> For the complete documentation index, see [llms.txt](https://documentation.opencrvs.org/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://documentation.opencrvs.org/v2.1/technical/guides/installation/deploy-set-up-a-server-hosted-environment/create-a-github-environment/environment-secrets-and-variables-explained.md).

# Environment secrets and variables explained

#### **Global repository secrets**

<table><thead><tr><th width="295">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>DOCKER_USERNAME</td><td><p>Your <a href="https://hub.docker.com/">Dockerhub</a> username to access the container registry. If you are using a different container registry, you will need to manually edit the deploy.yml at OpenCRVS Countryconfig repository appropriately.<br></p><p>NOTE: Dockerhub is used to store only OpenCRVS Countryconfig docker images. All Core images are stored in GitHub Packages</p></td></tr><tr><td>DOCKER_TOKEN</td><td>Your <a href="https://hub.docker.com/">Dockerhub</a> access token.</td></tr><tr><td>DOCKERHUB_ACCOUNT</td><td>The name of your Dockerhub account or organisation that forms the URL to your country config docker image on Dockerhub <em><strong>before</strong></em> the slash. e.g: <strong>opencrvs</strong></td></tr><tr><td>DOCKERHUB_REPO</td><td>The name of your Dockerhub repository that forms the URL to your country config docker image on Dockerhub <em><strong>after</strong></em> the slash.. e.g. <strong>ocrvs-farajaland</strong></td></tr><tr><td>GH_TOKEN</td><td>The personal Github Token used in all Action runners.</td></tr><tr><td>GH_ENCRYPTION_PASSWORD</td><td>Using the Github Token, a password is created that allows automated actions to access the secrets from other environments. This occurs during provisioning so that the <strong>production, backup</strong> and <strong>staging</strong> environments use the same BACKUP_ENCRYPTION_PASSPHRASE.</td></tr></tbody></table>

#### **Global repository variables**

| Variable      | Description                                                                      |
| ------------- | -------------------------------------------------------------------------------- |
| GH\_APPROVERS | List of valid GitHub accounts to approve deployments for particular environment. |
| COUNTRY       | Country code (ISO 3166 alpha-3) of your OpenCRVS installation.                   |

#### **Environment secrets**

| Secret                              | Description                                                                                                                                                                                              |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| ENCRYPTION\_KEY                     | A password used to LUKS encrypt the `/data` folder containing OpenCRVS data.                                                                                                                             |
| ELASTICSEARCH\_SUPERUSER\_PASSWORD  | The Elasticsearch superuser password. You can also use this to login to Kibana with the username "**elastic**" and you have superuser Elastic privileges. Kibana URL: <https://kibana.\\>\<your\_domain> |
| KIBANA\_USERNAME                    | A username for a regular Kibana user to login and monitor OpenCRVS stack health. Useful for developers as this user will have no superuser privileges.                                                   |
| KIBANA\_PASSWORD                    | A password for a regular Kibana user to login and monitor OpenCRVS stack health                                                                                                                          |
| KIBANA\_SYSTEM\_PASSWORD            | Password for the built-in `kibana_system` user that Kibana uses to connect to Elasticsearch. Generated by the script.                                                                                    |
| POSTGRES\_USER                      | The PostgreSQL superuser admin username. A powerful account that has all rights to OpenCRVS data. Generated by the script.                                                                               |
| POSTGRES\_PASSWORD                  | The PostgreSQL superuser admin password. Generated by the script.                                                                                                                                        |
| SUPER\_USER\_PASSWORD               | Password of the OpenCRVS super user account used by the data seeding and data migration jobs. Generated by the script.                                                                                   |
| MINIO\_ROOT\_USER                   | A username for a Minio superuser admin to login to the Minio console to view supporting document attachments submitted during registrations. <https://minio-console.\\>\<your\_domain>                   |
| MINIO\_ROOT\_PASSWORD               | A password for a Minio superuser admin                                                                                                                                                                   |
| SMTP\_HOST                          |                                                                                                                                                                                                          |
| SMTP\_PORT                          |                                                                                                                                                                                                          |
| SMTP\_USERNAME                      |                                                                                                                                                                                                          |
| SMTP\_PASSWORD                      |                                                                                                                                                                                                          |
| SMTP\_SECURE                        | Whether or not your SMTP port requires TLS                                                                                                                                                               |
| ALERT\_EMAIL                        | Email address or Slack channel address to send system technical alerts to.                                                                                                                               |
| SENDER\_EMAIL\_ADDRESS              | The sender email address that appears in all emails will need to be configured.                                                                                                                          |
| OPENCRVS\_METABASE\_ADMIN\_EMAIL    | Email address for metabase admin panel login                                                                                                                                                             |
| OPENCRVS\_METABASE\_ADMIN\_PASSWORD | Password for metabase admin panel login                                                                                                                                                                  |

