Skip to main content

Security environment variables

Use these security environment variables with your Self-hosted Retool deployment.

Only configure environment variables when needed. You can configure many environment variables from your organization's Settings rather than directly editing your deployment's configuration file.

Environment variables take effect only once the change is applied to your deployment, and where you set them depends on how Retool was deployed.

  • Terraform blueprints. Set the variable in retool_helm_extra_values in main.tf, then run terraform apply. Editing Helm values directly on a blueprint-managed instance is overwritten by the next apply.
  • Helm. Set the variable in your values.yaml, then run helm upgrade. That command restarts the affected pods as part of applying the new values, so restarting pods without re-running it doesn't pick up the change.
  • Docker Compose. Set the variable in docker.env, then run sudo docker compose up -d.

ENABLE_CLIENT_SIDE_CUSTOM_AUTH_BROWSER_CALLS

Whether to allow custom authentication steps for resources that make REST API calls directly from the browser. If true, these requests include all browser credentials, even cross-origin calls.

Type boolean
ConfigurabilityUpdate the deployment's configuration file.
Required Optional
Defaultfalse
Examples
ENABLE_CLIENT_SIDE_CUSTOM_AUTH_BROWSER_CALLS=true

ENCRYPTION_KEY

The encryption key used to encrypt data stored in the PostgreSQL database (e.g., database credentials, SSH keys, etc). Must contain only ASCII characters (required from version 3.332.4). If your key contains non-ASCII characters, rotate it before upgrading. If you change this key without rotating, you will lose access to all resources created before the change.

Type string
Format Plain Text
ConfigurabilityUpdate the deployment's configuration file.
Required Optional
Defaultnull
Examples
ENCRYPTION_KEY=key

SCOPED_SECRETS

Whether to restrict secrets using naming enforcement. When enabled, use the naming convention scoped__resources__<folder>__<secret> to restrict secrets to specific resources and folders. For example, scoped__resources__folder1__secret1 restricts secret1 to resources within folder1.

Type boolean
ConfigurabilityUpdate the deployment's configuration file.
Required Optional
Defaultfalse
Examples
SCOPED_SECRETS=true

USE_GCM_ENCRYPTION

Whether to use AES-192-GCM authenticated encryption method instead of AES-192-CBC. If set to true, you must also set ENCRYPTION_KEY.

Type boolean
ConfigurabilityUpdate the deployment's configuration file.
Required Optional
Defaultfalse
Examples
USE_GCM_ENCRYPTION=true