Skip to content

Configuration ​

Rowbird is configured with environment variables, flags or a config file. When a setting comes from more than one place, the first of these wins:

  1. command-line flags (--listen-addr :9090)
  2. environment variables (ROWBIRD_LISTEN_ADDR=:9090)
  3. the server section of a config file
  4. built-in defaults

Config file ​

Pass the path with --config or ROWBIRD_CONFIG_FILE. Keys are the variable names in lower case without the ROWBIRD_ prefix; the S3 groups are nested:

yaml
server:
  base_url: https://rowbird.example.com
  listen_addr: ":8080"
  workers: 8
  log_format: json
  trusted_proxies: ["10.0.0.0/8"]
  backup_schedule: "0 3 * * *"
  storage_backend: s3
  storage_s3:
    endpoint: https://s3.eu-central-1.amazonaws.com
    region: eu-central-1
    bucket: acme-rowbird

Keep secrets (keys, passwords, the database URL) in the environment or in files, not in the config file.

Variables ​

Core ​

VariableDefaultDescription
ROWBIRD_BASE_URLnoneThe public URL of Rowbird, such as https://rowbird.example.com. Links in messages (reports, runs, shared files), passkeys and secure cookies need it. Without it messages carry no links, the link mode is refused and attachments that would fall back to a link fail with delivery.base_url_missing. Rowbird warns at startup when it is unset.
ROWBIRD_LISTEN_ADDR:8080The HTTP listen address.
ROWBIRD_DATA_DIR/dataThe SQLite store, local artifacts (artifacts/), the generated master key, run spools (spool/, kept 24 hours) and scheduled backups.
ROWBIRD_DATABASE_URLsqlite://$ROWBIRD_DATA_DIR/rowbird.dbThe internal store: sqlite://path or postgres://user:password@host/db. See Scaling.
ROWBIRD_CONFIG_FILEnonePath of a config file whose server section is loaded (also --config).
ROWBIRD_SETUP_TOKENnoneWhen set, the setup wizard asks for this value, so only you can create the first admin.
ROWBIRD_LOG_LEVELinfodebug, info, warn or error.
ROWBIRD_LOG_FORMATtexttext or json.
ROWBIRD_UPDATE_CHECKtrueCheck GitHub once a day for a newer release. Admins can also turn it off in Settings > About.

Master key ​

The master key encrypts every stored secret (AES-256-GCM): connection and channel passwords, TOTP secrets, AI keys, secret settings. It is 32 random bytes, base64 encoded (openssl rand -base64 32). When you provide none, Rowbird generates one into $ROWBIRD_DATA_DIR/master.key and logs a warning to back it up.

VariableDefaultDescription
ROWBIRD_MASTER_KEYgeneratedThe key itself.
ROWBIRD_MASTER_KEY_FILEnoneA file holding the key, for Docker and Kubernetes secrets.
ROWBIRD_MASTER_KEY_PREVIOUSnoneAn older key accepted for decryption only, while a rotation reaches every instance.
ROWBIRD_MASTER_KEY_PREVIOUS_FILEnoneThe same, from a file.

Scheduler and workers ​

VariableDefaultDescription
ROWBIRD_WORKERS4Runs executed at the same time by this instance.
ROWBIRD_SCHEDULER_TICK5sHow often the scheduler looks for due reports. It also paces heartbeats and the recovery of runs left by a lost instance.
ROWBIRD_SHUTDOWN_TIMEOUT30sHow long running runs may take to finish when Rowbird stops.
ROWBIRD_NO_SCHEDULERfalseDo not schedule reports on this instance (also --no-scheduler).
ROWBIRD_NO_WORKERSfalseDo not execute runs on this instance (also --no-workers).

Artifact storage ​

Files generated for deliveries (and served by download links) are kept in one place for the whole instance.

VariableDefaultDescription
ROWBIRD_STORAGE_BACKENDlocallocal (under $ROWBIRD_DATA_DIR/artifacts) or s3.
ROWBIRD_STORAGE_S3_ENDPOINTnoneThe S3-compatible endpoint, such as https://s3.amazonaws.com or http://minio:9000. The scheme decides TLS. Required for s3.
ROWBIRD_STORAGE_S3_REGIONnoneThe bucket's region.
ROWBIRD_STORAGE_S3_BUCKETnoneThe bucket. Required for s3.
ROWBIRD_STORAGE_S3_ACCESS_KEYnoneAccess key id.
ROWBIRD_STORAGE_S3_SECRET_KEYnoneSecret access key.
ROWBIRD_STORAGE_S3_PATH_STYLEfalsePath-style URLs, for MinIO and similar servers.
ROWBIRD_STORAGE_S3_PREFIXnoneKeep objects under this folder of a shared bucket.

Artifacts record their backend, but only the configured one is read: changing the backend makes earlier files unreachable, and their links answer 410 Gone.

Backups ​

Scheduled backups cover a SQLite store. See Backups and restore.

VariableDefaultDescription
ROWBIRD_BACKUP_SCHEDULEnoneA cron expression in UTC, such as 0 3 * * *. Empty turns scheduled backups off.
ROWBIRD_BACKUP_DIR$ROWBIRD_DATA_DIR/backupsWhere backups are written.
ROWBIRD_BACKUP_KEEP7How many backups to keep, in the directory and in the bucket.
ROWBIRD_BACKUP_WITH_ARTIFACTSfalseInclude local artifacts in each backup.
ROWBIRD_BACKUP_S3_ENDPOINTnoneAlso upload each backup to this S3-compatible endpoint.
ROWBIRD_BACKUP_S3_REGIONnoneRegion of the backup bucket.
ROWBIRD_BACKUP_S3_BUCKETnoneThe backup bucket. Uploads happen only when it is set.
ROWBIRD_BACKUP_S3_ACCESS_KEYnoneAccess key id.
ROWBIRD_BACKUP_S3_SECRET_KEYnoneSecret access key.
ROWBIRD_BACKUP_S3_PATH_STYLEfalsePath-style URLs.
ROWBIRD_BACKUP_S3_PREFIXnoneFolder for the backups inside the bucket.

Network and security ​

VariableDefaultDescription
ROWBIRD_TRUSTED_PROXIESnoneComma-separated CIDRs allowed to set X-Forwarded-For and X-Forwarded-Proto. Set it to your reverse proxy's address, or client IPs (used for rate limits and the security log) will be the proxy's.
ROWBIRD_NETWORK_POLICYopenopen, or block-private to stop connections, channels and AI providers from reaching private, loopback, link-local and cloud metadata addresses. See Hardening.
ROWBIRD_SQLITE_DIRS$ROWBIRD_DATA_DIR/sqliteComma-separated absolute directories that SQLite connections may read.
ROWBIRD_METRICS_TOKENnoneWhen set, /metrics requires Authorization: Bearer <token>.

GitOps ​

VariableDefaultDescription
ROWBIRD_CONFIG_DIRnoneA directory of YAML documents applied at startup, or right after setup. See Config as code.

CLI ​

VariableDefaultDescription
ROWBIRD_API_KEYnoneThe API key rowbird apply and rowbird export use with --server.

Settings in the UI ​

Some settings belong to the workspace rather than the instance and are changed by admins in the UI: the system mailer, alert channels and heartbeat, retention of runs and files, requiring 2FA, OIDC sign-in, the AI assistant and the update check.

Released under the Apache License 2.0.