Skip to Content
ReferenceAll Environment Variables

All Environment Variables

Alphabetical reference of Pilot’s environment variables. For grouped explanations with examples, see Configuration.

Core

VariableDefaultDescription
KAFKA_AUTO_OFFSET_RESETlatestNo effect; kept for compatibility
KAFKA_BOOTSTRAP_SERVERSlocalhost:9092Kafka broker addresses (comma-separated)
LOG_LEVELINFOLog level: DEBUG, INFO or WARN (case-insensitive). Any other value uses INFO
METADATA_UPDATE_INTERVAL10sMetadata collection frequency
PORT8080HTTP server port
UI_PATH./ui/distPath to UI assets (overridden when embedded)

Server TLS

VariableDefaultDescription
SERVER_TLS_CERT_FILE""Path to TLS certificate file (PEM)
SERVER_TLS_ENABLEDfalseEnable HTTPS for the Pilot HTTP server
SERVER_TLS_KEY_FILE""Path to TLS private key file (PEM)
SERVER_TLS_MIN_VERSION1.2Minimum TLS version: 1.2 or 1.3

Kafka Security

VariableDefaultDescription
KAFKA_SASL_KERBEROS_CONFIG_FILE""Path to Kerberos config file (krb5.conf)
KAFKA_SASL_KERBEROS_KEYTAB_FILE""Path to Kerberos keytab file
KAFKA_SASL_KERBEROS_PASSWORD""Kerberos password (if not using keytab)
KAFKA_SASL_KERBEROS_REALM""Kerberos realm
KAFKA_SASL_KERBEROS_SERVICE_NAMEkafkaKerberos service name
KAFKA_SASL_KERBEROS_USERNAME""Kerberos principal name
KAFKA_SASL_MECHANISMPLAINSASL mechanism: PLAIN, SCRAM-SHA-256, SCRAM-SHA-512, GSSAPI, OAUTHBEARER
KAFKA_SASL_OAUTH_CLIENT_ID""OAuth client ID
KAFKA_SASL_OAUTH_CLIENT_SECRET""OAuth client secret
KAFKA_SASL_OAUTH_EXTENSIONS""SASL OAUTHBEARER extensions sent to the brokers (comma-separated key=value); not sent to the token endpoint
KAFKA_SASL_OAUTH_SCOPE""OAuth scope
KAFKA_SASL_OAUTH_TOKEN_ENDPOINT_URL""OAuth token endpoint URL
KAFKA_SASL_PASSWORD""SASL password (PLAIN/SCRAM)
KAFKA_SASL_USERNAME""SASL username (PLAIN/SCRAM)
KAFKA_SECURITY_PROTOCOLPLAINTEXTSecurity protocol: PLAINTEXT, SSL, SASL_PLAINTEXT, SASL_SSL
KAFKA_SSL_CA_CERT_FILE""Path to CA certificate file. Trusted for broker TLS and, with OAUTHBEARER, for the HTTPS token endpoint (in addition to the system roots)
KAFKA_SSL_CA_CERT_PEM""CA certificate PEM content (inline). Same trust scope as KAFKA_SSL_CA_CERT_FILE
KAFKA_SSL_CERT_FILE""Path to the client certificate (PEM, chain allowed) for mutual TLS. Needs a key via KAFKA_SSL_KEY_FILE or KAFKA_SSL_KEY_PEM. See Mutual TLS
KAFKA_SSL_CERT_PEM""Client certificate PEM content (inline). Used instead of KAFKA_SSL_CERT_FILE when both are set
KAFKA_SSL_ENABLED_PROTOCOLSTLSv1.2,TLSv1.3Not applied. The Kafka client uses TLS 1.2 or 1.3
KAFKA_SSL_INSECURE_SKIP_VERIFYfalseSkip TLS certificate verification for brokers and the OAUTHBEARER token endpoint (insecure)
KAFKA_SSL_KEY_FILE""Path to the client private key (PEM: PKCS#1, PKCS#8, EC, or PKCS#8 encrypted) for mutual TLS. Needs a certificate via KAFKA_SSL_CERT_FILE or KAFKA_SSL_CERT_PEM
KAFKA_SSL_KEY_PASSWORD""Password of a PKCS#8 encrypted client key (BEGIN ENCRYPTED PRIVATE KEY). Ignored, with a warning, when the key is not encrypted
KAFKA_SSL_KEY_PEM""Client private key PEM content (inline). Used instead of KAFKA_SSL_KEY_FILE when both are set
KAFKA_SSL_VERIFY_HOSTNAMEtrueVerify broker hostname against certificate. false skips only the hostname match; the certificate chain is still verified

Balance Engine

VariableDefaultDescription
PILOT_BALANCE_FLOOR"" (off)Optional minimum difference. Set, for example, bytes=2MB/s disk=2GiB to ignore smaller per-broker differences on quiet test clusters: a rate or disk metric is then balanced only when some broker is at least that far from its equal share. Settings left out use bytes=2MB/s and disk=2GiB; message rates follow the byte rate at the average message size unless msgs= is given (msgs=auto is accepted). Leader and follower counts are not affected. Unset or off balances differences of any size. An invalid value stops Pilot at startup. See Minimum Difference
PILOT_BALANCE_MIN_RF0Minimum replication factor enforcement (0 = disabled)
PILOT_BALANCE_RACK_AWAREtrueEnforce rack-aware partition placement
PILOT_BALANCE_THRESHOLD5.0Applies per broker and load: Pilot moves partitions only when a broker stays more than twice this percentage from its fair share (10% at the default), then evens that load until every broker is within this percentage, give or take one partition. Must be greater than 0. See Even Balance
PILOT_BALANCE_WORKERS0Candidate-generation goroutines (0 = auto, uses GOMAXPROCS); does not affect proposal output
PILOT_BROKER_PROFILE""Broker capacity, e.g. network=10Gbit/s disk=2TiB, plus optional rack=, host= or broker= selector rules separated by ;. Reports broker network and disk utilization and does not change balancing; fair shares do not depend on it, and capacity-based overload protection is planned. With network= set, settling after moves ends on evidence instead of a timer. An invalid value stops Pilot at startup. See Broker Profiles
PILOT_BROKER_PROFILE_FILE""Path to a broker profile file (same rules, one per line, # comments). Set only one of PILOT_BROKER_PROFILE and PILOT_BROKER_PROFILE_FILE

Movement Control

VariableDefaultDescription
PILOT_MOVE_MAX_PER_BROKER20Max concurrent moves per broker
PILOT_PROPOSAL_MAX_PARTITIONS0Max partitions a single proposal may move (0 = unlimited). Whole transitions with the lowest marginal benefit per movement cost are dropped first, then the remaining benefit is checked again. Critical/RF-fix moves are always kept

Throttle

VariableDefaultDescription
PILOT_THROTTLE_MANAGEDtruePilot manages replication throttles. false marks proposals unsafe to apply (throttles_externally_managed) and skips the startup cleanup of leftover throttles
PILOT_THROTTLE_MAX_RATE_MB1000Highest throttle that can be set at runtime, in MB/s. Must not be below PILOT_THROTTLE_RATE_MB
PILOT_THROTTLE_RATE_MB50Base throttle rate in MB/s. Must be >= 1 when PILOT_THROTTLE_MANAGED=true (0 or negative is rejected at startup)

Self-Healing

VariableDefaultDescription
PILOT_HEAL_CRITICAL_ENABLEDfalseEnable critical fixes healing (URP, rack)
PILOT_HEAL_CRITICAL_INTERVAL5mCritical healing check interval
PILOT_HEAL_DRY_RUNtrueSimulate healing without applying changes
PILOT_HEAL_ENABLEDfalseEnable activity-based healing
PILOT_HEAL_INTERVAL30mActivity healing interval
PILOT_HEAL_MAX_PARTITIONS_PER_RUN0Max partitions moved per healing cycle (0 = unlimited)
PILOT_HEAL_RF_ENABLEDfalseEnable replication factor increase healing
PILOT_HEAL_RF_INTERVAL15mRF healing check interval
PILOT_HEAL_WINDOW_END-1Healing window end hour (0-23, -1 = always)
PILOT_HEAL_WINDOW_START-1Healing window start hour (0-23, -1 = always)

Exclusions & Observability

VariableDefaultDescription
PILOT_BROKER_EXPIRY1hHow long a broker must stay continuously unavailable and unreferenced by any partition replica set before Pilot forgets it. Removes it from the tracked broker union and tombstones its persisted state so a permanently scaled-down broker stops inflating TotalBrokers and blocking rolling restarts. Set to 0 to disable. A broker that reappears in metadata is tracked again.
PILOT_EXCLUDE_TOPICS""Comma-separated topic regexes to leave out of proposals and self-healing (unanchored)
PILOT_FOLLOWER_LAG_WARNING_THRESHOLD1000Warning threshold for total follower lag. When total cluster follower lag exceeds this value, the health endpoint reports a warning.

Consumer Groups

VariableDefaultDescription
PILOT_CONSUMER_GROUP_COLLECTION_ENABLEDtrueEnable background consumer group collection
PILOT_CONSUMER_GROUP_COLLECTION_INTERVAL15sCollection interval

CORS

VariableDefaultDescription
CORS_ALLOWED_ORIGINS*Allowed origins (comma-separated)
CORS_ALLOWED_METHODSGET,POST,PUT,DELETE,OPTIONSAllowed methods (comma-separated)
CORS_ALLOWED_HEADERS*Allowed request headers (comma-separated)
CORS_EXPOSED_HEADERS""Response headers exposed to the browser (comma-separated)
CORS_ALLOW_CREDENTIALSfalseAllow credentials on cross-origin requests
CORS_MAX_AGE0Preflight cache duration in seconds

An empty list means *.

Pilot Agent

VariableDefaultDescription
PILOT_AGENT_BOOTSTRAP_TOKENrequiredMaster token for agent certificate enrollment. Required when using auto-TLS. Generate with openssl rand -hex 32
PILOT_AGENT_DATA_DIR/data/agent-certsDirectory for auto-generated CA and certificates
PILOT_AGENT_ENABLEDfalseEnable the agent gRPC server
PILOT_AGENT_GRPC_PORT9190Port for agent gRPC connections
PILOT_AGENT_INSECUREfalseAllow gRPC server without TLS (development only)
PILOT_AGENT_TLS_CA(auto)Path to CA certificate for verifying agents
PILOT_AGENT_TLS_CERT(auto)Path to server TLS certificate
PILOT_AGENT_TLS_KEY(auto)Path to server TLS private key
PILOT_AGENT_TLS_SANS""Extra DNS names or IP addresses for auto-generated server certificate (comma-separated)
PILOT_DEPLOY_ALLOW_HTTPfalseAllow SSH deploy endpoints over plain HTTP. By default, deploy endpoints that transmit SSH credentials require HTTPS
PILOT_TRUSTED_PROXIES"" (trust all)Comma- or space-separated CIDRs or IPs of reverse proxies whose X-Forwarded-Proto and X-Forwarded-Host Pilot trusts, for the HTTPS check on SSH deploy endpoints and the URLs given to agents. Unset trusts every source; set it when clients can reach Pilot without the proxy. Invalid entries are skipped with a warning
PILOT_AGENT_DOWNLOAD_URLhttps://downloads.calinora.io/agent/v{version}/pilot-agent-linux-{arch}Upstream URL template for downloading agent binaries. Supports {version} and {arch} placeholders. Override for corporate proxies (JFrog, Nexus)
PILOT_AGENT_BINARY_DIR""Local directory for air-gapped mode. When set, Pilot reads agent binaries from this directory and does not download from the upstream URL
PILOT_AGENT_BINARY_CACHE_DIR{data-dir}/binariesDirectory where downloaded agent binaries are cached on disk
PILOT_AGENT_SSH_KNOWN_FINGERPRINTS""Comma-separated list of trusted SSH host-key fingerprints in canonical OpenSSH form (SHA256:<base64>). Pilot merges this list into every hop of an agent deploy that does not supply its own knownFingerprints. Deploys without any trust source (fingerprint, captured host key, or explicit allowInsecureHostKey) are refused. See agent SSH host key verification

Pilot Agent (Agent-Side)

These variables configure the agent binary deployed alongside each Kafka broker. They are set on the agent, not on the Pilot server.

