PageSourceSearch

https://docs-pactflow-preview.netlify.app/assets/js/8acb4b87.2d7ced78.js

js docs-pactflow-preview.netlify.app collected 2026-10-03 10:41:11 UTC 53,644 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkpartners=self.webpackChunkpartners||[]).push([[15840],{15680:(e,n,t)=>{t.d(n,{xA:()=>g,yg:()=>_});var a=t(96540);function l(e,n,t){return n in e?Object.defineProperty(e,n,{value:t,enumerable:!0,configurable:!0,writable:!0}):e[n]=t,e}function r(e,n){var t=Object.keys(e);if(Object.getOwnPropertySymbols){var a=Object.getOwnPropertySymbols(e);n&&(a=a.filter((function(n){return Object.getOwnPropertyDescriptor(e,n).enumerable}))),t.push.apply(t,a)}return t}function o(e){for(var n=1;n<arguments.length;n++){var t=null!=arguments[n]?arguments[n]:{};n%2?r(Object(t),!0).forEach((function(n){l(e,n,t[n])})):Object.getOwnPropertyDescriptors?Object.defineProperties(e,Object.getOwnPropertyDescriptors(t)):r(Object(t)).forEach((function(n){Object.defineProperty(e,n,Object.getOwnPropertyDescriptor(t,n))}))}return e}function i(e,n){if(null==e)return{};var t,a,l=function(e,n){if(null==e)return{};var t,a,l={},r=Object.keys(e);for(a=0;a<r.length;a++)t=r[a],n.indexOf(t)>=0||(l[t]=e[t]);return l}(e,n);if(Object.getOwnPropertySymbols){var r=Object.getOwnPropertySymbols(e);for(a=0;a<r.length;a++)t=r[a],n.indexOf(t)>=0||Object.prototype.propertyIsEnumerable.call(e,t)&&(l[t]=e[t])}return l}var p=a.createContext({}),s=function(e){var n=a.useContext(p),t=n;return e&&(t="function"==typeof e?e(n):o(o({},n),e)),t},g=function(e){var n=s(e.components);return a.createElement(p.Provider,{value:n},e.children)},u="mdxType",d={inlineCode:"code",wrapper:function(e){var n=e.children;return a.createElement(a.Fragment,{},n)}},y=a.forwardRef((function(e,n){var t=e.components,l=e.mdxType,r=e.originalType,p=e.parentName,g=i(e,["components","mdxType","originalType","parentName"]),u=s(t),y=l,_=u["".concat(p,".").concat(y)]||u[y]||d[y]||r;return t?a.createElement(_,o(o({ref:n},g),{},{components:t})):a.createElement(_,o({ref:n},g))}));function _(e,n){var t=arguments,l=n&&n.mdxType;if("string"==typeof e||l){var r=t.length,o=new Array(r);o[0]=y;var i={};for(var p in n)hasOwnProperty.call(n,p)&&(i[p]=n[p]);i.originalType=e,i[u]="string"==typeof e?e:l,o[1]=i;for(var s=2;s<r;s++)o[s]=t[s];return a.createElement.apply(null,o)}return a.createElement.apply(null,t)}y.displayName="MDXCreateElement"},90038:(e,n,t)=>{t.r(n),t.d(n,{assets:()=>p,contentTitle:()=>o,default:()=>d,frontMatter:()=>r,metadata:()=>i,toc:()=>s});var a=t(58168),l=(t(96540),t(15680));const r={title:"Environment variables"},o=void 0,i={unversionedId:"docs/on-premises/environment-variables",id:"docs/on-premises/environment-variables",title:"Environment variables",description:"\x3c!--",source:"@site/docs/docs/on-premises/environment-variables.md",sourceDirName:"docs/on-premises",slug:"/docs/on-premises/environment-variables",permalink:"/docs/on-premises/environment-variables",draft:!1,editUrl:"https://github.com/pactflow/docs.pactflow.io/edit/master/website/docs/docs/on-premises/environment-variables.md",tags:[],version:"current",lastUpdatedBy:"Matt Fellows",lastUpdatedAt:1755665408,formattedLastUpdatedAt:"Aug 20, 2025",frontMatter:{title:"Environment variables"},sidebar:"onprem",previous:{title:"SAML",permalink:"/docs/on-premises/authentication/saml"},next:{title:"Configuration file templates",permalink:"/docs/on-premises/environment-variables/templates"}},p={},s=[{value:"Logging",id:"logging",level:2},{value:"PACTFLOW_LOG_LEVEL",id:"pactflow_log_level",level:3},{value:"PACTFLOW_LOG_FORMAT",id:"pactflow_log_format",level:3},{value:"PACTFLOW_HTTP_LOGGING_ENABLED",id:"pactflow_http_logging_enabled",level:3},{value:"Monitoring",id:"monitoring",level:2},{value:"NEW_RELIC_AGENT_ENABLED",id:"new_relic_agent_enabled",level:3},{value:"Database",id:"database",level:2},{value:"PACTFLOW_DATABASE_URL",id:"pactflow_database_url",level:3},{value:"PACTFLOW_DATABASE_ADAPTER",id:"pactflow_database_adapter",level:3},{value:"PACTFLOW_DATABASE_USERNAME",id:"pactflow_database_username",level:3},{value:"PACTFLOW_DATABASE_PASSWORD",id:"pactflow_database_password",level:3},{value:"PACTFLOW_DATABASE_HOST",id:"pactflow_database_host",level:3},{value:"PACTFLOW_DATABASE_PORT",id:"pactflow_database_port",level:3},{value:"PACTFLOW_DATABASE_NAME",id:"pactflow_database_name",level:3},{value:"PACTFLOW_DATABASE_SSLMODE",id:"pactflow_database_sslmode",level:3},{value:"PACTFLOW_DATABASE_CONNECTION_VALIDATION_TIMEOUT",id:"pactflow_database_connection_validation_timeout",level:3},{value:"PACTFLOW_SQL_LOG_WARN_DURATION",id:"pactflow_sql_log_warn_duration",level:3},{value:"PACTFLOW_SQL_LOG_LEVEL",id:"pactflow_sql_log_level",level:3},{value:"PACTFLOW_DATABASE_MAX_CONNECTIONS",id:"pactflow_database_max_connections",level:3},{value:"PACTFLOW_DATABASE_POOL_TIMEOUT",id:"pactflow_database_pool_timeout",level:3},{value:"PACTFLOW_DATABASE_AUTO_MIGRATE",id:"pactflow_database_auto_migrate",level:3},{value:"AWS_REGION",id:"aws_region",level:3},{value:"Webhooks",id:"webhooks",level:2},{value:"PACTFLOW_WEBHOOK_HOST_WHITELIST",id:"pactflow_webhook_host_whitelist",level:3},{value:"PACTFLOW_WEBHOOK_SCHEME_WHITELIST",id:"pactflow_webhook_scheme_whitelist",level:3},{value:"PACTFLOW_WEBHOOK_HTTP_METHOD_WHITELIST",id:"pactflow_webhook_http_method_whitelist",level:3},{value:"PACTFLOW_DISABLE_SSL_VERIFICATION",id:"pactflow_disable_ssl_verification",level:3},{value:"PACTFLOW_WEBHOOK_CERTIFICATES",id:"pactflow_webhook_certificates",level:3},{value:"SAML authentication",id:"saml-authentication",level:2},{value:"PACTFLOW_SAML_AUTH_ENABLED",id:"pactflow_saml_auth_enabled",level:3},{value:"PACTFLOW_SAML_ISSUER",id:"pactflow_saml_issuer",level:3},{value:"PACTFLOW_SAML_IDP_NAME",id:"pactflow_saml_idp_name",level:3},{value:"PACTFLOW_SAML_IDP_LOGO",id:"pactflow_saml_idp_logo",level:3},{value:"PACTFLOW_SAML_IDP_SSO_TARGET_URL",id:"pactflow_saml_idp_sso_target_url",level:3},{value:"PACTFLOW_SAML_IDP_CERT_FINGERPRINT",id:"pactflow_saml_idp_cert_fingerprint",level:3},{value:"PACTFLOW_SAML_IDP_ID_ATTRIBUTE",id:"pactflow_saml_idp_id_attribute",level:3},{value:"PACTFLOW_SAML_EMAIL_ATTRIBUTE",id:"pactflow_saml_email_attribute",level:3},{value:"PACTFLOW_SAML_NAME_ATTRIBUTE",id:"pactflow_saml_name_attribute",level:3},{value:"PACTFLOW_SAML_FIRST_NAME_ATTRIBUTE",id:"pactflow_saml_first_name_attribute",level:3},{value:"PACTFLOW_SAML_LAST_NAME_ATTRIBUTE",id:"pactflow_saml_last_name_attribute",level:3},{value:"PACTFLOW_SAML_IDP_METADATA_URL",id:"pactflow_saml_idp_metadata_url",level:3},{value:"PACTFLOW_SAML_NAME_IDENTIFIER_FORMAT",id:"pactflow_saml_name_identifier_format",level:3}
1,{value:"PACTFLOW_SAML_ALLOWED_CLOCK_DRIFT",id:"pactflow_saml_allowed_clock_drift",level:3},{value:"Demo authentication",id:"demo-authentication",level:2},{value:"PACTFLOW_DEMO_AUTH_ENABLED",id:"pactflow_demo_auth_enabled",level:3},{value:"Encryption",id:"encryption",level:2},{value:"PACTFLOW_MASTER_ENCRYPTION_KEY",id:"pactflow_master_encryption_key",level:3},{value:"Secrets",id:"secrets",level:2},{value:"PACTFLOW_MASTER_SECRETS_ENCRYPTION_KEY",id:"pactflow_master_secrets_encryption_key",level:3},{value:"Content Security",id:"content-security",level:2},{value:"PACTFLOW_CSP_ALLOWED_SOURCES",id:"pactflow_csp_allowed_sources",level:3},{value:"User administration",id:"user-administration",level:2},{value:"PACTFLOW_ADMIN_API_KEY",id:"pactflow_admin_api_key",level:3},{value:"Domain",id:"domain",level:2},{value:"PACTFLOW_ALLOW_DANGEROUS_CONTRACT_MODIFICATION",id:"pactflow_allow_dangerous_contract_modification",level:3},{value:"PACTFLOW_USE_FIRST_TAG_AS_BRANCH",id:"pactflow_use_first_tag_as_branch",level:3},{value:"PACTFLOW_CREATE_DEPLOYED_VERSIONS_FOR_TAGS",id:"pactflow_create_deployed_versions_for_tags",level:3},{value:"Badges",id:"badges",level:2},{value:"PACTFLOW_SHIELDS_IO_BASE_URL",id:"pactflow_shields_io_base_url",level:3},{value:"Resources",id:"resources",level:2},{value:"PACTFLOW_BASE_URL",id:"pactflow_base_url",level:3},{value:"PACTFLOW_HTTP_PORT",id:"pactflow_http_port",level:3},{value:"PACTFLOW_SESSION_LENGTH",id:"pactflow_session_length",level:3},{value:"PACTFLOW_SESSION_INACTIVITY_TIMEOUT",id:"pactflow_session_inactivity_timeout",level:3},{value:"PACTFLOW_COOKIE_SECRET",id:"pactflow_cookie_secret",level:3},{value:"PACTFLOW_OLD_COOKIE_SECRET",id:"pactflow_old_cookie_secret",level:3},{value:"PACTFLOW_REQUIRE_HTTPS",id:"pactflow_require_https",level:3},{value:"SSL_CERT_FILE",id:"ssl_cert_file",level:3},{value:"SSL_CERT_DIR",id:"ssl_cert_dir",level:3},{value:"http_proxy",id:"http_proxy",level:3},{value:"https_proxy",id:"https_proxy",level:3},{value:"no_proxy",id:"no_proxy",level:3},{value:"PACTFLOW_USE_HAL_BROWSER",id:"pactflow_use_hal_browser",level:3},{value:"Miscellaneous",id:"miscellaneous",level:2},{value:"TZ",id:"tz",level:3},{value:"API Tokens",id:"api-tokens",level:2},{value:"PACTFLOW_API_TOKEN_AUTH_ENABLED",id:"pactflow_api_token_auth_enabled",level:3},{value:"PACTFLOW_API_TOKEN_ENCRYPTION_ENABLED",id:"pactflow_api_token_encryption_enabled",level:3},{value:"PACTFLOW_API_TOKEN_IV",id:"pactflow_api_token_iv",level:3},{value:"Observability",id:"observability",level:2},{value:"OTEL_EXPORTER_OTLP_ENDPOINT",id:"otel_exporter_otlp_endpoint",level:3},{value:"OTEL_DEPLOYMENT_ENVIRONMENT",id:"otel_deployment_environment",level:3},{value:"OTEL_LOG_LEVEL",id:"otel_log_level",level:3}],g={toc:s},u="wrapper";function d(e){let{components:n,...t}=e;return(0,l.yg)(u,(0,a.A)({},g,t,{components:n,mdxType:"MDXLayout"}),(0,l.yg)("h2",{id:"logging"},"Logging"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_log_level"},"PACTFLOW_LOG_LEVEL"),(0,l.yg)("p",null,"The PactFlow application log level"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"INFO"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"DEBUG"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"INFO"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"WARN"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"ERROR"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"FATAL"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_log_format"},"PACTFLOW_LOG_FORMAT"),(0,l.yg)("p",null,"The PactFlow application log format"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"json"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"json"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"default"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"color"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/rocketjob/semantic_logger/tree/master/lib/semantic_logger/formatters"},"https://github.com/rocketjob/semantic_logger/tree/master/lib/semantic_logger/formatters"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_http_logging_enabled"},"PACTFLOW_HTTP_LOGGING_ENABLED"),(0,l.yg)("p",null,"When true, HTTP request details and response status and duration will be logged to stdout in json format"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"monitoring"},"Monitoring"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"new_relic_agent_enabled"},"NEW_RELIC_AGENT_ENABLED"),(0,l.yg)("p",null,"Set this to true to enable New Relic application monitoring. The New Relic config file should be mou
1nted at /home/pactflow/config/newrelic.yml"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"database"},"Database"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_database_url"},"PACTFLOW_DATABASE_URL"),(0,l.yg)("p",null,"The fully qualified database connection string. If using Postgres on RDS with IAM authentication, the scheme must be ",(0,l.yg)("inlineCode",{parentName:"p"},"postgresiam")," and the port must also be set."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if separate host, name, username, password environment variables are not set",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"postgresql://username:password@host:port/database"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_adapter"},"PACTFLOW_DATABASE_ADAPTER"),(0,l.yg)("p",null,"The database adapter to use. Use ",(0,l.yg)("inlineCode",{parentName:"p"},"postgresiam")," when using Postgres on RDS with IAM authentication (rather than username/password authentication)."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"postgres"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"postgres"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"postgresiam"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_username"},"PACTFLOW_DATABASE_USERNAME"),(0,l.yg)("p",null,"The database username"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_DATABASE_URL is not set",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_password"},"PACTFLOW_DATABASE_PASSWORD"),(0,l.yg)("p",null,"The database password"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_DATABASE_URL is not set, unless using Postgres on RDS with IAM authentication",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_host"},"PACTFLOW_DATABASE_HOST"),(0,l.yg)("p",null,"The database host"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_DATABASE_URL is not set",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_port"},"PACTFLOW_DATABASE_PORT"),(0,l.yg)("p",null,"The database port"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_DATABASE_URL is not set",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_name"},"PACTFLOW_DATABASE_NAME"),(0,l.yg)("p",null,"The database name"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_DATABASE_URL is not set",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_sslmode"},"PACTFLOW_DATABASE_SSLMODE"),(0,l.yg)("p",null,"The Postgresql ssl mode. Note, if using Postgres on AWS RDS with IAM authentication, this must be ",(0,l.yg)("inlineCode",{parentName:"p"},"require"),"."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"require"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"disable"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"allow"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"prefer"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"require"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"verify-ca"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"verify-full"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://ankane.org/postgres-sslmode-explained"},"https://ankane.org/postgres-sslmode-explained"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_connection_validation_timeout"},"PACTFLOW_DATABASE_CONNECTION_VALIDATION_TIMEOUT"),(0,l.yg)("p",null,"The number of seconds after which to check the health of a connection from a connection pool before passing it to the application."),(0,l.yg)("p",null,(0,l.yg)("inlineCode",{parentName:"p"},"-1")," means that connections will be validated every time, which avoids errors\nwhen databases are restarted and connections are killed.  This has a performance\npenalty, so consider increasing this timeout if building a frequently accessed service."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"3600"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," -1 or any positive integer.",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://sequel.jeremyevans.net/rdoc-plugins/files/lib/sequel/extensions/connection_validator_rb.html"},"https://sequel.jeremyevans.net/rdoc-plugins/files/lib/sequel/extensions/connection_validator_rb.html"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_sql_log_warn_duration"},"PACTFLOW_SQL_LOG_WARN_DURATION"),(0,l.yg)("p",null,"The duration in seconds, as a float, after which to log an SQL statement"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"5"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_sql_log_level"},"PACTFLOW_SQL_LOG_LEVEL"),(0,l.yg)("p",null,"The log level that will be specified when the SQL query statements are logged."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"NONE"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"NONE"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"DEBUG"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"INFO"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"WARN"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"ERROR"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"FATAL"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_max_connections"},"PACTFLOW_DATABASE_MAX_CONNECTIONS"),(0,l.yg)("p",null,"The maximum size of the connection pool per application instance. The total number of connections for the database must be calculated by multiplying this value b
1y the number of instances (ie. running Docker containers)."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"4"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," A positive integer value.",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://sequel.jeremyevans.net/rdoc/files/doc/opening_databases_rdoc.html#label-General+connection+options"},"https://sequel.jeremyevans.net/rdoc/files/doc/opening_databases_rdoc.html#label-General+connection+options"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_pool_timeout"},"PACTFLOW_DATABASE_POOL_TIMEOUT"),(0,l.yg)("p",null,"The number of seconds to wait if a connection cannot be acquired before raising an error."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"5"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," A positive integer.",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://sequel.jeremyevans.net/rdoc/files/doc/opening_databases_rdoc.html#label-General+connection+options"},"https://sequel.jeremyevans.net/rdoc/files/doc/opening_databases_rdoc.html#label-General+connection+options"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_database_auto_migrate"},"PACTFLOW_DATABASE_AUTO_MIGRATE"),(0,l.yg)("p",null,"Whether or not to automatically apply the schema and data migrations to the database on startup"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"aws_region"},"AWS_REGION"),(0,l.yg)("p",null,"Required for running Postgres on RDS with IAM authentication. This must be set to the AWS region where the RDS database instance is running."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"webhooks"},"Webhooks"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_webhook_host_whitelist"},"PACTFLOW_WEBHOOK_HOST_WHITELIST"),(0,l.yg)("p",null,"A space delimited list of hosts for which webhook response logging will be enabled. By default, all responses will be redacted for security purposes. To allow logging for all hosts, use the value ",(0,l.yg)("inlineCode",{parentName:"p"},"/.*/"),"."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"/.*\\.foo\\.com$/ github.com foo.slack.com"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"},"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_webhook_scheme_whitelist"},"PACTFLOW_WEBHOOK_SCHEME_WHITELIST"),(0,l.yg)("p",null,"A space delimited list of allowed schemes for a webhook to use."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"http"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"},"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_webhook_http_method_whitelist"},"PACTFLOW_WEBHOOK_HTTP_METHOD_WHITELIST"),(0,l.yg)("p",null,"A space delimited list of allowed http methods for a webhook to use. ",(0,l.yg)("em",{parentName:"p"},"It is strongly recommended to only allow POST requests for security purposes.")),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"POST"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"GET"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"POST"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"PUT"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"PATCH"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"DELETE"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"},"https://docs.pact.io/pact_broker/configuration#webhook-whitelists"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_disable_ssl_verification"},"PACTFLOW_DISABLE_SSL_VERIFICATION"),(0,l.yg)("p",null,"Whether or not to disable SSL verificaton when executing webhooks."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_webhook_certificates"},"PACTFLOW_WEBHOOK_CERTIFICATES"),(0,l.yg)("p",null,"A list of SSL certificate configuration objects with the properties ",(0,l.yg)("inlineCode",{parentName:"p"},"description"),", and either ",(0,l.yg)("inlineCode",{parentName:"p"},"content")," or ",(0,l.yg)("inlineCode",{parentName:"p"},"path"),". These\ncertificates are used when a webhook needs to connect to a server that uses a self signed certificate."),(0,l.yg)("p",null,"Each certificate configuration item accepts a chain of certificates in PEM format - there may be multiple 'BEGIN CERTIFICATE' and 'END CERTIFICATE' in the content of each item."),(0,l.yg)("p",null,"The certificate configuration is not val
1idated on startup. If any of the configured certificates cannot be loaded during the execution of a webhook, an error\nwill be logged, and they will be ignored. You can check if the configuration is working by testing the execution of\na webhook that connects to the server with the self signed certificate by following these instructions ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/pact_broker/webhooks/debugging_webhooks#testing-webhook-execution"},"https://docs.pact.io/pact_broker/webhooks/debugging_webhooks#testing-webhook-execution")),(0,l.yg)("p",null,"When setting the path, the full path to the certificate file in PEM format must be specified. When using Docker, you must ensure the\ncertificate file is ",(0,l.yg)("a",{parentName:"p",href:"https://docs.docker.com/storage/volumes/"},"mounted into the container"),"."),(0,l.yg)("p",null,"Each property of the certificate is described by an indexed environment variable in the format ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_WEBHOOK_CERTIFICATES__<INDEX>__<PROPERTY>"),".\nEnvironment variables with the same index are grouped together to form the complete object. Note the use of the double underscores before the index and property."),(0,l.yg)("p",null,"Example:"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre",className:"language-shell"},'PACTFLOW_WEBHOOK_CERTIFICATES__0__LABEL="An example self signed certificate with content"\nPACTFLOW_WEBHOOK_CERTIFICATES__0__CONTENT="-----BEGIN CERTIFICATE-----\n      MIIDZDCCAkygAwIBAgIBATANBgkqhkiG9w0BAQsFADBCMRMwEQYKCZImiZPyLGQB\n      <REST OF CERTIFICATE>\n      jHT1Ty2CglM=\n      -----END CERTIFICATE-----"\nPACTFLOW_WEBHOOK_CERTIFICATES__1__LABEL="An example self signed certificate with a path"\nPACTFLOW_WEBHOOK_CERTIFICATES__1__PATH="/full/path/to/the/cert.pem"\n')),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Supported versions:")," From v1.14.0",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"saml-authentication"},"SAML authentication"),(0,l.yg)("hr",null),(0,l.yg)("p",null,"To configure more than one SAML identity provider, specify another set of the following environment variables with a ",(0,l.yg)("inlineCode",{parentName:"p"},"_2")," after the ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML")," prefix (and ",(0,l.yg)("inlineCode",{parentName:"p"},"_3")," for the third etc.). The ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_ISSUER")," is shared between all the SAML providers so does not need to be duplicated."),(0,l.yg)("p",null,"eg. For the second SAML identity provider set ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_2_AUTH_ENABLED"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_2_IDP_NAME")," etc and for the third ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_3_AUTH_ENABLED"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_3_IDP_NAME")," etc."),(0,l.yg)("h3",{id:"pactflow_saml_auth_enabled"},"PACTFLOW_SAML_AUTH_ENABLED"),(0,l.yg)("p",null,"Whether or not to enable SAML authentication."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_issuer"},"PACTFLOW_SAML_ISSUER"),(0,l.yg)("p",null,"The name of this application as it is known to the SAML IDP."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https://pactflow.io"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"http://pactflow.mycompany.com"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_name"},"PACTFLOW_SAML_IDP_NAME"),(0,l.yg)("p",null,"The display name of the SAML IDP. This value will be used as the login button label."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_logo"},"PACTFLOW_SAML_IDP_LOGO"),(0,l.yg)("p",null,"URL of a logo for IDP, to be displayed next to the login button."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_sso_target_url"},"PACTFLOW_SAML_IDP_SSO_TARGET_URL"),(0,l.yg)("p",null,"The URL to which the authentication request should be sent. This endpoint is on the identity provider."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_SAML_IDP_METADATA_URL is not set",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/omniauth/omniauth-saml#options"},"https://github.com/omniauth/omniauth-saml#options"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_cert_fingerprint"},"PACTFLOW_SAML_IDP_CERT_FINGERPRINT"),(0,l.yg)("p",null,'The SHA1 fingerprint of the certificate, e.g. "90:CC:16:F0:8D:...". This is provided from the identity provider when setting up the relationship.'),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if PACTFLOW_SAML_IDP_METADATA_URL is not set",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/omniauth/omniauth-saml#options"},"https://github.com/omniauth/omniauth-saml#options"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_id_attribute"},"PACTFLOW_SAML_IDP_ID_ATTRIBUTE"),(0,l.yg)("p",null,"The name of the SAML response attribute that uniquely and permanently identifies a user for the IDP."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_email_attribute"},"PACTFLOW_SAML_EMAIL_ATTRIBUTE"),(0,l.yg)("p",null,"The name of the SAML response attribute that contains the email address."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_name_attribute"},"PACTFLOW_SAML_NAME_ATTRIBUTE"),(0,l.yg)("p",null,"The name of the SAML response attribute that contains the full name."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_first_name_attribute"},"PACTFLOW_SAML_FIRST_NAME_ATTRIBUTE"),(0,l.yg)("p",null,"The name of the SAML response attribute that contains the first name."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_last_name_attribute"},"PACTFLOW_SAML_LAST_NAME_ATTRIBUTE"),(0,l.yg)("p",null,"The name of the SAML response attribute that contains the last name."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_idp_metadata_url"},"PACTFLOW_SAML_IDP_METADATA_URL"),(0,l.yg)("p",null,"The URL of the IDP's metadata endpoint. If this is set, then the PACTFLOW_SAML_IDP_SSO_TARGET_URL and PACTFLOW_SAML_IDP_CERT_FINGERPRINT can be skipped."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/omniauth/omniauth-saml#idp-metadata"},"https://github.com/omniauth/omniauth-saml#idp-metadata"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_name_identifier_format"},"PACTFLOW_SAML_NAME_IDENTIFIER_FORMAT"),(0,l.yg)("p",null,"Used during SP-initiated SSO. Describes the format of the username required by this application."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"urn:oasis:names:tc:SAML:2.0:nameid-format:persistent"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_saml_allowed_clock_drift"}
1,"PACTFLOW_SAML_ALLOWED_CLOCK_DRIFT"),(0,l.yg)("p",null,"To allow for a small amount of clock drift between PactFlow and the Identity Provider, the allowed clock drift may be specified. Its value must be given in a number (and/or fraction) of seconds. The value is added to the current time at which the response is validated, before it is tested against the NotBefore assertion."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"0"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"demo-authentication"},"Demo authentication"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_demo_auth_enabled"},"PACTFLOW_DEMO_AUTH_ENABLED"),(0,l.yg)("p",null,"Whether or not to enable authentication for demo users. For demonstration purposes only - not to be set to ",(0,l.yg)("inlineCode",{parentName:"p"},"true")," for production use."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"encryption"},"Encryption"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_master_encryption_key"},"PACTFLOW_MASTER_ENCRYPTION_KEY"),(0,l.yg)("p",null,"A randomly generated string which will be the master key for encrypting secrets and API tokens. Renamed from ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_MASTER_SECRETS_ENCRYPTION_KEY"),"."),(0,l.yg)("p",null,"Do not change or lose the value of this key. All encrypted data (secrets and API keys) will be unretrievable if this key is lost. Rotation is not currently supported but will be added in a future release."),(0,l.yg)("p",null,"To generate an appropriate value, run the following on Linux/Mac:"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre"},"env LC_CTYPE=C tr -dc '_A-Z-a-z-0-9!#$%&*+-\\\\.^_|~' < /dev/urandom | fold -w 32 | head -n 1\n")),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"eLM5xPxPu9ftDhA34ZUw2ry2okpMnOPCrA-twxLBUUk"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"secrets"},"Secrets"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_master_secrets_encryption_key"},"PACTFLOW_MASTER_SECRETS_ENCRYPTION_KEY"),(0,l.yg)("p",null,"Deprecated in favour of ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_MASTER_ENCRYPTION_KEY"),". If you have a previous installation of PactFlow with ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_MASTER_SECRETS_ENCRYPTION_KEY")," set, please rename it to ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_MASTER_ENCRYPTION_KEY"),"."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"content-security"},"Content Security"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_csp_allowed_sources"},"PACTFLOW_CSP_ALLOWED_SOURCES"),(0,l.yg)("p",null,"Space separated list of allowed content sources that should be allowed in addition to the hosts configured in the identity provider settings (eg. ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SAML_IDP_SSO_TARGET_URL"),"). This may be useful if you need additional assets on your instance of PactFlow. For example, if you need to support multiple redirects for SAML authentication, you need to add them here for PactFlow to generate the appropriate Content-Security-Policy to allow that to happen."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https://my-intermediate-idp-host.com"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"user-administration"},"User administration"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_admin_api_key"},"PACTFLOW_ADMIN_API_KEY"),(0,l.yg)("p",null,"The value of the X-Api-Key header required to make the HTTP call to provision the admin user."),(0,l.yg)("p",null,"To generate an appropriate value, run the following on Linux/Mac:"),(0,l.yg)("pre",null,(0,l.yg)("c
1ode",{parentName:"pre"},"env LC_CTYPE=C tr -dc '_A-Z-a-z-0-9!#$%&*+-\\\\.^_|~' < /dev/urandom | fold -w 32 | head -n 1\n")),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"A-Za-z0-9!#$%&*+-^_``|~."),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"4wmplZfucVG-LdIHD9L"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://tools.ietf.org/html/rfc7230#section-3.2.6"},"https://tools.ietf.org/html/rfc7230#section-3.2.6"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"domain"},"Domain"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_allow_dangerous_contract_modification"},"PACTFLOW_ALLOW_DANGEROUS_CONTRACT_MODIFICATION"),(0,l.yg)("p",null,"Whether or not to allow the pact content for an existing consumer version to be modified. It is strongly recommended that this is set to false,\nas allowing modification makes the results of can-i-deploy unreliable. When this is set to false as recommended, each commit must publish pacts\nwith a unique version number."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Supported versions:")," From v1.14.0",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," For new installations of v1.14.0 and later, this defaults to ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),".",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/versioning"},"https://docs.pact.io/versioning"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_use_first_tag_as_branch"},"PACTFLOW_USE_FIRST_TAG_AS_BRANCH"),(0,l.yg)("p",null,"When the value is ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", the first tag applied to a version (within 10 seconds)\nwill be used to populate the ",(0,l.yg)("inlineCode",{parentName:"p"},"branch")," property of the version."),(0,l.yg)("p",null,"This is to assist in the migration from using tags to track branches to using the branches feature."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_create_deployed_versions_for_tags"},"PACTFLOW_CREATE_DEPLOYED_VERSIONS_FOR_TAGS"),(0,l.yg)("p",null,"When the value is ",(0,l.yg)("inlineCode",{parentName:"p"},"true")," and a tag is created, if there is an environment with the name of the newly created tag, a deployed version is\nalso created for the pacticipant version."),(0,l.yg)("p",null,"This is to assist in the migration from using tags to track deployments to using the deployed and released versions feature."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Supported versions:")," From v1.14.0",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://docs.pact.io/pact_broker/recording_deployments_and_releases/"},"https://docs.pact.io/pact_broker/recording_deployments_and_releases/"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"badges"},"Badges"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_shields_io_base_url"}
1,"PACTFLOW_SHIELDS_IO_BASE_URL"),(0,l.yg)("p",null,"The URL of the free service that is used to generate the build badges. Note that the badge files are served via a redirect in the browser, so there is no request made from the PactFlow application to the shields server."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https://img.shields.io"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://shields.io"},"https://shields.io"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"resources"},"Resources"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_base_url"},"PACTFLOW_BASE_URL"),(0,l.yg)("p",null,"The base url, including HTTP scheme and any application context path, at which the PactFlow application will be publicly\naccessible. It should not include a trailing slash. If there are multiple interfaces on which the application will be addressed,\nlist all the base URLs separated by spaces."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"https://pactflow.mycompany.com https://pactflow.internal.mycompany.com"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_http_port"},"PACTFLOW_HTTP_PORT"),(0,l.yg)("p",null,"The HTTP port on which the PactFlow application will be exposed on the Docker container. Must be greater than 1024."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"9292"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_session_length"},"PACTFLOW_SESSION_LENGTH"),(0,l.yg)("p",null,"The number of seconds after which the user needs to re-authenticate with the IDP. Default is 1 week."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"604800"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_session_inactivity_timeout"},"PACTFLOW_SESSION_INACTIVITY_TIMEOUT"),(0,l.yg)("p",null,"The number of seconds of inactivity after which the user needs to re-authenticate with the IDP. By default, this will be set to the value of the ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_SESSION_LENGTH"),", effectively disabling the feature, unless a value is specified by the user."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"604800"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_cookie_secret"},"PACTFLOW_COOKIE_SECRET"),(0,l.yg)("p",null,"The secret used to encrypt the rack.session cookie.\nTo generate an appropriate value, run the following on Linux/Mac:"),(0,l.yg)("pre",null,(0,l.yg)("code",{parentName:"pre"},"LC_ALL=C tr -dc '_A-Z-a-z-0-9!#$%&*+-\\\\.^_|~' < /dev/urandom | fold -w 64 | head -n 1\n")),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"X-sbeCpAUgO-8FRtKxYrVhgZ2hIJhPuzCh_89PypYrI"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_old_cookie_secret"},"PACTFLOW_OLD_COOKIE_SECRET"),(0,l.yg)("p",null,"The previous secret - used when rotating the rack.session cookie secret."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_require_https"},"PACTFLOW_REQUIRE_HTTPS"),(0,l.yg)("p",null,"When set to ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", the header ",(0,l.yg)("inlineCode",{parentName:"p"},"Strict-Transport-Security: max-age=31536000 ; includeSubDomains")," is added to ensure connections are made over HTTPS, and the ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_BASE_URL")," is validated to ensure it starts with https."),(0,l.yg)("p",null,"This value should never be set to false in a production environment. It should only ever be set to false for local testing or demonstration purposes where an SSL certificate is not available."