g., for Immich integration). Defaults tofalse.
HTTPS and Reverse Proxy Configuration
When running TREK behind a reverse proxy like Nginx or Traefik, these variables ensure proper TLS handling and prevent redirect loops.
FORCE_HTTPS: Enforces HTTPS, sets HSTS headers, and adds CSPupgrade-insecure-requests. Defaults tofalse.TRUST_PROXY: Number of trusted proxy hops; required forX-Forwarded-Protoparsing. Defaults to1in production.COOKIE_SECURE: Secure flag for thetrek_sessioncookie. Auto-derived fromFORCE_HTTPSif not set.HSTS_INCLUDE_SUBDOMAINS: Include sub-domains in the HSTS header. Defaults tofalse.
As documented in wiki/Reverse-Proxy.md, setting FORCE_HTTPS=true without a proper TRUST_PROXY value creates a redirect loop.
OpenID Connect (OIDC) and SSO
Enable single sign-on by configuring your identity provider.
OIDC_ISSUER: Provider URL (e.g.,https://auth.example.com).OIDC_CLIENT_IDandOIDC_CLIENT_SECRET: Credentials from your IdP.OIDC_DISPLAY_NAME: Button label on the login screen. Defaults toSSO.OIDC_ONLY: Disable local login and registration when set totrue. Defaults tofalse.OIDC_ADMIN_CLAIM/OIDC_ADMIN_VALUE: Claim name and value that automatically grant admin privileges.OIDC_SCOPE: Space-separated scopes. Must includeopenid email profile. Defaults toopenid email profile.OIDC_DISCOVERY_URL: Override the discovery endpoint if your provider uses a non-standard path.
WebAuthn and Passkeys
Configure hardware key and passkey authentication.
WEBAUTHN_RP_ID: Relying-Party domain for passkeys. Derived fromAPP_URLif unset.WEBAUTHN_ORIGINS: Allowed origins for WebAuthn ceremonies. Derived fromAPP_URLif unset.
Email and SMTP Configuration
Required for password resets and notifications.
SMTP_HOST: SMTP server hostname.SMTP_PORT: Port number. Port 465 implies implicit TLS.SMTP_USER/SMTP_PASS: Authentication credentials.SMTP_FROM: Sender address (e.g.,TREK <noreply@example.com>).SMTP_SKIP_TLS_VERIFY: Disable TLS verification for self-signed certificates. Defaults tofalse.
Initial Admin Setup
These variables only apply on first boot when the database initializes.
ADMIN_EMAIL: Email for the first admin account. Defaults toadmin@trek.local.ADMIN_PASSWORD: Password for the first admin account. Defaults to a random generated value.
Advanced Features and Tuning
Configure specific TREK modules and performance characteristics.
Multi-Channel API (MCP)
MCP_RATE_LIMIT: Maximum API requests per user per minute. Defaults to300.MCP_MAX_SESSION_PER_USER: Maximum concurrent MCP sessions per user. Defaults to20.
Booking Import
KITINERARY_EXTRACTOR_PATH: Path to thekitinerary-extractorbinary for KDE Itinerary parsing. Auto-detected if not specified.
Storage Paths
TREK_PLACE_PHOTO_DIR: Directory for cached Google Place photos. Defaults touploads/photos/google.BACKUP_UPLOAD_LIMIT_MB: Maximum size for uploaded restore archives. Defaults to500.
Performance Tuning
IDEMPOTENCY_TTL_SECONDS: TTL for stored idempotency keys. Defaults to2592000(30 days).OVERPASS_URL: Custom Overpass API endpoint(s) as comma-separated values. Defaults to bundled public mirrors.OVERPASS_TIMEOUT_MS: Per-endpoint timeout for Overpass requests. Defaults to12000.
Demo Mode
Enable a sandbox environment for testing.
DEMO_MODE: Enable demo sandbox with auto-reset and limited mutations. Defaults tofalse.DEMO_ADMIN_USER/DEMO_ADMIN_EMAIL/DEMO_ADMIN_PASS: Credentials for the seeded demo admin. Defaults toadmin/admin@trek.app/admin12345.
Deployment Examples
Reference implementations for common container orchestration platforms are maintained in wiki/Install-Docker-Compose.md and charts/trek/values.yaml.
Docker Run
docker run -d \
-p 3000:3000 \
-e NODE_ENV=production \
-e PORT=3000 \
-e APP_URL=https://trek.example.com \
-e FORCE_HTTPS=true \
-e TRUST_PROXY=1 \
-e SESSION_DURATION=24h \
-e SESSION_DURATION_REMEMBER=30d \
-e SMTP_HOST=smtp.example.com \
-e SMTP_PORT=587 \
-e SMTP_USER=mailer \
-e SMTP_PASS=secret \
-e SMTP_FROM="TREK <noreply@example.com>" \
mauriceboe/trek:latest
Docker Compose
version: "3.8"
services:
trek:
image: mauriceboe/trek:latest
ports:
- "3000:3000"
environment:
NODE_ENV: production
PORT: "3000"
APP_URL: https://trek.example.com
FORCE_HTTPS: "true"
TRUST_PROXY: "1"
SESSION_DURATION: 24h
SESSION_DURATION_REMEMBER: 30d
SMTP_HOST: smtp.example.com
SMTP_PORT: "587"
SMTP_USER: mailer
SMTP_PASS: secret
SMTP_FROM: "TREK <noreply@example.com>"
restart: unless-stopped
Helm Values
env:
NODE_ENV: production
PORT: "3000"
APP_URL: https://trek.example.com
FORCE_HTTPS: "true"
TRUST_PROXY: "1"
SESSION_DURATION: 24h
SESSION_DURATION_REMEMBER: 30d
SMTP_HOST: smtp.example.com
SMTP_PORT: "587"
SMTP_USER: mailer
SMTP_PASS: secret
SMTP_FROM: "TREK <noreply@example.com>"
Summary
- TREK Docker deployment relies on environment variables defined in
wiki/Environment-Variables.mdand defaulted incharts/trek/values.yaml. - Core variables include
PORT,APP_URL,ENCRYPTION_KEY, andNODE_ENVfor basic server operation. - Security configuration requires careful tuning of
FORCE_HTTPS,TRUST_PROXY, andCOOKIE_SECUREwhen running behind reverse proxies. - Authentication supports OIDC (
OIDC_*variables) and WebAuthn (WEBAUTHN_*variables) for enterprise SSO and passkey login. - Feature toggles like
DEMO_MODE,MCP_RATE_LIMIT, andALLOW_INTERNAL_NETWORKcontrol specific application behaviors without code changes.
Frequently Asked Questions
What is the default port for TREK Docker containers?
TREK listens on port 3000 by default when running inside Docker. You can override this by setting the PORT environment variable, but ensure your container port mapping (-p flag or ports: section) matches this value.
How do I prevent redirect loops when forcing HTTPS?
Set both FORCE_HTTPS=true and TRUST_PROXY=1 (or higher, depending on your proxy chain length). The TRUST_PROXY variable tells TREK how many reverse proxy hops to trust when reading X-Forwarded-Proto headers. Without this configuration, the application enters a redirect loop as documented in wiki/Reverse-Proxy.md.
Where are encryption keys handled in TREK?
The ENCRYPTION_KEY variable defines at-rest encryption for sensitive data. If omitted, server/src/config.ts auto-generates a key on first boot. However, explicitly setting this value is recommended for production deployments to prevent key rotation issues during container restarts.
Can I disable local login and use only SSO?
Yes. Set OIDC_ONLY=true to disable local username/password authentication and registration forms. Ensure you have valid OIDC_ISSUER, OIDC_CLIENT_ID, and OIDC_CLIENT_SECRET values configured, or you will lock yourself out of the application.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →