TREK Environment Variables: Complete Configuration Guide for Advanced Deployment
TREK exposes extensive configuration options through environment variables defined in server/src/config.ts, covering everything from server ports and encryption keys to OIDC SSO and WebAuthn passkeys, with all variables documented in wiki/Environment-Variables.md.
The TREK travel planning platform (mauriceboe/TREK) centralizes its runtime configuration in a single configuration loader that reads directly from process.env. This architecture allows administrators to customize behavior without modifying source code, whether deploying via Docker Compose, Kubernetes Helm charts, or running from source with a local .env file.
Core Server Configuration
The core category controls fundamental runtime parameters including network binding, encryption, and localization. In server/src/config.ts, the server initializes these values at startup before binding to any port.
Key variables include:
PORT– The HTTP server port (default:3000).HOST– The bind address. Note: Only honored for non-container installations (Proxmox or source). Docker deployments should never set this, as container networking handles binding internally (lines 32-42).NODE_ENV– Runtime mode (developmentorproduction).ENCRYPTION_KEY– Primary symmetric key for session encryption. The server checks the environment first, then falls back to filesdata/.encryption_key→data/.jwt_secret→ auto-generated key. This order guarantees that a manually supplied key is always persisted (lines 52-62).TZ– Server timezone (e.g.,Europe/Berlin).LOG_LEVEL– Logging verbosity (debug,info,warn,error).DEFAULT_LANGUAGE– UI language code (e.g.,de,en).SESSION_DURATIONandSESSION_DURATION_REMEMBER– Session TTL values (e.g.,12h,30d).ALLOWED_ORIGINS– CORS whitelist for the public base URL.INTERNAL_NETWORKS– IP ranges granted internal-network access privileges.
HTTPS and Reverse Proxy Settings
When running behind TLS-terminating reverse proxies like NGINX or Traefik, the HTTPS/Proxy category ensures secure cookie handling and protocol enforcement:
FORCE_HTTPS– Enables HTTP to HTTPS redirection.HSTS_MAX_AGE– HTTP Strict Transport Security header duration.TRUST_PROXY– Number of trusted proxy hops (e.g.,2for typical cloud load balancers).- Cookie security flags – Automatically hardened when
FORCE_HTTPSis enabled.
Authentication and Single Sign-On
TREK supports enterprise authentication through OIDC/SSO and passwordless WebAuthn/Passkeys:
OIDC Configuration
OIDC_ISSUER– OpenID Connect provider discovery URL (e.g.,https://auth.example.com).OIDC_CLIENT_IDandOIDC_CLIENT_SECRET– Service provider credentials.OIDC_ADMIN_CLAIMandOIDC_ADMIN_VALUE– Claims that elevate users to administrator status.OIDC_SCOPES– Requested scopes (default:openid profile email).
WebAuthn Configuration
WEBAUTHN_RP_ID– Relying Party ID for passkey authentication.WEBAUTHN_ORIGINS– Allowed origins for passwordless login, overriding UI-derived defaults.
Email and SMTP Configuration
The Email/SMTP category enables password-reset flows and notifications:
SMTP_HOSTandSMTP_PORT– Mail server endpoint.SMTP_USERandSMTP_PASSWORD– Authentication credentials.SMTP_FROM– Sender address (e.g.,TREK <noreply@example.com>).SMTP_SECUREandSMTP_VERIFY_CERT– TLS/SSL verification controls.
Advanced Tuning and Performance
For high-availability installations, the Advanced/Tuning and MCP (Multi-Channel Platform) categories provide fine-grained control:
IDEMPOTENCY_TTL_SECONDS– Time-to-live for idempotency keys (default suitable for most deployments, but adjustable for long-running offline sync operations).OVERPASS_URL– Custom OpenStreetMap Overpass API endpoint.OVERPASS_TIMEOUT_MS– Query timeout for OSM data fetching (e.g.,20000for 20 seconds on self-hosted Overpass servers).MCP_RATE_LIMIT– API request caps for shared installations.MCP_MAX_CONCURRENT_SESSIONS– Concurrent session limits for the MCP API.
