PalveronPalveronDocs

Configuration

Every environment variable, default, and health endpoint for the Palveron stack.

This page lists the required values, the common options, and the health endpoints for self-hosters.

Gateway (palveron-gateway)

Required

VariableStart behaviorDescription
DATABASE_URLBoot stops alwaysPostgreSQL connection string
PALVERON_DASHBOARD_URLBoot stops in productionPublic dashboard address; billing return addresses need it
TRACE_ENCRYPTION_ROOT_KEYBoot stops in productionEncrypts the stored records (openssl rand -base64 32)
FLARE_ENCRYPTION_KEYBoot stops in productionEncrypts the wallet signing keys

A missing recommended value only logs a warning at start and turns off one capability each: PALVERON_ENCRYPTION_KEY (stored model key endpoint, 503 without it), PALVERON_PUBLIC_URL (falls back to http://localhost:8080), INTERNAL_PROXY_SECRET (dashboard trust, 403 without it), OPENAI_API_KEY (managed model path), DLQ_ENCRYPTION_KEY (buffer during a database outage), OPERATOR_API_KEY (/operator/* and /health/detailed), and RESEND_API_KEY (e-mail notifications).

Optional

VariableDefaultDescription
PORT8080HTTP listen port
HOST127.0.0.1Bind address. Set to 0.0.0.0 so the service is reachable in a container.
REDIS_URL—Enables rate-limit cache and approval queue cache when set
RUST_LOGpalveron_gateway=info,tower_http=infoLog filter
NGE_MODELS_DIR/app/models/ngePath to ONNX model directory (~4 GB)
NGE_MODEnge_fallbackdisabled, nge_local, nge_fallback, llm_only
FLARE_PRIVATE_KEY—Hex-encoded key for managed-wallet anchoring
FLARE_CONTRACT_ADDRESS—PalveronNotary contract on Flare
FLARE_RPC_URLhttps://coston2-api.flare.network/ext/C/rpcSwitch to mainnet RPC for production
BRAND_NAMEPalveronWhite-label brand name in API responses

Dashboard (palveron-nexus)

Required

VariableDescription
DATABASE_URLPostgreSQL — same DB as the gateway
KINDE_CLIENT_IDKinde OIDC client ID
KINDE_CLIENT_SECRETKinde OIDC client secret
KINDE_ISSUER_URLKinde issuer URL (e.g. https://palveron.kinde.com)
KINDE_SITE_URLPublic URL of the dashboard (used for OIDC redirects)
INTERNAL_PROXY_SECRETMust match the gateway's value

Optional

VariableDefaultDescription
PALVERON_CORE_INTERNAL_URLhttp://gateway:8080Container-to-container gateway URL
NEXT_PUBLIC_PALVERON_CORE_URL—Public gateway URL (for client-side calls)
RESEND_API_KEY—Required only if email notifications are enabled
STRIPE_SECRET_KEY—Required only when self-billing through Stripe
STRIPE_WEBHOOK_SECRET—Used to verify Stripe webhooks

Health endpoints

Every service exposes a health endpoint. Use them in liveness/readiness probes and uptime monitors.

ServicePathHealthy response
GatewayGET /health200 — pure liveness (process alive; no dependency checks)
GatewayGET /ready200 unless Postgres is critical/unprobed (reads the cached health state, never probes inline)
DashboardGET /api/health200 with build metadata

The gateway's /health does not indicate readiness — use /ready for load-balancer probes during deployments. A full subsystem snapshot is available at GET /health/detailed, gated by the X-Palveron-Operator-Key header (503 when OPERATOR_API_KEY is unset).

Observability

EndpointDescription
GET /metricsPrometheus exposition on the gateway port — includes governance-availability, trace-durability and DLQ-replay-p95 SLO gauges
GET /api/v1/integrity/statusTamper-detection status, checked regularly (API-key auth)
GET /api/v1/admin/system-healthSystem health for the admin panel (admin role required)

Retry & rate-limit behavior

The gateway returns:

  • 429 Too Many Requests with a Retry-After header and a structured body (limit_type: rpm or monthly) when a rate limit is hit
  • 503 Service Unavailable (empty body) when a governance decision could not be durably recorded (DB and DLQ unavailable) — retry with backoff

Official SDKs honor Retry-After and retry transient 5xx/timeout errors with exponential backoff and jitter. When building custom clients, replicate the same pattern.

For a deployment example, copy .env.example from the gateway repo (gateway/.env.example) to .env.production and fill in the required values, or use the commented values.yaml of the Helm chart (deploy/charts/palveron).

On this page