How to Configure Environment Variables for Kaneo: Complete Setup Guide
Kaneo uses a single .env file at the repository root to configure both the API server and the web frontend, with all supported variables documented in ENVIRONMENT_SETUP.md and templated in .env.sample.
The open-source project management platform Kaneo (usekaneo/kaneo) centralizes its configuration through environment variables, allowing both the Hono-based API and the Vite-powered web application to read from the same source. This unified approach simplifies deployment across development and production environments while supporting optional integrations like Redis, SMTP, and SSO providers.
Core Configuration Architecture
Kaneo follows a single-source-of-truth pattern where one .env file serves the entire stack. According to the ENVIRONMENT_SETUP.md documentation, variables defined here are automatically available to both the backend API and the frontend build process, eliminating mismatched URLs between client and server.
The API server consumes variables directly via process.env, while the web application accesses them through import.meta.env for Vite-specific prefixes. In apps/api/src/index.ts, the server reads KANEO_CLIENT_URL and KANEO_API_URL to configure CORS and routing, while apps/web/src/lib/invitation-link.ts demonstrates how the frontend consumes VITE_APP_URL or falls back to KANEO_CLIENT_URL.
Required Environment Variables
To run Kaneo locally, you must define a minimum set of variables in the repository root .env file:
KANEO_CLIENT_URL– The base URL of the web frontend (e.g.,http://localhost:5173).KANEO_API_URL– The base URL of the API server (e.g.,http://localhost:1337). If omitted, the API assumes the client URL with/apiappended.AUTH_SECRET– A secret string for signing JWTs. Must be at least 32 characters in production; if omitted, a random secret generates at startup (sessions will not survive restarts).DATABASE_URL– A PostgreSQL connection string (e.g.,postgresql://kaneo:password@localhost:5432/kaneo).
Alternatively, you may omit DATABASE_URL and provide the PostgreSQL credentials separately:
POSTGRES_DB– Database name.POSTGRES_USER– Database user.POSTGRES_PASSWORD– Database password.POSTGRES_HOSTandPOSTGRES_PORT– Optional; default tolocalhostand5432.
Minimal Development Configuration
# .env (copy from .env.sample)
KANEO_CLIENT_URL=http://localhost:5173
KANEO_API_URL=http://localhost:1337
AUTH_SECRET=0123456789abcdef0123456789abcdef
POSTGRES_DB=kaneo
POSTGRES_USER=kaneo
POSTGRES_PASSWORD=secret
Development-Specific Variables
When running the Vite development server, these variables override behavior for the web client:
VITE_API_URL– Overrides the API endpoint URL for the frontend dev server.VITE_APP_URL– Used by the web app to generate absolute links (e.g., in email invitations).CORS_ORIGINS– Comma-separated list of allowed origins for cross-origin requests. Leaving this empty enables all origins in development mode.
In apps/api/src/auth.ts, the server references process.env.KANEO_CLIENT_URL to construct callback URLs, while the web layer uses import.meta.env.VITE_APP_URL as shown in the invitation link utility.
Optional Integrations
Kaneo supports extensive optional features toggled via environment variables:
Redis Pub/Sub for WebSocket Scaling
For horizontal scaling of real-time features, configure one of three Redis modes:
- Standalone:
REDIS_URL=redis://localhost:6379 - Sentinel:
REDIS_SENTINELS,REDIS_SENTINEL_MASTER_NAME,REDIS_SENTINEL_PASSWORD,REDIS_SENTINEL_TLS - Cluster:
REDIS_CLUSTER_NODES,REDIS_PASSWORD
SMTP Email Delivery
Enable email-based sign-in and invitation notifications:
SMTP_HOST=smtp.mailtrap.io
SMTP_PORT=2525
SMTP_USER=your_user
SMTP_PASSWORD=your_pass
SMTP_FROM=no-reply@mydomain.com
SMTP_SECURE=true
SMTP_REQUIRE_TLS=true
Single Sign-On (SSO)
Configure OAuth providers using the following patterns:
- GitHub:
GITHUB_OAUTH_CLIENT_IDandGITHUB_OAUTH_CLIENT_SECRET(or legacyGITHUB_CLIENT_ID/GITHUB_CLIENT_SECRET). - Google and Discord: Similar patterns documented in
ENVIRONMENT_SETUP.md.