Specialized Features and Paths
Additional variables control specific TREK features:
- Initial Setup –
INITIAL_ADMIN_EMAILandINITIAL_ADMIN_PASSWORDbootstrap the first administrator account only on first boot. - Booking Import –
KITINERARY_EXTRACTOR_PATHpoints to thekitinerary-extractorbinary for KDE Itinerary integration. - Storage –
PHOTO_CACHE_DIRandBACKUP_UPLOAD_MAX_SIZEmanage disk usage for place photos and restore archives. - Demo Mode –
DEMO_MODEand related credentials enable the self-resetting sandbox instance.
Configuration Examples
Docker Compose Deployment
For containerized deployments, pass variables through the environment list or external .env files:
version: "3.8"
services:
trek:
image: ghcr.io/mauriceboe/trek:latest
ports:
- "3000:3000"
environment:
- PORT=3000
- NODE_ENV=production
- ENCRYPTION_KEY=${ENCRYPTION_KEY}
- TZ=Europe/Berlin
- LOG_LEVEL=info
- DEFAULT_LANGUAGE=de
- SESSION_DURATION=12h
- SESSION_DURATION_REMEMBER=30d
- ALLOWED_ORIGINS=https://trek.example.com
- TRUST_PROXY=2
- FORCE_HTTPS=true
- OIDC_ISSUER=https://auth.example.com
- OIDC_CLIENT_ID=trek-app
- OIDC_CLIENT_SECRET=${OIDC_CLIENT_SECRET}
- OVERPASS_URL=https://overpass.example.com/api/interpreter
Kubernetes Helm Values
For Kubernetes deployments, inject variables through the Helm values file:
env:
- name: IDEMPOTENCY_TTL_SECONDS
value: "2592000" # 30 days
- name: OVERPASS_TIMEOUT_MS
value: "20000" # 20 s for self-hosted Overpass
- name: MCP_RATE_LIMIT
value: "500"
- name: DEMO_MODE
value: "false"
Source Deployment with .env
When running from source, TREK automatically loads a local .env file:
cat > .env <<EOF
PORT=3001
HOST=10.0.0.72
ENCRYPTION_KEY=my-secret-key
SMTP_HOST=smtp.example.com
SMTP_PORT=587
SMTP_FROM=TREK <noreply@example.com>
OIDC_ISSUER=https://auth.example.com
OIDC_CLIENT_ID=trek
OIDC_CLIENT_SECRET=super-secret
EOF
npm run start
Summary
- TREK environment variables are defined in
server/src/config.tsand documented inwiki/Environment-Variables.md, covering 11 functional categories from core networking to specialized features. - The
ENCRYPTION_KEYresolution follows a strict priority: environment variable →data/.encryption_key→data/.jwt_secret→ auto-generated, ensuring deployment flexibility. HOSTshould only be set for bare-metal or Proxmox deployments; Docker containers handle networking internally.- All variables are read from
process.env, making TREK compatible with Docker Compose, Kubernetes, Helm, and traditional.envfile workflows.
Frequently Asked Questions
How does TREK resolve the ENCRYPTION_KEY variable?
TREK checks for ENCRYPTION_KEY in the environment first, then falls back to files data/.encryption_key and data/.jwt_secret, finally auto-generating a key if none exist. This hierarchy, implemented in server/src/config.ts (lines 52-62), ensures that manually supplied keys are persisted while maintaining backward compatibility.
Should I set the HOST variable when running TREK in Docker?
No. The HOST variable is only honored for non-container installations such as Proxmox or direct source deployments. In Docker environments, container networking handles binding automatically, and setting HOST can cause connectivity issues (see server/src/config.ts, lines 32-42).
Where are TREK environment variables documented?
The canonical documentation resides in wiki/Environment-Variables.md within the repository. This file contains the complete reference for every supported variable, while server/src/config.ts contains the actual implementation logic that parses these values at runtime.
How do I configure OIDC SSO in TREK?
Set OIDC_ISSUER to your provider's discovery URL, OIDC_CLIENT_ID and OIDC_CLIENT_SECRET to your service credentials, and optionally define OIDC_ADMIN_CLAIM and OIDC_ADMIN_VALUE to automatically elevate specific users to administrator status. These variables are processed during the authentication initialization phase in server/src/config.ts.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →