All configuration is through environment variables. Organised by service.
| Type |
Default |
Required |
string |
postgresql://postgres:postgres@localhost:5432/undolog_dev |
Yes |
PostgreSQL connection string for effect storage, sessions, approvals, and tool registry.
Format: postgresql://[user[:password]@][host][:port][/database][?params]
| Type |
Default |
Required |
string |
0.0.0.0:50051 |
Yes |
IP:port for the tonic gRPC server that handles Intercept, Commit, Fail, Approve, Reject RPCs.
| Type |
Default |
Required |
string |
0.0.0.0:9090 |
Yes |
IP:port for the HTTP health endpoint (GET / → {"status":"ok","service":"undolog-engine"}).
| Type |
Default |
Valid Values |
string |
info |
trace, debug, info, warn, error |
Log level for the Rust engine. Used as the default directive for tracing_subscriber::EnvFilter.
| Type |
Default |
Description |
uint64 |
60 |
Interval in seconds between tool registry refreshes from the database. The engine loads undolog_tool_registry into an in-memory cache on startup and refreshes periodically at this interval. |
| Type |
Default |
Description |
uint32 |
3 |
Maximum number of attempts to acquire a PostgreSQL advisory lock for a call signature before returning AdvisoryLockTimeout. |
| Type |
Default |
Description |
uint64 |
100 |
Delay in milliseconds between advisory lock acquisition attempts. |
| Type |
Default |
Required |
string |
:8080 |
Yes |
HTTP bind address for the MCP proxy server.
| Type |
Default |
Description |
int |
15 |
Maximum seconds the server waits for request headers. |
| Type |
Default |
Description |
int |
15 |
Maximum seconds the server waits while writing responses. |
| Type |
Default |
Description |
int |
30 |
Maximum seconds for graceful shutdown before force closing connections. |
| Type |
Default |
Description |
int |
30 |
Maximum seconds for tool execution and engine RPC calls. Applied as a context timeout on the interception flow. |
| Type |
Default |
Description |
int |
128 |
Per-organisation SSE channel buffer size for dashboard event delivery. Events beyond this size are dropped (non-blocking). |
| Type |
Default |
Required |
string |
localhost:50051 |
Yes |
Address of the Rust UndoLog Engine gRPC endpoint. Used by the proxy to forward interception, commit, fail, approve, and reject requests.
| Type |
Default |
Required |
string |
"" |
No (required for tool execution) |
HTTP endpoint that receives forwarded tool calls. When empty, tool execution is not available.
| Type |
Default |
Valid Values |
string |
info |
debug, info, warn, error |
Log level for the proxy server. Shared env var name across both engine and proxy.
| Type |
Default |
Description |
string |
"" |
Comma-separated key=org_id pairs for API key authentication. Example: sk-abc123=org-xyz,sk-def456=org-uvw |
| Type |
Default |
Services |
string |
info |
Engine, Proxy |
Shared log level variable. When set, affects both the Rust engine and Go proxy.
| Variable |
Service |
Type |
Default |
Required |
DATABASE_URL |
Engine |
string |
postgresql://postgres:postgres@localhost:5432/undolog_dev |
Yes |
UNDOLOG_ENGINE_GRPC_ADDR |
Engine |
string |
0.0.0.0:50051 |
Yes |
UNDOLOG_ENGINE_HEALTH_ADDR |
Engine |
string |
0.0.0.0:9090 |
Yes |
UNDOLOG_LOG_LEVEL |
Engine, Proxy |
string |
info |
No |
UNDOLOG_REGISTRY_REFRESH_SECS |
Engine |
uint64 |
60 |
No |
UNDOLOG_LOCK_MAX_ATTEMPTS |
Engine |
uint32 |
3 |
No |
UNDOLOG_LOCK_RETRY_MS |
Engine |
uint64 |
100 |
No |
UNDOLOG_PROXY_LISTEN_ADDR |
Proxy |
string |
:8080 |
Yes |
UNDOLOG_PROXY_READ_TIMEOUT_SECS |
Proxy |
int |
15 |
No |
UNDOLOG_PROXY_WRITE_TIMEOUT_SECS |
Proxy |
int |
15 |
No |
UNDOLOG_PROXY_SHUTDOWN_TIMEOUT_SECS |
Proxy |
int |
30 |
No |
UNDOLOG_PROXY_REQUEST_TIMEOUT_SECS |
Proxy |
int |
30 |
No |
UNDOLOG_PROXY_DASHBOARD_EVENT_CHAN_SIZE |
Proxy |
int |
128 |
No |
UNDOLOG_PROXY_ENGINE_GRPC_ADDR |
Proxy |
string |
localhost:50051 |
Yes |
UNDOLOG_PROXY_UPSTREAM_TOOL_URL |
Proxy |
string |
"" |
No |
UNDOLOG_PROXY_API_KEYS |
Proxy |
string |
"" |
No |