Cloud-Mode Abuse Mitigation
For hosted SaaS deployments, enable KANEO_CLOUD=true to activate stricter rate limits and disposable email blocking. This mode requires Turnstile captcha configuration:
TURNSTILE_SECRET_KEY– Server-side secret.KANEO_TURNSTILE_SITE_KEYandVITE_TURNSTILE_SITE_KEY– Public site keys for server and client.
Sentry Error Monitoring
Optional error tracking supports dual DSN configuration:
SENTRY_DSNandKANEO_SENTRY_DSN– API side.VITE_SENTRY_DSN– Client side.SENTRY_ENVIRONMENTandSENTRY_TRACES_SAMPLE_RATE– Shared configuration.
Configuration Examples
Enabling Redis for Multi-Instance Deployments
# Add to .env for WebSocket scaling
REDIS_URL=redis://localhost:6379
GitHub OAuth Setup
GITHUB_OAUTH_CLIENT_ID=your_github_app_id
GITHUB_OAUTH_CLIENT_SECRET=your_github_app_secret
Production Database URL
DATABASE_URL=postgresql://kaneo:secure_password@db.example.com:5432/kaneo_production
Summary
- Kaneo reads configuration from a single
.envfile at the repository root, shared between the API (apps/api/src/index.ts) and web frontend (apps/web/src/lib/invitation-link.ts). - Required variables include
KANEO_CLIENT_URL,KANEO_API_URL,AUTH_SECRET(≥32 characters), and PostgreSQL credentials via eitherDATABASE_URLorPOSTGRES_DB/POSTGRES_USER/POSTGRES_PASSWORD. - Development-specific prefixes (
VITE_API_URL,VITE_APP_URL) configure the Vite dev server independently from production API routing. - Optional integrations require specific variable sets: Redis for scaling, SMTP for email, OAuth credentials for SSO, and Turnstile keys for cloud-mode security.
- The repository provides
.env.sampleas a complete template andENVIRONMENT_SETUP.mdas the authoritative reference for all supported variables.
Frequently Asked Questions
What happens if I don't set AUTH_SECRET?
If AUTH_SECRET is omitted, Kaneo generates a random secret at startup. While this allows the application to run, user sessions will not survive server restarts, forcing all users to log in again after each deployment. In production, always set a persistent secret of at least 32 characters.
Can I use environment variables for database configuration instead of a connection string?
Yes. If you omit DATABASE_URL, Kaneo constructs the connection string from individual components: POSTGRES_DB, POSTGRES_USER, POSTGRES_PASSWORD, POSTGRES_HOST (default: localhost), and POSTGRES_PORT (default: 5432). This approach simplifies local development setups where connection string formatting might vary by platform.
How do I configure Kaneo for horizontal scaling across multiple servers?
Enable Redis Pub/Sub by setting REDIS_URL for standalone mode, or configure Sentinel/Cluster variables (REDIS_SENTINELS, REDIS_CLUSTER_NODES, etc.) for high-availability setups. This allows WebSocket connections to synchronize across multiple API instances, ensuring real-time updates propagate to all connected clients regardless of which server handles their connection.
What is the difference between KANEO_CLIENT_URL and VITE_APP_URL?
KANEO_CLIENT_URL is the canonical server-side reference to the frontend URL, used by the API for CORS configuration and callback generation in apps/api/src/auth.ts. VITE_APP_URL is a development-specific override consumed by the Vite dev server in apps/web/src/lib/invitation-link.ts to generate absolute links during local development. In production builds, the application typically relies on KANEO_CLIENT_URL.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →