Configuration
Every environment variable, default, and health endpoint for the Palveron stack.
This page lists the required values, the common options, and the health endpoints for self-hosters.
Gateway (palveron-gateway)
Required
| Variable | Start behavior | Description |
|---|---|---|
DATABASE_URL | Boot stops always | PostgreSQL connection string |
PALVERON_DASHBOARD_URL | Boot stops in production | Public dashboard address; billing return addresses need it |
TRACE_ENCRYPTION_ROOT_KEY | Boot stops in production | Encrypts the stored records (openssl rand -base64 32) |
FLARE_ENCRYPTION_KEY | Boot stops in production | Encrypts the wallet signing keys |
A missing recommended value only logs a warning at start and turns off one capability each: PALVERON_ENCRYPTION_KEY (stored model key endpoint, 503 without it), PALVERON_PUBLIC_URL (falls back to http://localhost:8080), INTERNAL_PROXY_SECRET (dashboard trust, 403 without it), OPENAI_API_KEY (managed model path), DLQ_ENCRYPTION_KEY (buffer during a database outage), OPERATOR_API_KEY (/operator/* and /health/detailed), and RESEND_API_KEY (e-mail notifications).
Optional
| Variable | Default | Description |
|---|---|---|
PORT | 8080 | HTTP listen port |
HOST | 127.0.0.1 | Bind address. Set to 0.0.0.0 so the service is reachable in a container. |
REDIS_URL | — | Enables rate-limit cache and approval queue cache when set |
RUST_LOG | palveron_gateway=info,tower_http=info | Log filter |
NGE_MODELS_DIR | /app/models/nge | Path to ONNX model directory (~4 GB) |
NGE_MODE | nge_fallback | disabled, nge_local, nge_fallback, llm_only |
FLARE_PRIVATE_KEY | — | Hex-encoded key for managed-wallet anchoring |
FLARE_CONTRACT_ADDRESS | — | PalveronNotary contract on Flare |
FLARE_RPC_URL | https://coston2-api.flare.network/ext/C/rpc | Switch to mainnet RPC for production |
BRAND_NAME | Palveron | White-label brand name in API responses |
Dashboard (palveron-nexus)
Required
| Variable | Description |
|---|---|
DATABASE_URL | PostgreSQL — same DB as the gateway |
KINDE_CLIENT_ID | Kinde OIDC client ID |
KINDE_CLIENT_SECRET | Kinde OIDC client secret |
KINDE_ISSUER_URL | Kinde issuer URL (e.g. https://palveron.kinde.com) |
KINDE_SITE_URL | Public URL of the dashboard (used for OIDC redirects) |
INTERNAL_PROXY_SECRET | Must match the gateway's value |
Optional
| Variable | Default | Description |
|---|---|---|
PALVERON_CORE_INTERNAL_URL | http://gateway:8080 | Container-to-container gateway URL |
NEXT_PUBLIC_PALVERON_CORE_URL | — | Public gateway URL (for client-side calls) |
RESEND_API_KEY | — | Required only if email notifications are enabled |
STRIPE_SECRET_KEY | — | Required only when self-billing through Stripe |
STRIPE_WEBHOOK_SECRET | — | Used to verify Stripe webhooks |
Health endpoints
Every service exposes a health endpoint. Use them in liveness/readiness probes and uptime monitors.
| Service | Path | Healthy response |
|---|---|---|
| Gateway | GET /health | 200 — pure liveness (process alive; no dependency checks) |
| Gateway | GET /ready | 200 unless Postgres is critical/unprobed (reads the cached health state, never probes inline) |
| Dashboard | GET /api/health | 200 with build metadata |
The gateway's /health does not indicate readiness — use /ready for load-balancer probes during deployments. A full subsystem snapshot is available at GET /health/detailed, gated by the X-Palveron-Operator-Key header (503 when OPERATOR_API_KEY is unset).
Observability
| Endpoint | Description |
|---|---|
GET /metrics | Prometheus exposition on the gateway port — includes governance-availability, trace-durability and DLQ-replay-p95 SLO gauges |
GET /api/v1/integrity/status | Tamper-detection status, checked regularly (API-key auth) |
GET /api/v1/admin/system-health | System health for the admin panel (admin role required) |
Retry & rate-limit behavior
The gateway returns:
429 Too Many Requestswith aRetry-Afterheader and a structured body (limit_type:rpmormonthly) when a rate limit is hit503 Service Unavailable(empty body) when a governance decision could not be durably recorded (DB and DLQ unavailable) — retry with backoff
Official SDKs honor Retry-After and retry transient 5xx/timeout errors with exponential backoff and jitter. When building custom clients, replicate the same pattern.
For a deployment example, copy .env.example from the gateway repo
(gateway/.env.example)
to .env.production and fill in the required values, or use the commented values.yaml of the Helm chart
(deploy/charts/palveron).