Factorio Admin RCON Source code

Configuration

Every environment variable, its default, and what it actually changes.

All configuration comes from environment variables, validated once at startup by a zod schema. A malformed value — a port that is not a number, a negative duration — is caught there rather than in the middle of a request six hours later.

An empty variable counts as unset docker compose passes FOO= when the .env does not define FOO. The panel treats that as an absence and applies the default, rather than rejecting an empty string.

If the configuration is invalid the panel still starts: it logs the problem, /api/ready answers 503, and every request returns an explicit error. Failing loudly beats refusing to boot without saying why.

Accounts and sessions#

VariableDefaultEffect
ADMIN_PASSWORD—Password for the administrator role. With no password set at all, the panel starts but refuses every sign-in.
MODERATOR_PASSWORD—Password for the moderator role.
VIEWER_PASSWORD—Password for the viewer role.
SESSION_SECRETrequiredSession cookie signing key, 32 characters minimum. Independent from the passwords: rotating one signs nobody out. openssl rand -hex 32.
SESSION_TTL_HOURS12Session lifetime, 720 h at most.
COOKIE_SECUREautoauto sets secure as soon as the request arrives over HTTPS. true forces it, false forbids it.
TRUST_PROXYfalseTrusts X-Forwarded-For and X-Forwarded-Proto. Only enable behind a proxy you control.
LOGIN_MAX_ATTEMPTS5Sign-in attempts per IP, when the IP is trustworthy.
LOGIN_WINDOW_MINUTES15Sliding window for the limit above.
LOGIN_GLOBAL_MAX_ATTEMPTS50Global cap, always active, including without a trustworthy IP.

RCON connection#

VariableDefaultEffect
RCON_HOSTfactorioGame server host, on the Compose network.
RCON_PORT27015RCON port.
RCON_PASSWORD—RCON password in clear. Takes precedence over the file below.
RCON_PASSWORD_FILE/factorio-config/rconpwFile holding the password, re-read on every connection: a regeneration on the Factorio side is picked up without restarting the panel.
RCON_TIMEOUT_MS5000How long to wait for an RCON reply.
RCON_MAX_QUEUE20Queued commands beyond which the panel refuses (503) instead of piling up.
RCON_MAX_PER_MINUTE60Commands per minute, per session.
STATUS_CACHE_MS5000Server status cache duration. Without it, every open tab would fire two RCON commands every few seconds.

Custom commands#

VariableDefaultEffect
CUSTOM_COMMANDS_FILE/factorio-config/commands.jsonThe operator's command catalogue. File absent: the feature is simply inactive. See Custom commands.

Storage and audit#

VariableDefaultEffect
DATA_DIR./.dataDirectory of the SQLite database. It is /data inside the image.
AUDIT_RETENTION_DAYS90Older audit entries are purged at startup.
AUDIT_FULL_COMMANDSfalseKeeps raw-console commands verbatim. Off by default: see the audit log.

Metrics#

Three levels: a master switch, then one flag per source. METRICS_ENABLED=false turns the whole feature off — no collector, no tab, no route — and the two source flags are then not even consulted.

VariableDefaultEffect
METRICS_ENABLEDtrueMaster switch.
METRICS_DOCKERtrueDocker source (CPU and memory). At false, players and UPS keep being collected.
DOCKER_API_URLhttp://docker-proxy:2375Read-only Docker proxy. The panel never mounts the Docker socket.
METRICS_CONTAINERfactorioValue of the com.docker.compose.service label, falling back to the container name.
DOCKER_TIMEOUT_MS10000Distinct from the RCON timeout: a Docker reading ties up the daemon for about a second to compute its CPU delta.
METRICS_INTERVAL_MS15000Collection period, 5,000 ms minimum.
METRICS_RETENTION_DAYS7Series retention, 365 days at most.
METRICS_UPStrueMeasures UPS through a Lua command. Turn it off if the save's achievements matter — they are disabled in multiplayer anyway.

Logging#

VariableDefaultEffect
LOG_LEVELinfodebug, info, warn or error. Logs are JSON on standard output, readable by any collector.

Development only#

VariableDefaultEffect
NEXT_DEV_ORIGINS—Hosts allowed to load next dev resources, hot reload included. Needed to open the panel from another machine on the network: NEXT_DEV_ORIGINS=192.168.1.17. No effect in production.