VariableDefaultDescription
AGENT_BOOTSTRAP_TOKEN""Token for certificate enrollment (master token or single-use enrollment token)
AGENT_BOOTSTRAP_URL""URL for certificate bootstrapping (e.g., http://pilot:8080/api/v1/agents/bootstrap-cert)
AGENT_BROKER_ID0Kafka broker ID. Auto-detected from server.properties or meta.properties if not set
AGENT_CA""Path to CA certificate for server verification
AGENT_CERT""Path to mTLS client certificate
AGENT_INSECUREfalseAllow running without TLS (development only)
AGENT_KEY""Path to mTLS client private key
AGENT_LOG_DIRS""Kafka log directories (comma-separated). Auto-detected from the running broker process if not set
AGENT_NODE_ID(hostname)Node identifier (defaults to system hostname)
AGENT_SERVER""Pilot gRPC server address (e.g., pilot:9190)
AGENT_KAFKA_SERVICE_UNIT""Override systemd unit name for broker lifecycle commands (e.g., my-kafka.service)
AGENT_KAFKA_START_CMD""Override broker start command
AGENT_KAFKA_STOP_CMD""Override broker stop command
AGENT_ALLOW_RESTARTtruePermit restart/stop/start commands. Set to false to disable broker lifecycle management on this agent
AGENT_DOCKER_CONTAINER""Docker container name to manage for lifecycle operations (docker stop/start/restart). Required for containerized brokers when using pid: "host"

MCP Server

VariableDefaultDescription
PILOT_MCP_ENABLEDtrueEnable Model Context Protocol server

AI Chat

VariableDefaultDescription
PILOT_CHAT_API_KEY""API key for chat provider (required if chat enabled)
PILOT_CHAT_APPROVAL_TIMEOUT5mUser approval window for mutations
PILOT_CHAT_BASE_URL""Override API base URL. Azure OpenAI: https://<resource>.openai.azure.com/openai (trailing /openai required)
PILOT_CHAT_CONVERSATION_TTL24hConversation expiry time
PILOT_CHAT_ENABLEDfalseEnable AI chat assistant
PILOT_CHAT_MAX_CONTEXT_TOKENS30000Estimated context-token budget per request (history + tool catalog); min 4096
PILOT_CHAT_MAX_CONVERSATIONS10Max conversations per user
PILOT_CHAT_MAX_TOKENS4096Max response tokens
PILOT_CHAT_MAX_TOOL_RESULT_CHARS8000Max characters of each tool result kept in conversation context; min 1000
PILOT_CHAT_MODELclaude-haiku-4-5-20251001AI model to use. For Azure OpenAI, the deployment name
PILOT_CHAT_OPENAI_APIautoOpenAI only: auto, responses, or chat_completions. auto uses Responses for GPT-5/GPT-6 model names and Chat Completions otherwise
PILOT_CHAT_PROVIDERanthropicChat provider: anthropic or openai
PILOT_CHAT_RATE_LIMIT20Messages per minute per user

The chat HTTP client honors the standard Go SSL_CERT_FILE / SSL_CERT_DIR variables; see AI Chat configuration for Azure OpenAI and corporate CA setup.

License

VariableDefaultDescription
LICENSE_FETCH_INTERVAL1hAuto-fetch interval
LICENSE_FETCH_SUBSCRIPTION_ID""Subscription ID for auto-fetch
LICENSE_FETCH_TOKEN""Per-customer fetch token
LICENSE_FETCH_URLhttps://license.calinora.io/api/license/fetchLicense fetch endpoint
LICENSE_STRING""JWT license token

Audit Logging

VariableDefaultDescription
AUDIT_ENABLEDtrueEnable audit event logging
AUDIT_PARTITIONS1Audit topic partition count
AUDIT_REPLICATION_FACTOR0Audit topic replication factor for a new topic (0 uses the broker default; a default of 1 is raised to 3, or 2 on a two-broker cluster)
AUDIT_RETENTION_MS2592000000Audit topic retention in milliseconds (default 30 days)
AUDIT_STORE_MAX_ITEMS10000Max audit events kept in memory for the UI
AUDIT_TOPIC__pilot_audit_logKafka topic name for audit events
AUDIT_USER_ID_CLAIMupnIdentity recorded as userId: upn (default), sub or email. Other values fall back to upn, then sub, then email

Authentication (UI & API)