#### Environment variables

| Variable                                                                       | Description                                                                                                                                                                                                                                                                                                                                                                                                |
| ------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| DOMAIN                                                                         | The host **domain name** (without www!) for your environment.                                                                                                                                                                                                                                                                                                                                              |
| SELF\_HOSTED\_RUNNER\_ADDITIONAL\_LABELS                                       | Additional labels for self-hosted runner, useful to deploy multiple OpenCRVS instances on shared Kubernetes cluster                                                                                                                                                                                                                                                                                        |
| CONTENT\_SECURITY\_POLICY\_WILDCARD                                            | This string is supplied to the clients and nginx config and ensures that the format of your domain above can be configurable for CORS purposes.                                                                                                                                                                                                                                                            |
| ACTIVATE\_USERS                                                                | When users are seeded, are they immediately active using a test password and six zeros as a 2-Factor auth code. Always false in production and staging.                                                                                                                                                                                                                                                    |
| AUTH\_HOST, CLIENT\_APP\_URL, COUNTRY\_CONFIG\_HOST, GATEWAY\_HOST, LOGIN\_URL | **DEPRECATED**: URLs passed to docker-compose to support internal micro-service communications.                                                                                                                                                                                                                                                                                                            |
| DISK\_SPACE                                                                    | The amount of disk space set aside for encrypted PII data stored by OpenCRVS                                                                                                                                                                                                                                                                                                                               |
| NOTIFICATION\_TRANSPORT                                                        | **DEPRECATED**: A prop which can be used to configure either Email or SMS for staff and beneficiary comms or potentially both.                                                                                                                                                                                                                                                                             |
| KUBE\_MASTER\_NODE                                                             | IP address of the Kubernetes master node. Used as the Kubernetes API advertise address and as the kubelet node IP, so on a master node with several network interfaces set it to the private IP address used for communication between cluster nodes. Leave empty to auto-detect.                                                                                                                          |
| KUBE\_API\_HOST                                                                | Kubernetes API host domain name or IP address. Defaults to `KUBE_MASTER_NODE`.                                                                                                                                                                                                                                                                                                                             |
| KUBE\_API\_ALLOWED\_CIDRS                                                      | Comma separated list of CIDRs allowed to access the Kubernetes API in addition to the cluster nodes. See [Ubuntu Firewall configuration](/v2.1/technical/guides/installation/advanced-topics/ubuntu-firewall-configuration.md).                                                                                                                                                                            |
| KUBE\_WORKER\_NODES                                                            | Comma separated list of Kubernetes workers nodes, in case you are planning to setup Kubernetes cluster with multiple nodes. This property could be left empty for single node setup or you can add worker nodes later. Firewall rules between cluster nodes are generated automatically from the nodes' internal IP addresses.                                                                             |
| APPROVAL\_REQUIRED                                                             | Make approval required for this particular environment. If set to true all GitHub workflows will ask for approval, otherwise approval process will be optional even with defined `GH_APPROVERS` list. **NOTE:** "Reset environment" workflow required 3 approvals to proceed, that additional requirement was made for security reasons. Single person is not able to take decision for environment reset. |

#### **Optional environment secrets**

<table><thead><tr><th width="371">Parameter</th><th>Description</th></tr></thead><tbody><tr><td>BACKUP_SERVER_USER</td><td>User used to upload backups, users home directory is used as default path for backup. Is used by Kubernetes backup jobs</td></tr><tr><td>BACKUP_ENCRYPTION_PASSPHRASE</td><td>Backup encryption passphrase, used only if backup is enabled. This is the password that is used to encrypt all the backups that OpenCRVS creates from a production server and that are stored on the <strong>backup</strong> server. Use this passphrase to decrypt the backups.</td></tr><tr><td>BACKUP_HOST_PUBLIC_KEY</td><td>ssh public key for <code>BACKUP_SERVER_USER</code> , used to authenticate Kubernetes backup jobs on backup server</td></tr><tr><td>BACKUP_HOST_PRIVATE_KEY</td><td>ssh private key for <code>BACKUP_SERVER_USER</code> is used for authentication by Kubernetes backup jobs</td></tr><tr><td>SSL_CRT, SSL_KEY</td><td>Static TLS certificate (or certificate chain) and private key for Traefik. Only created when you choose the static SSL certificate option. Stored in the Kubernetes secret <code>traefik-cert</code> in the <code>traefik</code> namespace.</td></tr></tbody></table>

{% hint style="info" %}
On an environment with restore configured, `RESTORE_ENCRYPTION_PASSPHRASE` is not stored in the environment. It is fetched from the source environment (usually **production**) during deployment and stored in the Kubernetes secret `restore-encryption-secret`.
{% endhint %}

#### **Optional environment variables**

| Parameter                  | Description                                                                                                                                                                                                                                                                                                                                                         |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| BACKUP\_HOST               | **IP address** of the backup server that this environment backs up to. Check Backup and restore section for more information how to configure backup server. Passed to the Dependencies Helm chart as `backup.host`. Must be an IP address, not a hostname: the Kubernetes network policy only allows SSH (port 22) egress from the backup jobs to this IP address. |
| BACKUP\_ENVIRONMENT\_MODE  | Backup environment mode: `dump` (daily full database backup) or `differential` (weekly full, daily differential backup).                                                                                                                                                                                                                                            |
| RESTORE\_ENVIRONMENT\_NAME | GitHub environment name used to configure restore on staging line environments.                                                                                                                                                                                                                                                                                     |
| RESTORE\_HOST              | **IP address** of the backup server that this environment restores from. Passed to the Dependencies Helm chart as `restore.host`. Must be an IP address, not a hostname. Restore jobs fail if restore is enabled and this variable is not set.                                                                                                                      |

{% hint style="warning" %}
**Upgrading to v2.1:** the backup server address used to be read from the `host` key of the `backup-server-ssh-credentials` Kubernetes secret. It is now read from the `BACKUP_HOST` and `RESTORE_HOST` GitHub environment variables. Run `yarn environment:init` for every environment that uses backup or restore (e.g. **production** and **staging**) before deploying v2.1, so that these variables are created.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://documentation.opencrvs.org/v2.1/technical/guides/installation/deploy-set-up-a-server-hosted-environment/create-a-github-environment/environment-secrets-and-variables-explained.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
