All configuration comes from environment variables, validated once at startup
by a zod schema. A malformed value — a port that is not a number, a
negative duration — is caught there rather than in the middle of a request
six hours later.
An empty variable counts as unset
docker compose passes FOO= when the .env
does not define FOO. The panel treats that as an absence and
applies the default, rather than rejecting an empty string.
If the configuration is invalid the panel still starts: it logs the problem,
/api/ready answers 503, and every request returns an
explicit error. Failing loudly beats refusing to boot without saying why.
Accounts and sessions#
| Variable | Default | Effect |
|---|
ADMIN_PASSWORD | — | Password for the administrator role. With no password set at all, the panel starts but refuses every sign-in. |
MODERATOR_PASSWORD | — | Password for the moderator role. |
VIEWER_PASSWORD | — | Password for the viewer role. |
SESSION_SECRET | required | Session cookie signing key, 32 characters minimum. Independent from the passwords: rotating one signs nobody out. openssl rand -hex 32. |
SESSION_TTL_HOURS | 12 | Session lifetime, 720 h at most. |
COOKIE_SECURE | auto | auto sets secure as soon as the request arrives over HTTPS. true forces it, false forbids it. |
TRUST_PROXY | false | Trusts X-Forwarded-For and X-Forwarded-Proto. Only enable behind a proxy you control. |
LOGIN_MAX_ATTEMPTS | 5 | Sign-in attempts per IP, when the IP is trustworthy. |
LOGIN_WINDOW_MINUTES | 15 | Sliding window for the limit above. |
LOGIN_GLOBAL_MAX_ATTEMPTS | 50 | Global cap, always active, including without a trustworthy IP. |
RCON connection#
| Variable | Default | Effect |
|---|
RCON_HOST | factorio | Game server host, on the Compose network. |
RCON_PORT | 27015 | RCON port. |
RCON_PASSWORD | — | RCON password in clear. Takes precedence over the file below. |
RCON_PASSWORD_FILE | /factorio-config/rconpw | File holding the password, re-read on every connection: a regeneration on the Factorio side is picked up without restarting the panel. |
RCON_TIMEOUT_MS | 5000 | How long to wait for an RCON reply. |
RCON_MAX_QUEUE | 20 | Queued commands beyond which the panel refuses (503) instead of piling up. |
RCON_MAX_PER_MINUTE | 60 | Commands per minute, per session. |
STATUS_CACHE_MS | 5000 | Server status cache duration. Without it, every open tab would fire two RCON commands every few seconds. |
Custom commands#
| Variable | Default | Effect |
|---|
CUSTOM_COMMANDS_FILE | /factorio-config/commands.json | The operator's command catalogue. File absent: the feature is simply inactive. See Custom commands. |
Storage and audit#
| Variable | Default | Effect |
|---|
DATA_DIR | ./.data | Directory of the SQLite database. It is /data inside the image. |
AUDIT_RETENTION_DAYS | 90 | Older audit entries are purged at startup. |
AUDIT_FULL_COMMANDS | false | Keeps raw-console commands verbatim. Off by default: see the audit log. |
Metrics#
Three levels: a master switch, then one flag per source.
METRICS_ENABLED=false turns the whole feature off — no
collector, no tab, no route — and the two source flags are then not even
consulted.
| Variable | Default | Effect |
|---|
METRICS_ENABLED | true | Master switch. |
METRICS_DOCKER | true | Docker source (CPU and memory). At false, players and UPS keep being collected. |
DOCKER_API_URL | http://docker-proxy:2375 | Read-only Docker proxy. The panel never mounts the Docker socket. |
METRICS_CONTAINER | factorio | Value of the com.docker.compose.service label, falling back to the container name. |
DOCKER_TIMEOUT_MS | 10000 | Distinct from the RCON timeout: a Docker reading ties up the daemon for about a second to compute its CPU delta. |
METRICS_INTERVAL_MS | 15000 | Collection period, 5,000 ms minimum. |
METRICS_RETENTION_DAYS | 7 | Series retention, 365 days at most. |
METRICS_UPS | true | Measures UPS through a Lua command. Turn it off if the save's achievements matter — they are disabled in multiplayer anyway. |
Logging#
| Variable | Default | Effect |
|---|
LOG_LEVEL | info | debug, info, warn or error. Logs are JSON on standard output, readable by any collector. |
Development only#
| Variable | Default | Effect |
|---|
NEXT_DEV_ORIGINS | — | Hosts allowed to load next dev resources, hot reload included. Needed to open the panel from another machine on the network: NEXT_DEV_ORIGINS=192.168.1.17. No effect in production. |