> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lumovi.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Server configuration

> The environment variables Lumovi reads when it runs as a server, and the addresses it answers.

The Helm chart sets these from its [values](/server/helm-values). They're for running the image another way, such as [with Docker](/server/docker), and for the few settings the chart has no value for, which you can set with `extraEnv`.

Lumovi reads them when it starts, and checks most of them: one that doesn't make sense stops it, and its log says which and why. A few aren't checked. `LUMOVI_READ_ONLY` and `LUMOVI_ALLOW_PRIVATE_CHARTS` are on only when they're exactly `true` or `1`, and anything else leaves them off. `LUMOVI_MAX_LIST_ITEMS` and `LUMOVI_REQUEST_TIMEOUT_MS` keep their defaults when they aren't numbers. `LUMOVI_HELM` and `LUMOVI_ARTIFACT_HUB_URL` are used as they are, so a wrong one shows up only when someone uses Helm.

## Set by the chart itself

The chart sets two of these without a value of its own: `LUMOVI_PORT` to `8080`, the port its Service, probes and network policy point at, and `LUMOVI_VIEWS_DIR` to `/etc/lumovi/views`, where it mounts the [views everyone sees](/server/views). Leave both out of `extraEnv`.

The chart puts `extraEnv` after its own variables. When two have the same name, Kubernetes uses the last, so a variable repeated in `extraEnv` wins over the chart's. For the two above, that breaks Lumovi: it listens on a port nothing sends to, or reads views from a folder the chart doesn't mount. For the others, set the chart's value instead. The chart builds more than the variable on its values, like the permission to impersonate for `auth.mode`, or the probes and the ingress path for `basePath`, while a variable in `extraEnv` changes only Lumovi.

## Where it runs

<ResponseField name="LUMOVI_PORT" type="number" default="8080">
  The port to listen on, from `0` to `65535`. `0` picks any free port, and the log says which. The chart sets it to `8080` itself.
</ResponseField>

<ResponseField name="LUMOVI_ADDRESS" type="string">
  The address to listen on: every interface unless set.
</ResponseField>

<ResponseField name="LUMOVI_URL" type="string">
  The address people open it at, like `https://lumovi.example.com`: an `http` or `https` URL. Single sign-on needs it. With `https:`, cookies are sent over HTTPS only.

  It's also an origin Lumovi accepts sign-ins, sign-outs and pages' connections from, besides the host each request is sent to. Set it when a proxy in front of Lumovi changes the `Host` header. See [Security](/server/security#sessions-and-cookies).
</ResponseField>

<ResponseField name="LUMOVI_BASE_PATH" type="string" default="/">
  Where it is below that address, like `/lumovi`. Each part of the path can have letters, digits, `_`, `.`, `~` and `-`.
</ResponseField>

## The cluster it shows

<ResponseField name="LUMOVI_CLUSTER_NAME" type="string">
  What it calls the cluster: `in-cluster` (or the kubeconfig's context) unless set.
</ResponseField>

<ResponseField name="KUBECONFIG" type="string">
  A kubeconfig to show a cluster from, instead of the cluster Lumovi runs in.
</ResponseField>

<ResponseField name="LUMOVI_CONTEXT" type="string">
  The kubeconfig's context to show: its current context unless set. A context the kubeconfig doesn't have stops Lumovi.
</ResponseField>

<ResponseField name="LUMOVI_SERVICE_ACCOUNT_DIR" type="string" default="/var/run/secrets/kubernetes.io/serviceaccount">
  Where the pod's service account token and CA certificate are, inside a cluster. Lumovi needs the token there even when people sign in with their own tokens, and stops without it. The chart always mounts it.
</ResponseField>

<ResponseField name="KUBERNETES_SERVICE_HOST" type="string">
  Where the API server is, inside a cluster, with `KUBERNETES_SERVICE_PORT`. Kubernetes sets both in every pod: you don't. Without `KUBERNETES_SERVICE_HOST` or `KUBECONFIG`, Lumovi stops, saying it isn't running in a cluster.
</ResponseField>

## Sign-in

<ResponseField name="LUMOVI_AUTH" type="string" default="token">
  `token`, `oidc` or `proxy`. See [Ways to sign in](/server/overview#ways-to-sign-in).
</ResponseField>

<ResponseField name="LUMOVI_OIDC_ISSUER" type="string">
  The OpenID Connect provider's issuer URL, `http` or `https`. Required with `oidc`.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_CLIENT_ID" type="string">
  Lumovi's client ID at the provider. Required with `oidc`.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_CLIENT_SECRET" type="string">
  The client's secret. Unset for a public client.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_SCOPES" type="string" default="openid email profile">
  The scopes to ask for, separated by spaces.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_USERNAME_CLAIM" type="string" default="email">
  The ID token claim that names people.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_GROUPS_CLAIM" type="string" default="groups">
  The ID token claim that lists their groups.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_PROVIDER_NAME" type="string" default="single sign-on">
  The provider's name on the sign-in button: **Sign in with** this.
</ResponseField>