Global

VariableDefaultDescription
AUTH_COOKIE_DOMAIN""Cookie domain scope
AUTH_COOKIE_NAMEpilot_sessionSession cookie name
AUTH_COOKIE_SECRET""HMAC signing key (auto-generated in dev)
AUTH_COOKIE_SECUREtrueHTTPS-only cookies
AUTH_DEBUG_EXPOSE_TOKENSfalseExpose raw tokens in /auth/me (debug only)
AUTH_SESSION_TTL12hSession time-to-live

Per-Provider (AUTH_<PROVIDER>_*)

Replace <PROVIDER> with ENTRAID, GOOGLE, GITHUB, or OIDC. AUTH_<PROVIDER>_ENABLED must be present in the environment for the rest of a provider’s block to be read.

VariableDefaultDescription
AUTH_<PROVIDER>_ALLOWED_AUDIENCES<client-id>Allowed token audiences (comma-separated), matched against a token’s aud and azp. Defaults to the client id (Entra ID also accepts api://<client-id>) so a bearer JWT must be minted for this deployment. A provider with no client id and no allowlist rejects every bearer JWT
AUTH_<PROVIDER>_ALLOWED_DOMAINS""Allowed email domains (comma-separated). Matched against the email resolved via AUTH_<PROVIDER>_EMAIL_CLAIM
AUTH_<PROVIDER>_ALLOWED_GROUPS""Allowed groups (comma-separated). Matched against the groups resolved via AUTH_<PROVIDER>_GROUPS_CLAIM
AUTH_<PROVIDER>_ALLOWED_ORGANIZATIONS""Allowed organizations (comma-separated)
AUTH_<PROVIDER>_ALLOW_SIGN_UPtrueAllow new user registration
AUTH_<PROVIDER>_API_URL""Userinfo endpoint URL
AUTH_<PROVIDER>_AUTH_URL""OAuth authorization URL
AUTH_<PROVIDER>_AUTO_LOGINfalseAuto-redirect to provider login
AUTH_<PROVIDER>_CLIENT_ID""OAuth client ID
AUTH_<PROVIDER>_CLIENT_SECRET""OAuth client secret
AUTH_<PROVIDER>_EMAIL_CLAIM""Claim used for the session email and ALLOWED_DOMAINS. Consulted first when set; default chain email, preferred_username, upn is the fallback
AUTH_<PROVIDER>_ENABLEDfalseEnable this provider
AUTH_<PROVIDER>_GROUPS_CLAIM""Claim used for session groups and ALLOWED_GROUPS. Consulted first when set; default chain groups, roles, role, group is the fallback (first present non-empty key wins). Accepts an array or a single string. AD FS: roles
AUTH_<PROVIDER>_ISSUER""OIDC issuer. Trust anchor for bearer JWT and id_token verification; required for local signature checking. A trailing slash is ignored when matching a token’s iss
AUTH_<PROVIDER>_JWKS_CACHE_TTL15mHow long fetched signing keys are cached
AUTH_<PROVIDER>_JWKS_URL""JWKS endpoint. Overrides discovery from the issuer (still requires AUTH_<PROVIDER>_ISSUER). Must be an absolute http/https URL; anything else is ignored
AUTH_<PROVIDER>_NAMEAutoDisplay name
AUTH_<PROVIDER>_SCOPESopenid email profileOAuth scopes
AUTH_<PROVIDER>_TOKEN_URL""OAuth token URL
AUTH_<PROVIDER>_USERNAME_CLAIM""Claim used for the session username (UPN). Consulted first when set; default chain upn, preferred_username is the fallback. AD FS: upn
AUTH_<PROVIDER>_USE_PKCEtrueEnable PKCE
AUTH_<PROVIDER>_USE_REFRESH_TOKENtrueEnable refresh tokens

Personal Access Tokens

VariableDefaultDescription
AUTH_PAT_ENABLEDfalseEnable PAT creation and validation (requires auth and AUTH_PAT_HASH_SECRET)
AUTH_PAT_HASH_SECRET""Required for PATs. HMAC-SHA256 secret for token hashing. Must be stable and persistent.
AUTH_PAT_MAX_PER_USER10Maximum tokens per user

Entra ID Convenience

VariableDefaultDescription
AUTH_ENTRAID_TENANT""Azure tenant ID (auto-derives auth/token/issuer URLs)
Last updated on