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"ssl_cert_file"},"SSL_CERT_FILE"),(0,l.yg)("p",null,"The PEM certificate file to use if the webhooks have to connect to servers that use self signed certificates."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"ssl_cert_dir"},"SSL_CERT_DIR"),(0,l.yg)("p",null,"The PEM certificate directory to use if the webhooks have to connect to servers that use self signed certificates."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"http_proxy"},"http_proxy"),(0,l.yg)("p",null,"HTTP proxy used when making outgoing HTTP requests"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"https_proxy"},"https_proxy"),(0,l.yg)("p",null,"HTTPS proxy used when making outgoing HTTP requests"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"no_proxy"},"no_proxy"),(0,l.yg)("p",null,"The hosts for which to not use a proxy"),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_use_hal_browser"},"PACTFLOW_USE_HAL_BROWSER"),(0,l.yg)("p",null,"Whether or not to enable the embedded HAL Browser."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"https://github.com/mikekelly/hal-browser"},"https://github.com/mikekelly/hal-browser"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"miscellaneous"},"Miscellaneous"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"tz"},"TZ"),(0,l.yg)("p",null,"The timezone in which to display dates for server side rendered pages."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," true",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"More information:")," ",(0,l.yg)("a",{parentName:"p",href:"/docs/on-premises/environment-variables/timezones"},"Valid timezones"),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"api-tokens"},"API Tokens"),(0,l.yg)("hr",null),(0,l.yg)("h3",{id:"pactflow_api_token_auth_enabled"},"PACTFLOW_API_TOKEN_AUTH_ENABLED"),(0,l.yg)("p",null,"Whether or not to enable the inbuilt PactFlow API tokens used for bearer authentication. Used to disable API tokens if an external Identify Provider is configured for API authentication."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_api_token_encryption_enabled"},"PACTFLOW_API_TOKEN_ENCRYPTION_ENABLED"),(0,l.yg)("p",null,"Enables encryption of API token values in the database. Requires ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_API_TOKEN_IV")," and ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_MASTER_ENCRYPTION_KEY")," to also be set."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," false",(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"pactflow_api_token_iv"},"PACTFLOW_API_TOKEN_IV"),(0,l.yg)("p",null,"If ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_API_TOKEN_ENCRYPTION_ENABLED")," is set to ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", then this value must contain a base 64 encoded string of random 16 bytes for the\nencryption initialization vector."),(0,l.yg)("p",null,"To generate an appropriate value, run the following on Linux/Mac:"),(0,l.yg)("pre",null,(0,l.yg)("c
1ode",{parentName:"pre"},"head < /dev/random -c 16 | base64\n")),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required:")," if ",(0,l.yg)("inlineCode",{parentName:"p"},"PACTFLOW_API_TOKEN_ENCRYPTION_ENABLED")," is set to ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"JUVDdnRzLXZyWHA7UF93RAo="),(0,l.yg)("br",null)),(0,l.yg)("h2",{id:"observability"},"Observability"),(0,l.yg)("hr",null),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"otel_exporter_otlp_endpoint"},"OTEL_EXPORTER_OTLP_ENDPOINT"),(0,l.yg)("p",null,"The OTLP (HTTP) endpoint to export spans to."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required"),": false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Example"),": ",(0,l.yg)("inlineCode",{parentName:"p"},"https://172.23.92.124:4318"),(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Allowed values:")," ",(0,l.yg)("inlineCode",{parentName:"p"},"true"),", ",(0,l.yg)("inlineCode",{parentName:"p"},"false"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"otel_deployment_environment"},"OTEL_DEPLOYMENT_ENVIRONMENT"),(0,l.yg)("p",null,"The name of the deployment environment (for example, ",(0,l.yg)("inlineCode",{parentName:"p"},"production"),")."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required"),": false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default"),": ",(0,l.yg)("inlineCode",{parentName:"p"},"dev"),(0,l.yg)("br",null)),(0,l.yg)("h3",{id:"otel_log_level"},"OTEL_LOG_LEVEL"),(0,l.yg)("p",null,"Log level for the OpenTelemetry SDK instrumentation (such as ",(0,l.yg)("inlineCode",{parentName:"p"},"debug")," or ",(0,l.yg)("inlineCode",{parentName:"p"},"info"),")."),(0,l.yg)("p",null,(0,l.yg)("strong",{parentName:"p"},"Required"),": false",(0,l.yg)("br",null),"\n",(0,l.yg)("strong",{parentName:"p"},"Default"),": ",(0,l.yg)("inlineCode",{parentName:"p"},"info"),(0,l.yg)("br",null)))}d.isMDXComponent=!0}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.