Configuration
One .env file, read at container start. Real environment variables always win, so a hosting platform's own configuration takes precedence. Required variables have no default — the app refuses to start without them. Optional ones can be left empty to disable a feature.
Database — required
| Variable | |
|---|---|
SPRING_DATASOURCE_URL | JDBC URL of the tenant database (jdbc:postgresql://hrida-postgres:5432/hridaone in the bundled compose) |
DB_USERNAME / DB_PASSWORD | Credentials |
SPRING_JPA_HIBERNATE_DDL_AUTO | update for first deploy / dev; validate in production |
App URL & CORS
| Variable | |
|---|---|
APP_BASE_URL / APP_FRONTEND_URL | Public origin — https://one.hrida.ai in production, http://localhost:8080 locally |
CORS_ALLOWED_ORIGINS | Comma-separated allow-list of browser origins |
FILE_UPLOAD_DIR | Where uploads land (/app/uploads, a Docker volume) |
Secrets — required
| Variable | Generate | Notes |
|---|---|---|
JWT_SECRET | openssl rand -hex 64 | 64+ chars, never reused |
GLOBAL_ADMIN_SECRET | openssl rand -hex 32 | Global Admin bootstrap; must differ from JWT_SECRET |
SECURITY_KEYWORD_ENC_KEY | openssl rand -hex 32 | AES key for the security keyword; must differ from both above |
Email — required
| Variable | |
|---|---|
MAIL_HOST / MAIL_PORT | SMTP server (smtp.gmail.com / 587) |
MAIL_USERNAME / MAIL_PASSWORD | Credentials — Gmail requires an App Password with 2-Step Verification |
ADMIN_EMAIL / MAIL_FROM | Default sender identity (fall back to MAIL_USERNAME) |
Per-company branded sending over SES is configured in-app, not here.
Optional integrations
| Feature | Variables |
|---|---|
| Cloudinary media | CLOUDINARY_NAME, CLOUDINARY_KEY, CLOUDINARY_SECRET |
| OpenAI document OCR | OPENAI_API_KEY, OPENAI_RESPONSES_URL, OPENAI_OCR_MODEL (gpt-4.1-mini) |
| Razorpay payments | RAZORPAY_KEY_ID, RAZORPAY_KEY_SECRET, RAZORPAY_WEBHOOK_SECRET |
Keycloak SSO — optional
Leave all blank for native auth. See Authentication → Keycloak SSO.
KEYCLOAK_ISSUER_URI · KEYCLOAK_CLIENT_ID · KEYCLOAK_CLIENT_SECRET · KEYCLOAK_SSO_CALLBACK_URL · KEYCLOAK_SSO_COOKIE_SECURE · KEYCLOAK_ALLOWED_CLIENT_IDS · KEYCLOAK_ADMIN_CLIENT_ID · KEYCLOAK_ADMIN_CLIENT_SECRET · KEYCLOAK_SYNC_INTERVAL_MS · KEYCLOAK_SYNC_INITIAL_DELAY_MS
LDAP — optional
The shared provisioning directory this app owns. See Authentication → LDAP.
LDAP_PROVISIONING_ENABLED · LDAP_URL · LDAP_BASE_DN (dc=hrida,dc=local) · LDAP_ADMIN_DN · LDAP_ADMIN_PASSWORD
A tenant's own LDAP / AD federation is configured per company in-app, not here.