<ResponseField name="LUMOVI_OIDC_FORWARD_TOKEN" type="string">
  `id` or `access`: pass people's own token on (the API server must trust the provider) instead of impersonating them. The token must be a JWT that says when it expires.
</ResponseField>

<ResponseField name="LUMOVI_PROXY_USER_HEADER" type="string" default="X-Forwarded-User">
  The header a proxy names people in. Upper and lower case don't matter.
</ResponseField>

<ResponseField name="LUMOVI_PROXY_GROUPS_HEADER" type="string" default="X-Forwarded-Groups">
  The header a proxy lists their groups in, separated by commas.
</ResponseField>

<ResponseField name="LUMOVI_PROXY_SIGN_OUT_URL" type="string">
  Where signing out of the proxy is: an `http` or `https` URL.
</ResponseField>

<ResponseField name="LUMOVI_USERNAME_PREFIX" type="string">
  Put before impersonated users' names.
</ResponseField>

<ResponseField name="LUMOVI_GROUPS_PREFIX" type="string">
  Put before impersonated groups' names.
</ResponseField>

<ResponseField name="LUMOVI_SESSION_HOURS" type="number" default="12">
  How long sessions last, in hours: more than 0, at most 168, a week.
</ResponseField>

<ResponseField name="LUMOVI_HEARTBEAT_SECONDS" type="number" default="30">
  How often pages' connections are checked, in seconds, at most 3600. Keep it shorter than the idle timeout of the proxies in front of Lumovi.
</ResponseField>

## What people can do

<ResponseField name="LUMOVI_READ_ONLY" type="boolean" default="false">
  `true` or `1`: nobody changes anything through Lumovi. Anything else leaves changes on.
</ResponseField>

<ResponseField name="LUMOVI_METRICS_SOURCE" type="string" default="auto">
  Where usage history comes from unless people choose: `auto`, `off`, or `namespace/service:port`, with a path after it for vmselect (`vm/vmselect:8481/select/0/prometheus`).
</ResponseField>

<ResponseField name="LUMOVI_ALLOW_PRIVATE_CHARTS" type="boolean" default="false">
  `true` or `1`: charts may come from private network addresses.
</ResponseField>

<ResponseField name="LUMOVI_ARTIFACT_HUB_URL" type="string" default="https://artifacthub.io">
  Where to search for charts.
</ResponseField>

<ResponseField name="LUMOVI_VIEWS_DIR" type="string" default="/etc/lumovi/views">
  Where the views and add-ons everyone sees are. The chart sets it itself, to the folder it mounts its `views` value at.
</ResponseField>

<ResponseField name="LUMOVI_HELM" type="string" default="helm">
  The helm to run: `helm` on the `PATH` unless set. The image sets it to `/usr/local/bin/helm`, the helm it comes with.
</ResponseField>

## Large clusters and slow API servers

These work the same as in the desktop app, and the chart has no values for them: set them with `extraEnv`.

<ResponseField name="LUMOVI_MAX_LIST_ITEMS" type="number" default="5000">
  The most objects a list loads. Lists are fetched in chunks of 500.
</ResponseField>

<ResponseField name="LUMOVI_REQUEST_TIMEOUT_MS" type="number" default="20000">
  How long the API server has to answer, in milliseconds.
</ResponseField>

```yaml values.yaml theme={"theme":{"light":"github-light","dark":"github-dark-default"}}
extraEnv:
  - name: LUMOVI_MAX_LIST_ITEMS
    value: '10000'
  - name: LUMOVI_REQUEST_TIMEOUT_MS
    value: '45000'
```

## Addresses it answers

All of these are below the base path. Whatever stands in front of Lumovi must pass them all through.

| Address | What it's for |
| - | - |
| `GET healthz` | Health checks: answers `200 ok` while Lumovi runs, without signing in. |
| `api/session` | Who's signed in (`GET`), signing in with a token (`POST`, only with token sign-in), and signing out (`DELETE`). |
| `GET auth/sign-in` | Where single sign-on starts: Lumovi sends the browser on to your provider. Only with `oidc`. |
| `auth/callback` | Where your OpenID Connect provider sends people back. Register it as the redirect URI. Only with `oidc`. |
| `api/socket` | Each page's WebSocket. Proxies in front of Lumovi must pass WebSockets here. |

Any other address below the base path is Lumovi's page or one of its files, for `GET` and `HEAD`. Other methods get `405`, and other addresses under `api/` and `auth/` get `404`.

Addresses outside the base path get `404`, with a note saying where Lumovi is. The base path without its trailing slash, like `/lumovi`, leads to `/lumovi/`.

<Columns cols={2}>
  <Card title="Helm values" icon="sliders-horizontal" href="/server/helm-values">
    The chart's settings, which set these for you.
  </Card>

  <Card title="Run it with Docker" icon="container" href="/server/docker">
    Use these to run the image outside Kubernetes.
  </Card>
</Columns>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.